Labs · Cyber Security
Lab: Install Nginx on Your Server, Hide the Version Number and Test Every Config Change with nginx -t
Course: Cyber Security · Chapter 7: Apache and Nginx: Install and Understand
Chapter 7 installs Apache and Nginx; this lab adds the first two safety habits.
Chala mitrano! A web server that announces its exact version is like a shop that writes "old lock, model 2019" on the door. Today we install Nginx, hide that label, and learn the most important habit: test the config before every reload. Chala suru karuya!
चला मित्रांनो! आपलं exact version सांगणारा web server म्हणजे दरवाज्यावर "जुनं कुलूप, model 2019" लिहिलेलं दुकान. आज आपण Nginx install करणार, ते label लपवणार, आणि सगळ्यात महत्त्वाची सवय शिकणार: प्रत्येक reload आधी config test. चला सुरू करूया!
चलो दोस्तों! अपना exact version बताने वाला web server ऐसा है जैसे दुकान के दरवाज़े पर "पुराना ताला, model 2019" लिखा हो। आज हम Nginx install करेंगे, वो label छुपाएँगे, और सबसे ज़रूरी आदत सीखेंगे: हर reload से पहले config test। चलो शुरू करते हैं!
Suppose we are…
Suppose we are a web-ops trainee at Nykaa. Before a sale, the team adds new Nginx settings every day. One wrong semicolon can take the whole site down during the sale, and an old version number in every response tells attackers which known bugs to try. So the team has two rules: hide the version and always run nginx -t before reload.
Goal of this lab
By the end you will have:
- Nginx installed, running and starting on boot.
- The
Server: nginx/1.x.xheader changed to justServer: nginx. - The habit
sudo nginx -t && sudo systemctl reload nginx, and you will have seen whatnginx -tdoes with a broken config.
What you need (all free)
- Your own free-tier EC2 Amazon Linux 2023 server (Lab 4), with an inbound rule HTTP, TCP 80, My IP.
- 30–35 minutes.
Safety and ethics
Do this on your own server only. Allow port 80 from My IP while practising. Terminate the server after the lab if you do not need it for the next one.
Steps
-
SSH to the server and install Nginx:
sudo dnf install -y nginx sudo systemctl enable --now nginx systemctl status nginx --no-pagerWhat you should see:
Active: active (running)in green. -
In the EC2 console add an inbound rule to the security group: Type HTTP, Source My IP. Open
http://<your-server-ip>in your browser.What you should see: the Nginx welcome page.
-
Look at the response headers from your laptop (or on the server with
localhost):curl -I http://localhostWhat you should see:
HTTP/1.1 200 OKandServer: nginx/1.24.0(your number may differ). That version is the leak. -
Make a backup of the main config before editing:
sudo cp /etc/nginx/nginx.conf /etc/nginx/nginx.conf.bak -
Open it with
sudo nano /etc/nginx/nginx.conf. Inside thehttp {block, just under the linehttp {, add:server_tokens off;Save with Ctrl + O, Enter, and exit with Ctrl + X.
-
Test the config, and reload only if the test passes:
sudo nginx -t && sudo systemctl reload nginxWhat you should see:
syntax is okandtest is successful. -
Check again with
curl -I http://localhost.What you should see:
Server: nginxwith no version number. -
Now see why
nginx -tmatters. Open the file again and delete the semicolon afterserver_tokens off. Save, then run step 6 again.What you should see:
nginx: [emerg] ... unexpected "}"(or similar) andtest failed. Because of&&, the reload did not run, so the website stayed up. -
Put the semicolon back, run step 6 again, and confirm it passes.
- Also check that an error page no longer shows the version:
curl http://localhost/does-not-existshows<center>nginx</center>with no number.
Ravindra Bagale's Tip
Hiding the version is not a replacement for updating. Attackers can still guess. The real protection is sudo dnf upgrade --refresh every week. Hide the label and change the old lock. Donhi pahije!
Ravindra Bagale's Tip – मराठी
Version लपवणं म्हणजे update करण्याला पर्याय नाही. Attackers अजूनही guess करू शकतात. खरं protection म्हणजे दर आठवड्याला sudo dnf upgrade --refresh. Label लपवा आणि जुनं कुलूप बदला. दोन्ही पाहिजे!
Ravindra Bagale's Tip – हिंदी
Version छुपाना update करने का विकल्प नहीं है। Attackers फिर भी guess कर सकते हैं। असली protection है हर हफ्ते sudo dnf upgrade --refresh। Label छुपाओ और पुराना ताला बदलो। दोनों ज़रूरी हैं!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
Putting server_tokens off; outside the http {} block |
nginx -t fails: directive is not allowed here |
Put it inside http { |
Running systemctl restart without testing |
A typo stops the website | Always sudo nginx -t && sudo systemctl reload nginx |
| No HTTP rule in the security group | Browser keeps loading and times out | Add HTTP 80 from My IP |
| Editing without a backup | Hard to undo a mistake | cp nginx.conf nginx.conf.bak first |
| Thinking hidden version = secure | Old bugs stay | Update packages regularly |
Self-check checklist
0 of 5 done
Try-at-home challenge
Find the exact line number where Nginx includes the extra config files from conf.d, and explain why you might put your own settings there instead of in nginx.conf.
Check your answer
Run grep -n "include" /etc/nginx/nginx.conf. You will see include /etc/nginx/conf.d/*.conf; inside the http block. Putting your settings in a small file such as /etc/nginx/conf.d/security.conf keeps them separate, easy to review, and safe from being overwritten when the package updates nginx.conf.
Clean up to avoid charges
If you are doing Lab 8 next, keep the server running. Otherwise: EC2 → Instances → select the server → Instance state → Terminate (delete) instance.
Samjla ka? Hide the version, back up first, and nginx -t before every reload. Aata pudhe jaauya: Chapter 8 hosts our own website on this Nginx.