Mengakatifkan module reqtimeout.conf pada apache.
# a2enmod headers
# a2enmod reqtimeout
Reqtimeout ini awalnya untuk mengurangi serangan seperti slowloris, maka dibuatlah module ini untuk menghalau serangan tersebut.
Biasanya module reqtimeout pada apache Debian 13 sudah aktif. Isi dari file bisa di lihat di /etc/apache2/mods-enabled/reqtimeout.conf
nano /etc/apache2/mods-enabled/reqtimeout.conf
# Wait max 20 seconds for the first byte of the request line+headers
# From then, require a minimum data rate of 500 bytes/s, but don't
# wait longer than 40 seconds in total.
# Note: Lower timeouts may make sense on non-ssl virtual hosts but can
# cause problem with ssl enabled virtual hosts: This timeout includes
# the time a browser may need to fetch the CRL for the certificate. If
# the CRL server is not reachable, it may take more than 10 seconds
# until the browser gives up.
RequestReadTimeout header=20-40,minrate=500
# Wait max 10 seconds for the first byte of the request body (if any)
# From then, require a minimum data rate of 500 bytes/s
RequestReadTimeout body=10,minrate=500
Kemudian restart apache jika ada perubahan pada file konfigurasi:
# systemctl reload apache2
Kemudian dilanjutkan dengan menambahkan pada /etc/apache2/apache2.conf
# nano /etc/apache2/apache2.conf
SSLProtocol -all +TLSv1.2 +TLSv1.3
Jika ada perubahan restart apache pada konfigurasi restart apache :
# systemctl reload apache2
Kemudian dilanjutkan lagi mendisable mod_info, dapat mengungkap informasi sensitif seperti path sistem, konfigurasi, nama database, bahkan informasi konfigurasi modul.
# a2dismod info
