{"id":1279,"date":"2017-03-24T17:05:49","date_gmt":"2017-03-24T11:35:49","guid":{"rendered":"https:\/\/pheonixsolutions.com\/blog\/?p=1279"},"modified":"2026-09-12T18:18:44","modified_gmt":"2026-09-12T12:48:44","slug":"hide-webserver-informationmodify-server-header-nginx","status":"publish","type":"post","link":"https:\/\/pheonixsolutions.com\/blog\/hide-webserver-informationmodify-server-header-nginx\/","title":{"rendered":"How to Hide Webserver Information and Modify the Server Header on Nginx"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">By default, Nginx may expose webserver version information through the HTTP response headers. Depending on the configuration, this can also reveal information about the underlying operating system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Exposing detailed server information is generally not recommended because it provides attackers with additional information about the server environment and may help them identify potential vulnerabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we will explain how to hide the Nginx version and modify the <code>Server<\/code> response header.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Prerequisites<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before proceeding, make sure you have:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>An Ubuntu or CentOS server.<\/li>\n\n\n\n<li>Root or sudo access to the server.<\/li>\n\n\n\n<li>Nginx installed and configured.<\/li>\n\n\n\n<li>Basic knowledge of Nginx configuration.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If Nginx is not installed, refer to the appropriate installation guide:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/pheonixsolutions.com\/blog\/install-nginx-php-mariadb-ubuntu-16-04-1\/\">Install Nginx on Ubuntu<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/pheonixsolutions.com\/blog\/install-nginx-php-fpm-mariadb-on-centos-7\/\">Install Nginx, PHP-FPM and MariaDB on CentOS 7<\/a><\/li>\n<\/ul>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Note:<\/strong> The configuration described in this article was tested on Ubuntu. The <code>more_set_headers<\/code> directive requires the Nginx headers-more module, which may need to be installed separately depending on your Nginx package.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Implementation<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Step 1: Install the Required Nginx Package<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">On Ubuntu, install <code>nginx-extras<\/code>:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">apt-get -y install nginx-extras<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>nginx-extras<\/code> package provides additional Nginx modules, including the functionality required for the <code>more_set_headers<\/code> directive.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 2: Check the Current Server Information<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before making any changes, check whether Nginx is exposing its version information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Run:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">curl -I http:\/\/IPaddress<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">You may see output similar to:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">HTTP\/1.1 301 Moved Permanently<br>Server: nginx\/1.10.0 (Ubuntu)<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>Server<\/code> header reveals both the Nginx version and operating system information.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Step 3: Modify the Nginx Configuration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Open the Nginx configuration file:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">vi \/etc\/nginx\/nginx.conf<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Under the <code>http<\/code> section, add or modify the following configuration:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">server_tokens off;<br>more_set_headers 'Server: PheonixSolutions';<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>server_tokens off;<\/code> directive prevents Nginx from including its version number in the <code>Server<\/code> header.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>more_set_headers<\/code> directive allows you to replace the default <code>Server<\/code> header with a custom value.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">http {<br>    server_tokens off;<br>    more_set_headers 'Server: PheonixSolutions';<br><br>    ...<br>}<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 4: Test the Nginx Configuration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Before restarting Nginx, check the configuration for syntax errors:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">nginx -t<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">A successful configuration test should return:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">syntax is ok<br>test is successful<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 5: Restart Nginx<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Restart the Nginx service:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">service nginx restart<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Alternatively, on systems using systemd:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">systemctl restart nginx<\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Step 6: Verify the Server Header<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Run the same <code>curl<\/code> command again:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">curl -I http:\/\/IPaddress<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The response should now contain a custom <code>Server<\/code> header similar to:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">HTTP\/1.1 301 Moved Permanently<br>Server: PheonixSolutions<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The Nginx version and operating system information are no longer exposed in the response header.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">By default, Nginx can expose server version information through HTTP response headers. Disabling <code>server_tokens<\/code> helps prevent Nginx from revealing its version, while the <code>headers-more<\/code> module can be used to customize the <code>Server<\/code> header.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Although hiding server information is not a complete security solution, reducing unnecessary information disclosure is a useful security hardening practice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAQs<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">1. Why should I hide the Nginx version?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Exposing the Nginx version provides unnecessary information about the server and may help attackers identify vulnerabilities associated with a particular version.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. What does <code>server_tokens off<\/code> do?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The <code>server_tokens off;<\/code> directive prevents Nginx from displaying its version number in the <code>Server<\/code> response header.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Does <code>server_tokens off<\/code> completely remove the Server header?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">No. It normally hides the version information but does not remove the <code>Server<\/code> header itself.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Related Article<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/install-nginx-on-cpanel-using-engintron\/\">Install Nginx on cPanel Using Engintron (Step-by-Step Guide)<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/pheonixsolutions.com\/blog\/how-to-install-and-configure-php-with-nginx-on-centos7\/\">How to install and configure PHP with Nginx on centos7 \u2013 Pheonix Solutions<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Talk to our experts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Have a technology challenge or looking for the right solution for your business? Our team can help you with&nbsp;<strong>cloud, DevOps, development, infrastructure, design, and more<\/strong>. Feel free to reach out to our experts&nbsp;<a href=\"https:\/\/pheonixsolutions.com\/contact\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction By default, Nginx may expose webserver version information through the HTTP response headers. Depending on the configuration, this can [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[1022],"tags":[271,307,159],"class_list":["post-1279","post","type-post","status-publish","format-standard","hentry","category-web-architecture","tag-nginx","tag-security","tag-webserver","psol-cat-web-architecture"],"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/phn2x7-kD","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/1279","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/comments?post=1279"}],"version-history":[{"count":1,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/1279\/revisions"}],"predecessor-version":[{"id":11730,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/posts\/1279\/revisions\/11730"}],"wp:attachment":[{"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/media?parent=1279"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/categories?post=1279"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pheonixsolutions.com\/blog\/wp-json\/wp\/v2\/tags?post=1279"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}