A Server Hardening Checklist

Stock Ubuntu 225 Apache 129 announces its version, signs error pages and passes backend banners through. The first three settings are in /etc/apache2/conf-available/security.conf; put the rest in a file of your own and enable it with a2enconf:

Server-wide hardening, with Ubuntu 26.04's defaults
Setting Ubuntu default Effect
ServerTokens Prod OS Server: Apache, no version
ServerSignature Off On no footer on error pages
TraceEnable Off already Off TRACE answers 405
Header unset X-Powered-By not set hides backend versions
Security headers not set Security Headers and CORS
Deny .git, .svn, .hg not set Protecting Sensitive Files
Timeout 60, LimitRequestBody 300 s, 1 GiB slow clients, uploads
The proxied page's headers, before and after the hardeningShell
curl -sI http://127.0.0.1:8103/app/ | grep -iE '^(server|x-powered|x-content|x-frame|referrer)'
Output
Server: Apache/2.4.66 (Ubuntu)
X-Powered-By: PHP/8.5.4
...
Server: Apache
X-Content-Type-Options: nosniff
X-Frame-Options: SAMEORIGIN
Referrer-Policy: strict-origin-when-cross-origin

Error pages also lost their <address>Apache/2.4.66 (Ubuntu) Server at 127.0.0.1 Port 8103</address> footer, and /.git/config answered 403. Hiding the version fixes nothing, but it keeps you off scanners' version lists. Also disable unused modules (Modules) and patch automatically (Security Updates).

ModSecurity 9,785 , the open-source web application firewall now run by OWASP, checks requests against the OWASP Core Rule Set (CRS). Ubuntu ships 2.9.12 (libapache2-mod-security2) and CRS 3.3.8; upstream is at 2.9.14 and CRS 4.29.0. With SecRuleEngine On (the package default is DetectionOnly), ?id=17 got 200, while ?id=1' OR '1'='1 and ?q=<script>alert(1)</script> got 403 with rule 949110, "Inbound Anomaly Score Exceeded". Run DetectionOnly for a week and tune exclusions first. A Hardening Block for Any Site is the per-directory version of this list.