For security reasons, we decided to hide the nginx version number. If the version number is exposed, it is equivalent to telling someone about your vulnerability. Someone else can use the vulnerability exploitation program corresponding to this version to intrude into your background. Just as I know that your OS kernel version is 2.6.18 or I know your apache version, I can use the corresponding 0-day attack. Therefore, hiding the version number is also a good security protection measure.
Before the version number is hidden:
# Curl -- head www.nginx.org
HTTP/1.1 200 OK
Server: nginx/0.8.31
Date: Wed, 13 Jan 2010 06:17:30 GMT
Content-Type: text/html
Content-Length: 2341
Last-Modified: Mon, 11 Jan 2010 15:45:11 GMT
Connection: keep-alive
Keep-Alive: timeout = 15
Accept-Ranges: bytes
In this way, you can see that your nginx version is 0.8.31.
Can it be left blank?
Of course.
# Vi nginx. conf
Add server_tokens off in http;
Http {
... Omitted Configuration
Sendfile on;
Tcp_nopush on;
Keepalive_timeout 65;
Tcp_nodelay on;
Server_tokens off www.2cto.com;
... Omitted Configuration
}
Edit the php-fpm configuration file, such as fcgi. conf and fastcgi. conf (depending on the configuration file name)
Fastcgi_param SERVER_SOFTWARE nginx/$ nginx_version;
Change
Fastcgi_param SERVER_SOFTWARE nginx;
After nginx is reloaded, The nginx version is not displayed on pages such as 404 and 501.
After the version is hidden:
# Curl -- head 127.0.0.1
HTTP/1.1 200 OK
Server: nginx
Date: Wed, 13 Jan 2010 06:25:01 GMT
Content-Type: text/html
Content-Length: 793
Last-Modified: Sat, 12 Dec 2009 02:28:16 GMT
Connection: keep-alive
Accept-Ranges: bytes
Source: http://www.cssbeta.com/blog/post/108/