Hello EveryOne,

VAPT i.e. Vulnerability assessment and penetration testing, disabling HTTP methods. For the security purposes VAPT is done to restrict site or application server i.e Jboss from hackers.

I have received many emails for blog on VAPT . So, Lets start with how to disable the HTTP Methods i.e disabling TRACE, DELETE, PUT OPTION and Only required HTTP Methods are GET and POST

OPTIONS is not really vulnerability but since there is no real use for it and ideally should be disabled.

Below Configuration need to be added outside the <VirtualHost> of the Apache configuration .

<Location />

<LimitExcept GET POST>

order deny,allow

deny from all



Test :

# telnet 80


 Connected to

 Escape character is ‘^]’.


 Host:   ==> hit enter twice

This way, we can disable the HTTP methods and its tried and tested !!!

Happy Learning !!!

