Welcome! Log In Create A New Profile

Advanced

[PATCH] HTTP: stop emitting server version by default

Piotr Sikora via nginx-devel
February 27, 2024 08:22PM
# HG changeset patch
# User Piotr Sikora <piotr@aviatrix.com>
# Date 1708977611 0
# Mon Feb 26 20:00:11 2024 +0000
# Branch patch001
# Node ID a8a592b9b62eff7bca03e8b46669f59d2da689ed
# Parent 89bff782528a91ad123b63b624f798e6fd9c8e68
HTTP: stop emitting server version by default.

This information is only useful to attackers.

The previous behavior can be restored using "server_tokens on".

Signed-off-by: Piotr Sikora <piotr@aviatrix.com>

diff -r 89bff782528a -r a8a592b9b62e src/http/ngx_http_core_module.c
--- a/src/http/ngx_http_core_module.c Wed Feb 14 20:03:00 2024 +0400
+++ b/src/http/ngx_http_core_module.c Mon Feb 26 20:00:11 2024 +0000
@@ -3899,7 +3899,7 @@
ngx_conf_merge_value(conf->etag, prev->etag, 1);

ngx_conf_merge_uint_value(conf->server_tokens, prev->server_tokens,
- NGX_HTTP_SERVER_TOKENS_ON);
+ NGX_HTTP_SERVER_TOKENS_OFF);

ngx_conf_merge_ptr_value(conf->open_file_cache,
prev->open_file_cache, NULL);
_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
https://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

[PATCH] HTTP: stop emitting server version by default

Piotr Sikora via nginx-devel 193 February 27, 2024 08:22PM

Re: [PATCH] HTTP: stop emitting server version by default

Sergey A. Osokin 36 February 29, 2024 09:06AM

Re: [PATCH] HTTP: stop emitting server version by default

Piotr Sikora via nginx-devel 36 March 08, 2024 10:10AM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 146
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready