<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Marketgrid Consulting Blog &#187; Apache</title>
	<atom:link href="http://www.marketgrid.com/blog/category/apache/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.marketgrid.com/blog</link>
	<description>MySQL, website development and performance news</description>
	<lastBuildDate>Wed, 01 Sep 2010 11:00:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Apache HTTP Server 2.3.8-alpha</title>
		<link>http://www.marketgrid.com/blog/2010/09/apache-http-server-2-3-8-alpha/</link>
		<comments>http://www.marketgrid.com/blog/2010/09/apache-http-server-2-3-8-alpha/#comments</comments>
		<pubDate>Wed, 01 Sep 2010 11:00:45 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Releases]]></category>
		<category><![CDATA[Apache 2.3]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=322</guid>
		<description><![CDATA[The Apache Software Foundation and the Apache HTTP Server Project have announced the release of version 2.3.8-alpha of the Apache HTTP Server (&#8220;Apache&#8221;). This version of Apache is principally an alpha release to test new technology and features that are incompatible or too large for the stable 2.2.x branch. This alpha release should not be [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.marketgrid.com/blog/wp-content/uploads/2010/06/feather.gif"><img class="aligncenter size-full wp-image-204" title="feather" src="http://www.marketgrid.com/blog/wp-content/uploads/2010/06/feather.gif" alt="" width="248" height="70" /></a></p>
<p>The Apache Software Foundation and the Apache HTTP Server Project have announced the release of version 2.3.8-alpha of the Apache HTTP Server (&#8220;Apache&#8221;).</p>
<p>This version of Apache is principally an alpha release to test new technology and features that are incompatible or too large for the stable 2.2.x branch.</p>
<p>This alpha release should not be presumed to be compatible with binaries built against any prior or future version.</p>
<p>This release is expected to be the last alpha release; subsequent releases will be beta releases as we move towards 2.4.0-GA.</p>
<p>Apache HTTP Server 2.3.8-alpha is available for download from:  <a href="http://httpd.apache.org/download.cgi">http://httpd.apache.org/download.cgi</a></p>
<p>Apache 2.3 offers numerous enhancements, improvements, and performance boosts over the 2.2 codebase.</p>
<p>For an overview of new features introduced since 2.3 please see:  <a href="http://httpd.apache.org/docs/trunk/new_features_2_4.html">http://httpd.apache.org/docs/trunk/new_features_2_4.html</a></p>
<p>Please see the CHANGES_2.3 file, linked from the download page, for a full list of changes.</p>
<p>This release includes the Apache Portable Runtime (APR) version 1.4.2 and APR-Util version 1.3.9 in a separate -deps tarball.  The APR libraries must be upgraded for all features of httpd to operate correctly.</p>
<p>This release builds on and extends the Apache 2.2 API.  Modules written for Apache 2.2 will need to be recompiled in order to run with Apache 2.3, and require minimal or no source code changes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/09/apache-http-server-2-3-8-alpha/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>verify- and notified- entries in Apache logs</title>
		<link>http://www.marketgrid.com/blog/2010/08/verify-and-notified-entries-in-apache-logs/</link>
		<comments>http://www.marketgrid.com/blog/2010/08/verify-and-notified-entries-in-apache-logs/#comments</comments>
		<pubDate>Sat, 21 Aug 2010 11:00:57 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Error logs]]></category>
		<category><![CDATA[ProxySG]]></category>
		<category><![CDATA[Webserver logs]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=294</guid>
		<description><![CDATA[If you&#8217;re finding 404&#8242;s in your Apache error logs relating to verify-&#60;other stuff&#62; and notified-&#60;other stuff&#62; such as the below 1.2.3.4 &#8211; - [20/Aug/2010:10:20:15 +0100] &#8220;GET /verify-AUP?aHR0cDovL3d3dy5sb2FuZmluZGVyLmNvLnVrL2NvbnRhY3QtdXM= HTTP/1.1&#8243; 200 3752 &#8220;-&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)&#8221; It is from a mis-configured [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re finding 404&#8242;s in your Apache error logs relating to verify-&lt;other stuff&gt; and notified-&lt;other stuff&gt; such as the below</p>
