Disable X-Powered-By HTTP Header and Rename the Server Value for all Connectors
Scanned 9/3/2026
Install to Claude Code
npx -y skills add CyberStrikeus/CyberStrike --skill cis-tomcat7-v100-2.4 --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Cis Tomcat7 V100 2.4?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-tomcat7-v100-2-4)More formats (shields.io, HTML) on the badges page.
---
name: cis-tomcat7-v100-2.4
description: "Disable X-Powered-By HTTP Header and Rename the Server Value for all Connectors"
category: cis-tomcat
version: "1.0.0"
author: cyberstrike-official
tags: [cis, tomcat, tomcat-7, information-disclosure]
cis_id: "2.4"
cis_benchmark: "CIS Apache Tomcat 7 Benchmark v1.0.0"
tech_stack: [tomcat, java]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---
# CIS Apache Tomcat 7 - 2.4 Disable X-Powered-By HTTP Header and Rename the Server Value for all Connectors (Scored)
## Profile Applicability
- Level 1
## Description
Disable X-Powered-By HTTP Header and Rename the Server Value for all Connectors
## Rationale
See CIS Apache Tomcat 7 Benchmark v1.0.0 for detailed rationale.
## Audit Procedure
Refer to CIS Apache Tomcat 7 Benchmark v1.0.0 Section 2.4 for audit commands.
## Remediation
Refer to CIS Apache Tomcat 7 Benchmark v1.0.0 Section 2.4 for remediation steps.
## References
- CIS Apache Tomcat 7 Benchmark v1.0.0
## Assessment Status
- **Scored**
- **Profile**: Level 1
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.
Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.
Team Mode security research skill. Orchestrates 3 vulnerability hunters and 2 PoC engineers to audit a codebase in parallel, prove exploitability, classify root causes, and calibrate severity by actual exploitability. Use for security review, vulnerability research, exploitability audit, pre-release security check, threat model validation, and `/security-research`. Triggers: 'security-research', 'security research', 'security review', 'vulnerability audit', 'exploitability audit', '보안 리뷰', '취...
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。