Disable Trace and Track for Better Security
The shared server on which I host Perishable Press was recently scanned by security software that revealed a significant security risk. Namely, the HTTP request methodsTRACE
and TRACK
were found to be enabled on my webserver. The TRACE
and TRACK
protocols are HTTP methods used in the debugging of webserver connections.
Although these methods are useful for legitimate purposes, they may compromise the security of your server by enabling cross-site scripting attacks (XST). By exploiting certain browser vulnerabilities, an attacker may manipulate the TRACE
and TRACK
methods to intercept your visitors’ sensitive data. The solution, of course, is disable these methods on your webserver.
The shared server on which I host Perishable Press was recently scanned by security software that revealed a significant security risk. Namely, the HTTP request methods
TRACE
and TRACK
were found to be enabled on my webserver. The TRACE
and TRACK
protocols are HTTP methods used in the debugging of webserver connections.
Although these methods are useful for legitimate purposes, they may compromise the security of your server by enabling cross-site scripting attacks (XST). By exploiting certain browser vulnerabilities, an attacker may manipulate the
TRACE
and TRACK
methods to intercept your visitors’ sensitive data. The solution, of course, is disable these methods on your webserver.How to disable the TRACE and TRACK methods
To disable TRACE
and TRACK
HTTP methods on your Apache-powered webserver, add the following directives to either your main configuration file or root HTAccess file:
RewriteEngine on
RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)
RewriteRule .* - [F]
These directives disable the TRACE
and TRACK
methods via the following process:
To disable
TRACE
and TRACK
HTTP methods on your Apache-powered webserver, add the following directives to either your main configuration file or root HTAccess file:RewriteEngine on
RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)
RewriteRule .* - [F]
These directives disable the
TRACE
and TRACK
methods via the following process:
No comments:
Post a Comment