<p>1.2.3.4 &#8211; - [20/Aug/2010:10:20:15 +0100] &#8220;GET /verify-AUP?aHR0cDovL3d3dy5sb2FuZmluZGVyLmNvLnVrL2NvbnRhY3QtdXM= HTTP/1.1&#8243; 200 3752 &#8220;-&#8221; &#8220;Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)&#8221;</p>
<p>It is from a mis-configured proxy server from ProxySG &#8211; see <a href="http://techlabs.bluecoat.com/policy/">http://techlabs.bluecoat.com/policy/</a> and nothing you can do about it.</p>
<p>/verify-Compliance_Page</p>
<p>/verify-AUP</p>
<p>/notified-Compliance_Page</p>
<p>/notified-AUP</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/08/verify-and-notified-entries-in-apache-logs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>/MSOffice/cltreq.asp in your web server logs</title>
		<link>http://www.marketgrid.com/blog/2010/08/msofficecltreq-asp-in-your-web-server-logs/</link>
		<comments>http://www.marketgrid.com/blog/2010/08/msofficecltreq-asp-in-your-web-server-logs/#comments</comments>
		<pubDate>Fri, 20 Aug 2010 09:29:55 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[Error logs]]></category>
		<category><![CDATA[Webserver logs]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=292</guid>
		<description><![CDATA[If you are finding 404&#8242;s in your web server logs referring to entries similar to the following /MSOffice/cltreq.asp?UL=1&#38;ACT=4&#38;BUILD=8164&#38;STRMVER=4&#38;CAPREQ=0 it is because someone has Microsoft Office installed, and the discussion bar turned on in Internet Explorer, which is querying your server to see whether it supports web discussions (which it probably doesn&#8217;t).]]></description>
			<content:encoded><![CDATA[<p>If you are finding 404&#8242;s in your web server logs referring to entries similar to the following</p>
<pre>/MSOffice/cltreq.asp?UL=1&amp;ACT=4&amp;BUILD=8164&amp;STRMVER=4&amp;CAPREQ=0</pre>
<p>it is because someone has Microsoft Office installed, and the discussion bar turned on in Internet Explorer, which is querying your server to see whether it supports web discussions (which it probably doesn&#8217;t).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/08/msofficecltreq-asp-in-your-web-server-logs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Use of ServerTokens in Apache</title>
		<link>http://www.marketgrid.com/blog/2010/08/use-of-servertokens-in-apache/</link>
		<comments>http://www.marketgrid.com/blog/2010/08/use-of-servertokens-in-apache/#comments</comments>
		<pubDate>Thu, 19 Aug 2010 09:14:15 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ServerTokens]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=275</guid>
		<description><![CDATA[This directive controls whether Server response header field which is sent back to clients includes a description of the generic OS-type of the server as well as information about compiled-in modules. Options are: ServerTokens Prod[uctOnly] Server sends (e.g.): Server: Apache ServerTokens Major Server sends (e.g.): Server: Apache/2 ServerTokens Minor Server sends (e.g.): Server: Apache/2.0 ServerTokens [...]]]></description>
			<content:encoded><![CDATA[<p>This directive controls whether <b>Server</b> response header field which is sent back to clients includes a description of the generic OS-type of the server as well as information about compiled-in modules.</p>
<p>Options are:</p>
<p>ServerTokens Prod[uctOnly]<br />
Server sends (<em>e.g.</em>):<br />
Server:       Apache</p>
<p>ServerTokens Major<br />
Server sends (<em>e.g.</em>):<br />
Server:       Apache/2</p>
<p>ServerTokens Minor<br />
Server sends (<em>e.g.</em>):<br />
Server:       Apache/2.0</p>
<p>ServerTokens Min[imal]<br />
Server sends (<em>e.g.</em>):<br />
Server:       Apache/2.0.41</p>
<p>ServerTokens OS<br />
Server sends (<em>e.g.</em>):<br />
Server: Apache/2.0.41       (Unix)</p>
<p>ServerTokens Full (or not specified)<br />
Server sends (<em>e.g.</em>):<br />
Server: Apache/2.0.41       (Unix) PHP/4.2.2 MyMod/1.2</p>
<p>This setting applies to the entire server, and cannot be enabled or disabled on a virtualhost-by-virtualhost basis.</p>
<p>After version 2.0.44, this directive also controls the     information presented by the ServerSignature directive.</p>
<p>This is what you would get as the response headers from a server without the ServerTokens set:</p>
<pre>

Date: Thu, 19 Aug 2010 08:58:08 GMT
Server: Apache/2.2.8 (CentOS) DAV/2 PHP/5.2.10 mod_python/3.2.8
     Python/2.4.3 mod_ssl/2.2.8 OpenSSL/0.9.8e-fips-rhel5
     mod_perl/2.0.4 Perl/v5.8.8
X-Powered-By: PHP/5.2.10
