Guides

Findings we actually hit, and what to do about them

Most security write-ups end at "remove it." That's fine until you're the one whose reverse proxy stops routing, or whose control panel dies two minutes after you follow the advice.

These are field notes from real production servers - including our own. Each one covers the same four things: what the finding means, why it's worse than it looks, why you often can't just delete it, and what to do instead.

Rather just find out what's on yours?

Every finding in these guides is something owlzops-mapper detects. It's a single static binary, read-only, and nothing leaves your server. Run it and read the output - we're not in the room.