httpd 默认项安全配置

1.ServerTokens

修改 ServerTokens 默认值为Prod

2.Options Index FollowSymLinks

修改目录权限下的 Options Index FollowSymLinks 为 Options -Index FollowSymLinks

3.HostnameLookups

修改HostnameLookups 默认值为off

4.修改ServerSignature Off

5.注销icons 别名目录

#Alias /icons/ “/var/www/icons”

#<Directory "/var/www/icons">
#    Options Indexes MultiViews FollowSymLinks
#    AllowOverride None
#    Order allow,deny
#    Allow from all
#</Directory> 

6.注销 dav功能

#<IfModule mod_dav_fs.c>
#    # Location of the WebDAV lock database.
#    DAVLockDB /var/lib/dav/lockdb
#</IfModule>

7.注销 CGI-BIN

#ScriptAlias /cgi-bin/ "/var/www/cgi-bin/"

# "/var/www/cgi-bin" should be changed to whatever your ScriptAliased
# CGI directory exists, if you have that configured.
#
#<Directory "/var/www/cgi-bin">
#    AllowOverride None
#    Options None
#    Order allow,deny
#    Allow from all
#</Directory>

发布者

勿忘心安

一念净心花开遍世界!