SV-33098r1_rule
V-6724
WG520
WG520 W22
CAT III
10
Ensure the web server is configured to not advertise the web server and operating system information to the client.
Locate the httpd.conf file.
Open the httpd.conf file with an editor such as Notepad, and search for the following uncommented directive: ServerTokens
The directive ServerTokens must be set to “Prod” (ex. ServerTokens Prod). This directive controls whether Server response header field that is sent back to clients that includes a description of the OS-type of the server as well as information about compiled-in modules.
If the web server or operating system information is sent to the client via the server response header, this is a finding. If the directive does not exist, this would be a finding as it defaults to Full.
V-6724
False
WG520 W22
Locate the httpd.conf file.
Open the httpd.conf file with an editor such as Notepad, and search for the following uncommented directive: ServerTokens
The directive ServerTokens must be set to “Prod” (ex. ServerTokens Prod). This directive controls whether Server response header field that is sent back to clients that includes a description of the OS-type of the server as well as information about compiled-in modules.
If the web server or operating system information is sent to the client via the server response header, this is a finding. If the directive does not exist, this would be a finding as it defaults to Full.
M
Web Administrator
158