In this section, let's shed some light on common mistakes observed on a web server. We will also discuss some points to harden the web server:
- Always hide your server signature.
- If possible, set a fake server signature to mislead attackers.
- Handle the errors.
- If possible, use a virtual environment (jailing) to run the application.
- Try to hide the programming language page extensions, because it will be difficult for the attacker to see the programming language of the web applications.
- Update the web server with the latest patch from the vendor. It avoids any chance of exploitation of the web server. The server can at least be secured for known vulnerabilities.
- Don't use a third-party patch to update the web server. A third-party patch may contain trojans or viruses.
- Do not install other applications on the web server. If you install an OS,...