mercredi 5 juin 2019

Hide server information to wappalyzer

Yesterday I set out to improve the security of my servers and found that my version of apache2, PHP and even my operating system could be obtained easily with the Wappalyzer chrome plugin. I was informing to hide the information and arrive at a couple of configuration lines in the file apache.conf, ServerTokens Prod and ServerSignature Off, with this I managed to eliminate the Apache version but it keeps coming out that I am using that technology. In PHP something similar happens to me and it's not what I want, I want to hide all information. Maybe at this point you think it's impossible, but if you can, web pages like google.com do not show any information about their servers and I would like to get the same. I attached a screenshot of how the plugin looks when trying to scan the google.com website and this is how I would like it to look mine.

SCREENSHOT




Aucun commentaire:

Enregistrer un commentaire