Mask Nginx version details from the HTTP Response Header.
In default NGINX configuration, Server header banner is ON which exposes what version of Nginx you are using.
This is considered as information leakage vulnerability.
If you are working on auditing or fixing a security issue, then you will be asked to get rid of a version as part of hardening & security.
- Go to nginx/conf folder
- Take a backup of configuration file
- Add following in nginx.conf under server section
- Restart Nginx web server
You can use online tool Header Checker or developer tools inbuilt in the browser to examine the header.
As you can see, no more version is shown.
I hope this helps and if you are looking to learn Nginx then check out this course by Ray Viljoen.