Project

General

Profile

Actions

Bug #14667

closed

Disable TRACE in Apache

Added by Brian Shaw about 8 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
External modules
Target version:
-
Difficulty:
trivial
Triaged:
Fixed in Releases:
Found in Releases:

Description

TRACE should be disabled in Apache per CERT Vulnerability Note VU#867593 (http://www.kb.cert.org/vuls/id/867593)

The attached patch file disables TRACE, ServerSignature, and minimizes ServerTokens to reduce the gathering of attack vector data in a production environment.


Files

httpd.conf-p0.patch httpd.conf-p0.patch 442 Bytes TRACE patch Brian Shaw, 04/15/2016 10:25 AM
Actions

Also available in: Atom PDF