« 一个PHP代码 | Home | How to get web server software and version of a remote server »

August 28, 2006

Hide PHP Version in Apache from remote users requests


In order to prevent PHP from exposing the fact that it is installed on the server, by adding its signature to the web server header we need to locate in php.ini the variable expose_php and turn it off.
By default expose_php is set to On.

In your php.ini (based on your Linux distribution this can be found in various places, like /etc/php.ini, /etc/php5/apache2/php.ini, etc.) locate the line containing “expose_php On” and set it to Off:

expose_php = Off

After making this change PHP will no longer add it’s signature to the web server header. Doing this, will not make your server more secure… it will just prevent remote hosts to easily see that you have PHP installed on the system and what version you are running.

Posted by Lifeng Shen on August 28, 2006 9:53 AM |

评论

添加评论







固定链接与引用