Apache Errorpage If you are running a very small web business and do not willing to purchase an SSL certificate you can still assign a Self signed certificate to your website. And to do so we need to make the following entry in main configuration file.

this can be set also outside the global server config in virtual hosts, per directory or .htaccess. Apache Error Page Redirect unlimited and when you allow large requests on a web server its possible that you could be a victim of Denial of service attacks. What the second line 'ServerTokens Prod' does is to suppress a server token in HTTP response headers to a bare minimal.

The other variables will exist only if they existed prior to the error/problem. The server is running at a host who will not provide me command line access, although I can browse the install location via ftp.

mod_evasive can be installed directly from the source. Configuration Use of ErrorDocument is enabled for .htaccess files when the AllowOverride is set accordingly. To keep your .htaccess file clean, make sure your text editor has word wrap disabled, and that it is using UNIX-style line endings.

This feature of mod_evasive enables it to handle the HTTP brute force and Dos or DDos attack. Apache Servertokens

The following five-step process is the most universal method, as it only requires FTP access to your server and a text editor, like Notepad++ (on a PC) or TextEdit (on a Mac).

You can set the value in bytes from 0 (unlimited) to 2147483647 (2GB) that are allowed in a request body. To show hidden files using Filezilla, go to the Server dropdown, then choose Force Showing Hidden Files.

If you want to hide PHP version in HTTP headers, open php.ini file with a text editor, look for "expose_php = On", and change it to "expose_php = Off". Related 198How can I check which version of apache is installed on a Debian machine?294How to enable mod_rewrite for Apache 2.260How do you increase the max number of concurrent connections in

So if your Linux distribution has not overwritten this, then you will be presenting all the possible information to the world. But there are also many such worms that will not check anything and just try to exploit any server… Also there are other complex fingerprinting applications that can find out various

So it's recommended to disable all those modules that are not in use currently. However, without the second line 'ServerTokens Prod', Apache server will still include a detailed server token in HTTP response headers, which reveals Apache version number.

Step Two: Create your .htaccess file (if you don't already have one) Fair warning: While any novice can create a .htaccess file (we're going to show you how right here!), if you have In any case I am getting plenty of access denied messages and the same stock 404 page. Options All - To enable All options at once. To do so you need to include the mod_log_config module.