Stock Ubuntu 225 Apache 129 announces its version, signs error pages and passes backend banners through. The first three settings are in /etc/apache2/conf-available/security.conf; put the rest in a file of your own and enable it with a2enconf:
| Setting | Ubuntu default | Effect |
|---|---|---|
| ServerTokens Prod | OS | Server: Apache, no version |
| ServerSignature Off | On | no footer on error pages |
| TraceEnable Off | already Off | TRACE answers 405 |
| Header unset X-Powered-By | not set | hides backend versions |
| Security headers | not set | Security Headers and CORS |
| Deny .git, .svn, .hg | not set | Protecting Sensitive Files |
| Timeout 60, LimitRequestBody | 300 s, 1 GiB | slow clients, uploads |
curl -sI http://127.0.0.1:8103/app/ | grep -iE '^(server|x-powered|x-content|x-frame|referrer)'Server: Apache/2.4.66 (Ubuntu) X-Powered-By: PHP/8.5.4 ... Server: Apache X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Referrer-Policy: strict-origin-when-cross-origin
Error pages also lost their <address>Apache/2.4.66 (Ubuntu) Server at 127.0.0.1 Port 8103</address> footer, and /.git/config answered 403. Hiding the version fixes nothing, but it keeps you off scanners' version lists. Also disable unused modules (Modules) and patch automatically (Security Updates).
ModSecurity 9,785 , the open-source web application firewall now run by OWASP, checks requests against the OWASP Core Rule Set (CRS). Ubuntu ships 2.9.12 (libapache2-mod-security2) and CRS 3.3.8; upstream is at 2.9.14 and CRS 4.29.0. With SecRuleEngine On (the package default is DetectionOnly), ?id=17 got 200, while ?id=1' OR '1'='1 and ?q=<script>alert(1)</script> got 403 with rule 949110, "Inbound Anomaly Score Exceeded". Run DetectionOnly for a week and tune exclusions first. A Hardening Block for Any Site is the per-directory version of this list.