View Single Post
Old 12-14-2009, 06:41 PM   #6 (permalink)
delayedinsanity
is cute and cuddly
 
delayedinsanity's Avatar
 
Join Date: Mar 2008
Location: Vegas, Baby
Posts: 963
Thanks: 31
delayedinsanity is on a distinguished road
Default

Quote:
Originally Posted by adamdecaf View Post
You're right, it's not. Some people just like to lock down everything they can, others don't.
I was hoping it would quote both responses, but eh.

I'm in agreement with Adam on this one, you should lock that stuff down. Many of those popular web sites have major IT teams with people who specialize in security to take care of business. Smaller web sites should do what they can to remove themselves from being a target, and when it comes to Apache this means at the very least you should have the following;

bash Code:
ServerSignature Off
ServerTokens Prod
TraceEnable Off

You should always put more effort into making sure your iptables configuration is on lock down, but these three simple settings in Apache can frighten even the loneliest of script kiddies.
delayedinsanity is offline  
Reply With Quote