Ravindra BagaleCourses & study guides Track your progress

Labs · Cyber Security

Lab: Install Nginx on Your Server, Hide the Version Number and Test Every Config Change with nginx -t

Beginner35 minYour EC2 Amazon Linux 2023 server · SSH · curl

Course: Cyber Security · Chapter 7: Apache and Nginx: Install and Understand

Chapter 7 installs Apache and Nginx; this lab adds the first two safety habits.

Chala mitrano! A web server that announces its exact version is like a shop that writes "old lock, model 2019" on the door. Today we install Nginx, hide that label, and learn the most important habit: test the config before every reload. Chala suru karuya!

Suppose we are…

Suppose we are a web-ops trainee at Nykaa. Before a sale, the team adds new Nginx settings every day. One wrong semicolon can take the whole site down during the sale, and an old version number in every response tells attackers which known bugs to try. So the team has two rules: hide the version and always run nginx -t before reload.

Goal of this lab

By the end you will have:

  • Nginx installed, running and starting on boot.
  • The Server: nginx/1.x.x header changed to just Server: nginx.
  • The habit sudo nginx -t && sudo systemctl reload nginx, and you will have seen what nginx -t does with a broken config.

What you need (all free)

  • Your own free-tier EC2 Amazon Linux 2023 server (Lab 4), with an inbound rule HTTP, TCP 80, My IP.
  • 30–35 minutes.

Safety and ethics

Do this on your own server only. Allow port 80 from My IP while practising. Terminate the server after the lab if you do not need it for the next one.

Steps

  1. SSH to the server and install Nginx:

    sudo dnf install -y nginx
    sudo systemctl enable --now nginx
    systemctl status nginx --no-pager
    

    What you should see: Active: active (running) in green.

  2. In the EC2 console add an inbound rule to the security group: Type HTTP, Source My IP. Open http://<your-server-ip> in your browser.

    What you should see: the Nginx welcome page.

  3. Look at the response headers from your laptop (or on the server with localhost):

    curl -I http://localhost
    

    What you should see: HTTP/1.1 200 OK and Server: nginx/1.24.0 (your number may differ). That version is the leak.

  4. Make a backup of the main config before editing:

    sudo cp /etc/nginx/nginx.conf /etc/nginx/nginx.conf.bak
    
  5. Open it with sudo nano /etc/nginx/nginx.conf. Inside the http { block, just under the line http {, add:

    server_tokens off;
    

    Save with Ctrl + O, Enter, and exit with Ctrl + X.

  6. Test the config, and reload only if the test passes:

    sudo nginx -t && sudo systemctl reload nginx
    

    What you should see: syntax is ok and test is successful.

  7. Check again with curl -I http://localhost.

    What you should see: Server: nginx with no version number.

  8. Now see why nginx -t matters. Open the file again and delete the semicolon after server_tokens off. Save, then run step 6 again.

    What you should see: nginx: [emerg] ... unexpected "}" (or similar) and test failed. Because of &&, the reload did not run, so the website stayed up.

  9. Put the semicolon back, run step 6 again, and confirm it passes.

  10. Also check that an error page no longer shows the version: curl http://localhost/does-not-exist shows <center>nginx</center> with no number.

Ravindra Bagale's Tip

Hiding the version is not a replacement for updating. Attackers can still guess. The real protection is sudo dnf upgrade --refresh every week. Hide the label and change the old lock. Donhi pahije!

Common mistakes

Mistake What happens Fix
Putting server_​tokens off; outside the http {} block nginx -t fails: directive is not allowed here Put it inside http {
Running systemctl restart without testing A typo stops the website Always sudo nginx -​t && sudo systemctl reload nginx
No HTTP rule in the security group Browser keeps loading and times out Add HTTP 80 from My IP
Editing without a backup Hard to undo a mistake cp nginx.​conf nginx.​conf.​bak first
Thinking hidden version = secure Old bugs stay Update packages regularly

Self-check checklist

0 of 5 done

Try-at-home challenge

Find the exact line number where Nginx includes the extra config files from conf.d, and explain why you might put your own settings there instead of in nginx.conf.

Check your answer

Run grep -n "include" /etc/nginx/nginx.conf. You will see include /etc/nginx/conf.d/*.conf; inside the http block. Putting your settings in a small file such as /etc/nginx/conf.d/security.conf keeps them separate, easy to review, and safe from being overwritten when the package updates nginx.conf.

Clean up to avoid charges

If you are doing Lab 8 next, keep the server running. Otherwise: EC2 → Instances → select the server → Instance state → Terminate (delete) instance.

Samjla ka? Hide the version, back up first, and nginx -t before every reload. Aata pudhe jaauya: Chapter 8 hosts our own website on this Nginx.