This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit


Revision as of 14:29, 21 November 2008 by Mjk303 (talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

Hardening the Apache HTTP Web Server

Remove pre-loaded modules

Remove pre-installed content

Don’t publicize names/versions of your running software

ServerSignature Off (Removes server information from error pages)

ServerTokens Prod (Removes server version from the HTTP header)

Comprehensive Checklists

“Securing Oracle Application Server”� by Caleb Sima

“Hardening Oracle Application Server 9i and 10g”� by Alexander Kornbrust