如何隐藏ActiveMQ Broker在STOMP CONNECTED响应头中的版本信息?
If you're aiming to meet OWASP ASVS 14.3.3 by removing or obfuscating the ActiveMQ version from the STOMP CONNECTED message, there are two straightforward approaches depending on whether you want to hide the entire server header or just strip the version number.
Option 1: Hide the Entire server Header
You can configure the STOMP transport connector to omit the server field entirely by setting the serverName parameter to an empty string.
Configuration Steps:
- Open your ActiveMQ configuration file (usually
activemq.xmlin theconfdirectory). - Locate the
<transportConnectors>section and find the STOMP connector entry (typically named "stomp"). - Modify the connector's URI to include
serverName=(empty value):
<transportConnectors> <!-- Other connectors here --> <transportConnector name="stomp" uri="stomp://0.0.0.0:61613?serverName=" /> </transportConnectors>
- Alternatively, set this via a JVM system property when starting ActiveMQ:
-Dorg.apache.activemq.stomp.serverName=
- Restart the ActiveMQ Broker for changes to take effect.
After this, your CONNECTED message will no longer include the server header at all.
Option 2: Keep the Server Name but Remove the Version
If you want to retain the ActiveMQ identifier without exposing the version, set the serverName parameter to just "ActiveMQ".
Configuration Steps:
- Edit the STOMP transport connector in
activemq.xmlas follows:
<transportConnectors> <transportConnector name="stomp" uri="stomp://0.0.0.0:61613?serverName=ActiveMQ" /> </transportConnectors>
- Or use the JVM system property:
-Dorg.apache.activemq.stomp.serverName=ActiveMQ
- Restart the Broker.
Your CONNECTED message will now show server:ActiveMQ instead of server:ActiveMQ/5.15.9, effectively hiding the version while maintaining the server identifier.
Quick Notes:
- This works across most 5.x versions of ActiveMQ. For newer versions like Artemis, the configuration syntax may differ slightly, but the core idea of overriding the server header remains consistent.
- Always test changes in a staging environment first before applying to production to avoid unexpected behavior.
内容的提问来源于stack exchange,提问作者snieguu