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate,
     post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding,User-Agent
Content-Encoding: gzip
Content-Length: 4896
Keep-Alive: timeout=15, max=99
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
</pre>
<p>and the same from a server with the ServerTokens set to <b>Prod</b>:</p>
<pre>

Date: Thu, 19 Aug 2010 08:58:08 GMT
Server: Apache
X-Powered-By: PHP/5.2.10
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate,
     post-check=0, pre-check=0
Pragma: no-cache
Vary: Accept-Encoding,User-Agent
Content-Encoding: gzip
Content-Length: 4896
Keep-Alive: timeout=15, max=99
Connection: Keep-Alive
Content-Type: text/html; charset=UTF-8
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/08/use-of-servertokens-in-apache/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache HTTP Server 2.3.6-alpha</title>
		<link>http://www.marketgrid.com/blog/2010/06/apache-http-server-2-3-6-alpha/</link>
		<comments>http://www.marketgrid.com/blog/2010/06/apache-http-server-2-3-6-alpha/#comments</comments>
		<pubDate>Tue, 22 Jun 2010 07:40:50 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Releases]]></category>
		<category><![CDATA[2.3]]></category>
		<category><![CDATA[HTTP]]></category>
		<category><![CDATA[Server]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=200</guid>
		<description><![CDATA[The Apache Software Foundation and the Apache HTTP Server Project have announced the release of version 2.3.6-alpha of the Apache HTTP Server (&#8220;Apache&#8221;). This version of Apache is principally an alpha release to test new technology and features that are incompatible or too large for the stable 2.2.x branch. This alpha release should not be [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter size-full wp-image-204" title="Apache Logo" src="http://www.marketgrid.com/blog/wp-content/uploads/2010/06/feather.gif" alt="" width="248" height="70" /></p>
<p>The Apache Software Foundation and the Apache HTTP Server Project have announced the release of version 2.3.6-alpha of the Apache HTTP Server (&#8220;Apache&#8221;).</p>
<p>This version of Apache is principally an alpha release to test new technology and features that are incompatible or too large for the stable 2.2.x branch. This alpha release should not be presumed to be compatible with binaries built against any prior or future version.</p>
<p>Apache HTTP Server 2.3.6-alpha is available for download from:  <a href="http://httpd.apache.org/download.cgi">http://httpd.apache.org/download.cgi</a></p>
<p>Apache 2.3 offers numerous enhancements, improvements, and performance boosts over the 2.2 codebase.</p>
<p>For an overview of new features introduced since 2.3 please see:</p>
<p><a href="http://httpd.apache.org/docs/trunk/new_features_2_4.html">http://httpd.apache.org/docs/trunk/new_features_2_4.html</a></p>
<p>Please see the CHANGES_2.3 file, linked from the download page, for a full list of changes.</p>
<p>This release includes the Apache Portable Runtime (APR) version 1.4.2 and APR-Util version 1.3.9 in a separate -deps tarball.  The APR libraries must be upgraded for all features of httpd to operate correctly.</p>
<p>This release builds on and extends the Apache 2.2 API.  Modules written for Apache 2.2 will need to be recompiled in order to run with Apache 2.3, and require minimal or no source code changes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/06/apache-http-server-2-3-6-alpha/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache HTTP Server (httpd) 2.2.15</title>
		<link>http://www.marketgrid.com/blog/2010/03/apache-http-server-httpd-2-2-15/</link>
		<comments>http://www.marketgrid.com/blog/2010/03/apache-http-server-httpd-2-2-15/#comments</comments>
		<pubDate>Sat, 06 Mar 2010 20:52:50 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Releases]]></category>
		<category><![CDATA[Apache 2.2]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=154</guid>
		<description><![CDATA[The Apache Software Foundation and the Apache HTTP Server Project has announced the release and immediate availability of version 2.2.15 of the Apache HTTP Server (&#8220;httpd&#8221;).  This version of httpd is principally a security and bug fix release. Notably, this release was updated to reflect the OpenSSL Project&#8217;s release 0.9.8m of the openssl library, and [...]]]></description>
			<content:encoded><![CDATA[<p>The Apache Software Foundation and the Apache HTTP Server Project has announced the release and immediate availability of version<br />
