public inbox for ipfire-scm@lists.ipfire.org
 help / color / mirror / Atom feed
From: Michael Tremer <git@ipfire.org>
To: ipfire-scm@lists.ipfire.org
Subject: [git.ipfire.org] IPFire 2.x development tree branch, next, updated. e981b751d180982563fb8a76e63bddadb69a5bd8
Date: Fri, 18 Jun 2021 09:08:46 +0000	[thread overview]
Message-ID: <4G5tQ65ZNFz2xcm@people01.haj.ipfire.org> (raw)

[-- Attachment #1: Type: text/plain, Size: 2284 bytes --]

This is an automated email from the git hooks/post-receive script. It was
generated because a ref change was pushed to the repository containing
the project "IPFire 2.x development tree".

The branch, next has been updated
       via  e981b751d180982563fb8a76e63bddadb69a5bd8 (commit)
      from  270d7c0d3747d7124a66770ee729aa519b8ee847 (commit)

Those revisions listed above that are new to this repository have
not appeared on any other notification email; so we list those
revisions in full, below.

- Log -----------------------------------------------------------------
commit e981b751d180982563fb8a76e63bddadb69a5bd8
Author: Peter Müller <peter.mueller(a)ipfire.org>
Date:   Fri Jun 18 09:07:21 2021 +0200

    proxy.cgi: Suppress Squid version by default
    
    While hiding version information does not come with any _actual_
    security improvements, it is generally a good thing to do so by default:
    Attackers will still be able to reasonably guess or enumerate the
    software version running, but need to conduct additional effort to do
    so, hence more likely raising alerts and drawing attention on their
    operation.
    
    In addition, we suppress version details somewhere else in IPFire 2.x by
    default, too (e. g. Unbound and Apache), so we can justify this patch by
    aiming to stay consistent, I guess. :-)
    
    Signed-off-by: Peter Müller <peter.mueller(a)ipfire.org>
    Signed-off-by: Michael Tremer <michael.tremer(a)ipfire.org>

-----------------------------------------------------------------------

Summary of changes:
 html/cgi-bin/proxy.cgi | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Difference in files:
diff --git a/html/cgi-bin/proxy.cgi b/html/cgi-bin/proxy.cgi
index 78ad33ad2..1b949d5b6 100644
--- a/html/cgi-bin/proxy.cgi
+++ b/html/cgi-bin/proxy.cgi
@@ -188,7 +188,7 @@ $proxysettings{'ADMIN_MAIL_ADDRESS'} = '';
 $proxysettings{'ADMIN_PASSWORD'} = '';
 $proxysettings{'ERR_LANGUAGE'} = 'en';
 $proxysettings{'ERR_DESIGN'} = 'ipfire';
-$proxysettings{'SUPPRESS_VERSION'} = 'off';
+$proxysettings{'SUPPRESS_VERSION'} = 'on';
 $proxysettings{'FORWARD_VIA'} = 'off';
 $proxysettings{'FORWARD_IPADDRESS'} = 'off';
 $proxysettings{'FORWARD_USERNAME'} = 'off';


hooks/post-receive
--
IPFire 2.x development tree

                 reply	other threads:[~2021-06-18  9:08 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4G5tQ65ZNFz2xcm@people01.haj.ipfire.org \
    --to=git@ipfire.org \
    --cc=ipfire-scm@lists.ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox