LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Feedback/Feature Requests > security

Reply
 
Thread Tools Display Modes
  #1  
Old 11-29-2005, 01:46 AM
Dani Dani is offline
Senior Member
 
Join Date: Nov 2005
Posts: 92
Default security

Hi,

great job with the server. My friend recommended me to change and oh did it perform as the benchmarks say. The load is about 60% lower if not more some times. The speed has increased with about 50% of before 'havent had time to play with the tuning yet'.

But have a question for the default 404, 403 etc files..

the line "Powered By LiteSpeed Web Server
Lite Speed Technologies is not responsible for administration and contents of this web site!" gets added to the bottom. Is there a way to hide the server info for security reasons? "except using cutom 404 error pages which seem to have a bug when using it on the 401 error...
Reply With Quote
  #2  
Old 11-29-2005, 08:11 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Thank you for your praise.

Which error page has problem? 403 or 401?
Reply With Quote
  #3  
Old 11-29-2005, 08:17 AM
Dani Dani is offline
Senior Member
 
Join Date: Nov 2005
Posts: 92
sorry for confusing you =) 401 gives error. for example I had a realm check on a statis link but it never reached it. I only got to the custom 401 error instead of being asked for the password. When I removed the 401 it worked without any problems.

but is it possible to hide the servername like in apache or is this embedded somehow?
Reply With Quote
  #4  
Old 11-29-2005, 10:29 AM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
OK, I see.

That's due to how custom error pages was handled. The information about authentication realm was lost.

We can't fix it right now, however, there is a work around though, set the customized error page to a URL under your protected context.
Reply With Quote
  #5  
Old 10-12-2007, 12:31 PM
jnrey jnrey is offline
Member
 
Join Date: Aug 2007
Posts: 17
Default Cust Redirect still displays Powered By LiteSpeed Web Server

For security reasons I would like to hide the name of the Server. I have customized 404 and 503 pages, to no avail; it still displays "Powered By LiteSpeed Web Server Lite Speed Technologies is not responsible for administration and contents of this web site!". Is there any way to hide all this ?

Many thanks !
Reply With Quote
  #6  
Old 10-13-2007, 12:55 AM
brrr brrr is offline
Senior Member
 
Join Date: Aug 2007
Posts: 94
I think the ability to hide the 'Powered by LSWS' etc only comes with the Enterprise version.
Reply With Quote
  #7  
Old 10-13-2007, 04:09 AM
jnrey jnrey is offline
Member
 
Join Date: Aug 2007
Posts: 17
Well got the trial enterprise version so far, but did not see it. Can this be confirmed by anyone ?
Reply With Quote
  #8  
Old 10-13-2007, 06:44 PM
brrr brrr is offline
Senior Member
 
Join Date: Aug 2007
Posts: 94
Doesn't:
Configuration > Server > General > General Settings > Server Signature > Hide Full Header

do it?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security vulnerability in Ruby's CGI could cause DoS on LS servers subBlue Bug Reports 1 10-28-2006 01:27 PM
security: possible to hide that the server is litespeed? apachesux Install/Configuration 5 01-03-2006 02:49 PM
CGI Security zoom Install/Configuration 4 12-23-2005 01:47 PM
Security Question zoom Install/Configuration 5 12-02-2005 09:20 AM
"Context Access Control" in vhost security section ts77 Install/Configuration 2 03-14-2005 01:19 AM


All times are GMT -7. The time now is 02:42 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.