Mod Security

ModSecurity is an Apache module that acts as an IDS/IPS embedded within the web server. Since it is a part of the web server itself, ModSecurity is able to analyze encrypted HTTPS traffic, or compressed content, after the web server has decrypted or decompressed it.

The ModSecurity directive, SecServerSignature, can be used to alter the HTTP Server header either to be empty to minimize information leakage or to contain false information to mislead an attacker. For example, an Apache web server containing the mod_security module could be configured with the following directive:

SecServerSignature "Microsoft-IIS/5.0"

It should be noted that this won't necessarily stop an attacker from fingerprinting your web server because default files, error messages, or headers may still reveal that the system is running an Apache web server. This type of information can also be captured by ModSecurity by pattern matching words and sentences that you do not want leaked through the web application or web server.

