# Change some HTTP Header parameters

**URL:** <https://community.wowza.com/t/change-some-http-header-parameters/55510>\
**Category:** Wowza Streaming Engine\
**Tags:** security\
**Created:** [July 3, 2020, 8:56am UTC](https://community.wowza.com/t/change-some-http-header-parameters/55510 "2020-07-03T08:56:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mike\_Breiter](https://avatars.discourse-cdn.com/v4/letter/m/a88e4f/32.png) [@Mike\_Breiter](https://community.wowza.com/u/Mike_Breiter)\
**Post date:** [July 3, 2020, 8:56am UTC](https://community.wowza.com/t/change-some-http-header-parameters/55510/1 "2020-07-03T08:56:27Z")

</div>

Hi,

I’m trying to learn how to harden Wowza Streaming Engine from a security perspective,

There is one thing I could not find any solution for,

When user or attacker, monitor received chunks or playlists, in **HTTP Response Header** , he will find out ServerName with correct engine name and version,

```auto
Server:WowzaStreamingEngine/4.8.5

```

Is it possible to modify or change values from configurations to prevent detection?

---

<div class="post-metadata">

**Author:** ![Karel\_Boek](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/karel_boek/32/454_2.png) [@Karel\_Boek](https://community.wowza.com/u/Karel_Boek)\
**Post date:** [July 4, 2020, 12:30pm UTC](https://community.wowza.com/t/change-some-http-header-parameters/55510/2 "2020-07-04T12:30:52Z")

</div>

You can write a custom Application module and override the Server parameter in the onHTTPSessionCreate method.

```auto
package mypackage;

public class MyModule extends ModuleBase {
  public void onHTTPSessionCreate(IHTTPStreamerSession httpSession) {
    httpSession.setUserHTTPHeader("Server", "ItsASecret");
  }
}

```

---

<div class="post-metadata">

**Author:** ![Mike\_Breiter](https://avatars.discourse-cdn.com/v4/letter/m/a88e4f/32.png) [@Mike\_Breiter](https://community.wowza.com/u/Mike_Breiter)\
**Post date:** [July 5, 2020, 6:37am UTC](https://community.wowza.com/t/change-some-http-header-parameters/55510/3 "2020-07-05T06:37:57Z")

</div>

thank you @Karel Boek-Senior Consultant

Is it possible to add this code to the current “conf/vod/Application.xml”?

any guide will be helpful but for a non-programmer person

---

<div class="post-metadata">

**Author:** ![Karel\_Boek](https://sea2.discourse-cdn.com/flex002/user_avatar/community.wowza.com/karel_boek/32/454_2.png) [@Karel\_Boek](https://community.wowza.com/u/Karel_Boek)\
**Post date:** [July 5, 2020, 8:48am UTC](https://community.wowza.com/t/change-some-http-header-parameters/55510/4 "2020-07-05T08:48:56Z")

</div>

@Mike Breiter, you must create a custom module and add the code above; then add the reference to the compiled version of the module to your Application.xml. For more information on how to create a custom module, see [https://www.wowza.com/blog/building-modules-why-they-matter](https://www.wowza.com/blog/building-modules-why-they-matter)

If you want to hire someone to create that module for you, you can post a request in [https://www.wowza.com/community/spaces/26/find-a-consultant.html](https://www.wowza.com/community/spaces/26/find-a-consultant.html)
