Tomcat服务在响应404/500等网络错误时,默认会将当前版本信息显示出来,这样就造成了中间件版本信息泄露这样的漏洞
方案一:修改版本号
1.进入Tomcat下的lib目录,备份catalina.jar文件后,解压该文件
cd tomcat/lib
cp catalina.jar catalina.jar.bak
unzip catalina.jar
2.解压后,通过vi编辑器修改解压出来的ServerInfo.properties文件(在/org/apache/catalina/util/下)
vim org/apache/catalina/util/ServerInfo.properties
3.去除ServerInfo.properties文件的版本信息
server.info=ApacheTomcat
server.number=0.0.0.0
server.built=Nov 72016 20:05:27 UTC
4.将修改后的文件压缩回catalina.jar包中
jar uvf catalina.jar org/apache/catalina/util/ServerInfo.properties
5.重启Tomcat服务,访问不存在的页面进行404报错验证,看是否还显示中间件版本号
方案二:自定义错误页面替换默认页面
1.进入Tomcat的conf目录,修改web.xml,在标签前添加如下内容
<error-page>
<error-code>404</error-code>
<location>/error_404.html</location>
</error-page>
<error-page>
<error-code>400</error-code>
<location>/error_404.html</location>
</error-page>
<error-page>
<error-code>500</error-code>
<location>/error_404.html</location>
</error-page>
<error-page>
<error-code>501</error-code>
<location>/error_404.html</location>
</error-page>
2.进入Tomcat的webapps/ROOT目录,新增error_404.html页面,使用自定义页面已达到隐藏中间件版本信息的目的
3.针对400错误需要单独处理
3.1创建一个web项目,创建类并继承ErrorReportValve
package com.java.report;
import java.io.BufferedWriter;
import java.io.IOException;
import java.io.OutputStreamWriter;
import java.util.logging.Logger;
import org.apache.catalina.connector.Request;
import org.apache.catalina.connector.Response;
import org.apache.catalina.valves.ErrorReportValve;
public class CustomErrorReportValve extends ErrorReportValve {
// Create a simple logger
Logger log = Logger.getLogger(CustomErrorReportValve.class.getName());
@Override
protected void report(Request request, Response response, Throwable t) {
try {
// Write a more friendly, less technical message to the user
BufferedWriter out = new BufferedWriter(new OutputStreamWriter(response.getOutputStream()));
out.write("<html><head><title>Oops</title><body>");
out.write("<h1>Oops</h1>");
out.write("<p>Well, that didn't go as we had expected.</p>");
out.write("<p>Don't worry though, we're working on it.</p>");
out.write("</body></html>");
out.close();
// Log the error with your favorite logging framework...
log.severe("Uncaught throwable was thrown: " + t.getMessage());
} catch (IOException e) {
e.printStackTrace();
}
}
}
3.2 项目右键导出jar包tomcat-error-report.jar
3.3 把jar包放到lib下,
3.4 配置errorReportValveClass
修改server.xml,在host里配置
<Host errorReportValveClass="com.java.report.CustomErrorReportValve" />
3.5重启Tomcat服务
errer_404.html:https://download.csdn.net/download/javaL_X/85115283
tomcat-error-report.jar:https://download.csdn.net/download/javaL_X/85115444