2.2.15 of the Apache HTTP Server (&#8220;httpd&#8221;).  This version of httpd is principally a security and bug fix release.</p>
<p>Notably, this release was updated to reflect the OpenSSL Project&#8217;s release 0.9.8m of the openssl library, and addresses CVE-2009-3555<br />
(<a href="http://cve.mitre.org/" target="_blank">cve.mitre.org</a>), the  TLS renegotiation prefix injection attack. This release further addresses the issues CVE-2010-0408, CVE-2010-0425 and CVE-2010-0434 within mod_proxy_ajp, mod_isapi and mod_headers respectively.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/03/apache-http-server-httpd-2-2-15/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache HTTP Server 1.3.42 (final release of 1.3.x)</title>
		<link>http://www.marketgrid.com/blog/2010/02/apache-http-server-1-3-42-final-release-of-1-3-x/</link>
		<comments>http://www.marketgrid.com/blog/2010/02/apache-http-server-1-3-42-final-release-of-1-3-x/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 18:40:54 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Releases]]></category>
		<category><![CDATA[Apache 1.3]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=105</guid>
		<description><![CDATA[The Apache Software Foundation and the Apache HTTP Server Project have announced the release of version 1.3.42 of the Apache HTTP Server. This release is intended as the final release of version 1.3 of the Apache HTTP Server, which has reached end of life status. There will be no more full releases of Apache HTTP [...]]]></description>
			<content:encoded><![CDATA[<p>The Apache Software Foundation and the Apache HTTP Server Project have announced the release of version 1.3.42 of the Apache HTTP Server. This release is intended as the final release of version 1.3 of the Apache HTTP Server, which has reached end of life status.</p>
<p>There will be no more full releases of Apache HTTP Server 1.3.</p>
<p>However, critical security updates may be made available from the following website: <a href="http://www.apache.org/dist/httpd/patches/">http://www.apache.org/dist/httpd/patches/</a></p>
<p>This version of Apache is is principally a bug and security fix release.</p>
<p>The following moderate security flaw has been addressed:</p>
<p>* CVE-2010-0010 (cve.mitre.org)</p>
<p>mod_proxy: Prevent chunk-size integer overflow on platforms where sizeof(int) &lt; sizeof(long). Reported by Adam Zabrocki.</p>
<p>Apache 1.3.42 is the final stable release of the Apache 1.3 family. We strongly recommend that users of all earlier versions, including 1.3 family releases, upgrade to to the current 2.2 version as soon as possible.</p>
<p>For information about how to upgrade, please see the documentation:  <a href="http://httpd.apache.org/docs/2.2/upgrading.html">http://httpd.apache.org/docs/2.2/upgrading.html</a></p>
<p>Apache 1.3.42 is available for download from <a href="http://httpd.apache.org/download.cgi">http://httpd.apache.org/download.cgi</a></p>
<p>Apache 1.3.42 Major changes</p>
<p>Security vulnerabilities</p>
<p>The main security vulnerabilities addressed in 1.3.42 are:</p>
<ul>
<li>SECURITY: CVE-2010-0010 (cve.mitre.org) mod_proxy: Prevent chunk-size integer overflow on platforms where sizeof(int) &lt; sizeof(long). Reported by Adam Zabrocki.</li>
</ul>
<p>Bugfixes addressed in 1.3.42 are:</p>
<ul>
<li> Protect logresolve from mismanaged DNS records that return blank/null hostnames.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/02/apache-http-server-1-3-42-final-release-of-1-3-x/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache HTTP Server 2.3.5-alpha</title>
		<link>http://www.marketgrid.com/blog/2010/01/apache-http-server-2-3-5-alpha/</link>
		<comments>http://www.marketgrid.com/blog/2010/01/apache-http-server-2-3-5-alpha/#comments</comments>
		<pubDate>Thu, 28 Jan 2010 22:30:16 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Releases]]></category>
		<category><![CDATA[Apache 2.3]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=90</guid>
		<description><![CDATA[The Apache Software Foundation and the Apache HTTP Server Project have announced the release of version 2.3.5-alpha of the Apache HTTP Server (&#8220;Apache&#8221;).  This version of Apache is principally an alpha release to test new technology and features that are incompatible or too large for the stable 2.2.x branch. This alpha release should not be [...]]]></description>
