microsimulation / ijm

A central place for general issues, documents, scripts and resources for the IJM
https://microsimulation.org/ijm/
MIT License
4 stars 0 forks source link

Rewrite rules for Nginx #76

Closed astrajescu closed 4 years ago

astrajescu commented 4 years ago

Mask/hide the nginx and PHP versions of site from response headers.

CWE-200 - risk: low tech details: server leaks technology stack info in response headers:

Server: nginx/1.15.5 X-Powered-By: PHP/7.0.29

vulnerability: Access to such information may facilitate attackers identifying other frameworks/components your web application is reliant upon and the vulnerabilities such components may be subject to.

rtudvasev commented 4 years ago

Added in https://github.com/microsimulation/ijm/commit/ffb2ff3fc58ae59cd4617ac8653abbf30f5759d0