Apache安全

十月 14th, 2009 Posted in 5.安全, Apache | 阅读次数: 216 次

制作:高进波
时间:2009-10-14

1.查看加载的模块
httpd -l

2.隐藏和伪装版本
vi httpd.conf
ServerSigature off
ServerTokens Prod

3.禁止访问文档根目录之外的任何文件
vi httpd.conf
<Directory/>
order deny,allow
deny from all
</Directory>

<Directory /var/www/html>
order allow,deny
allow from all
</Directory>

4.使用ModSecurity模块加固Apache
功能:
请求过滤
反检测绕过技术
HTTP过滤规则
完全审计记录
HTTP解释
CHROOT功能
掩盖WEB服务器标识

5.使用CIS的APACHE BENCHMARK对APACHE进行安全检测
benchmark.pl -c /etc/httpd/conf/httpd.conf -o result.html

完成!

相关日志:

3 Responses to “Apache安全”

  1. Resources Says:

    Interesting Article…

    [...]some interesting sites worth visitng. We recommend all our readers go and check these out[...]……


  2. insurance auto plan Says:

    Visitor recommendations…

    [...]one of our visitors recently recommended the following website[...]……


  3. healthy living and mood Says:

    Gems form the internet…

    [...]very few websites that happen to be detailed below, from our point of view are undoubtedly well worth checking out[...]……


留下您的脚印