apache httpd server默認http返回的HTTP RESPONSE 中的 HTTP HEADER會帶有其具體版本信息,如:
--------http head -----------
null = HTTP/1.1 404 Not Found
Date = Mon, 09 Jan 2012 07:40:54 GMT
Content-Length = 204
Keep-Alive = timeout=5, max=100
Connection = Keep-Alive
Content-Type = text/html; charset=iso-8859-1
Server = Apache/2.2.21 (Unix)
向外部提供具體apache版本可能不太安全,可以通過在httpd.conf 中添加指令 ServerTokens off
關閉,關閉後效果如下:
--------http head -----------
null = HTTP/1.1 404 Not Found
Date = Mon, 09 Jan 2012 07:37:42 GMT
Content-Length = 204
Keep-Alive = timeout=5, max=100
Connection = Keep-Alive
Content-Type = text/html; charset=iso-8859-1
Server = Apache