			<content:encoded><![CDATA[<p>The Apache Software Foundation and the Apache HTTP Server Project have announced the release of version 2.3.5-alpha of the Apache HTTP Server (&#8220;Apache&#8221;).  This version of Apache is principally an alpha release to test new technology and features that are incompatible or too large for the stable 2.2.x branch. This alpha release should not be presumed to be compatible with binaries built against any prior or future version.</p>
<p>Apache HTTP Server 2.3.5-alpha is available for download from:  <a href="http://httpd.apache.org/download.cgi">http://httpd.apache.org/download.cgi</a></p>
<p>Apache 2.3 offers numerous enhancements, improvements, and performance boosts over the 2.2 codebase.  For an overview of new features introduced since 2.3 please see:  <a href="http://httpd.apache.org/docs/trunk/new_features_2_4.html">http://httpd.apache.org/docs/trunk/new_features_2_4.html</a></p>
<p>Please see the CHANGES_2.3 file, linked from the download page, for a full list of changes.</p>
<p>This release includes the Apache Portable Runtime (APR) version 1.4.2 and APR-Util version 1.3.9 in a separate -deps tarball.  The APR libraries must be upgraded for all features of httpd to operate correctly.</p>
<p>This release builds on and extends the Apache 2.2 API.  Modules written for Apache 2.2 will need to be recompiled in order to run with Apache 2.3, and require minimal or no source code changes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/01/apache-http-server-2-3-5-alpha/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Masking your Apache information with ServerTokens</title>
		<link>http://www.marketgrid.com/blog/2010/01/masking-your-apache-information-with-servertokens/</link>
		<comments>http://www.marketgrid.com/blog/2010/01/masking-your-apache-information-with-servertokens/#comments</comments>
		<pubDate>Sun, 10 Jan 2010 13:20:53 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[Confirg]]></category>
		<category><![CDATA[Production]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=42</guid>
		<description><![CDATA[If you want to give away less information about your current version of Apache, then you can use the ServerTokens directive in the config file (httpd.conf). The recommended one for Production servers is &#8216;Prod&#8217;, which will only tell people you are running Apache. Others as you can see give more information about versions and O/S [...]]]></description>
			<content:encoded><![CDATA[<p>If you want to give away less information about your current version of Apache, then you can use the ServerTokens directive in the config file (httpd.conf). The recommended one for Production servers is &#8216;Prod&#8217;, which will only tell people you are running Apache. Others as you can see give more information about versions and O/S which may make it easier for attackers.</p>
<p>Your httpd.conf file should look something like this:</p>
<pre>
#
# Don't give away too much information about all the subcomponents
# we are running.  Comment out this line if you don't mind remote sites
# finding out what major optional modules you are running
ServerTokens OS
</pre>
<p>Change it to look like this</p>
<pre>#
# Don't give away too much information about all the subcomponents
# we are running.  Comment out this line if you don't mind remote sites
# finding out what major optional modules you are running
ServerTokens Prod
</pre>
<h2>ServerTokens</h2>
<p>This directive controls whether Server response header field which is sent back to clients includes a description of the generic OS-type of the server as well as information about compiled-in modules.</p>
<pre>ServerTokens Prod[uctOnly]
Server sends (e.g.):
Server:       Apache

ServerTokens Min[imal]
Server sends (e.g.):
Server:       Apache/1.3.0

ServerTokens OS
Server sends (e.g.):
Server: Apache/1.3.0       (Unix)

ServerTokens Full (or not specified)
Server sends (e.g.):
Server: Apache/1.3.0       (Unix) PHP/3.0 MyMod/1.2</pre>
<h2>Notes</h2>
<p>This setting applies to the entire server, and cannot be enabled or disabled on a virtualhost-by-virtualhost basis.</p>
<p>ServerTokens is     only available in Apache 1.3 and later; the ProductOnly keyword is only available in versions     later than 1.3.12</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/01/masking-your-apache-information-with-servertokens/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
