Apache安全
制作:高进波
时间:2009-10-14
1.查看加载的模块
httpd -l
2.隐藏和伪装版本
vi httpd.conf
ServerSigature off
ServerTokens Prod
3.禁止访问文档根目录之外的任何文件
vi httpd.conf
<Directory/>
order deny,allow
deny from all
</Directory>
<Directory /var/www/html>
order allow,deny
allow from all
</Directory>
4.使用ModSecurity模块加固Apache
功能:
请求过滤
反检测绕过技术
HTTP过滤规则
完全审计记录
HTTP解释
CHROOT功能
掩盖WEB服务器标识
5.使用CIS的APACHE BENCHMARK对APACHE进行安全检测
benchmark.pl -c /etc/httpd/conf/httpd.conf -o result.html
完成!
五月 12th, 2011 at 07:17
Interesting Article…
[...]some interesting sites worth visitng. We recommend all our readers go and check these out[...]……
七月 10th, 2011 at 01:06
Visitor recommendations…
[...]one of our visitors recently recommended the following website[...]……
一月 4th, 2012 at 11:03
Gems form the internet…
[...]very few websites that happen to be detailed below, from our point of view are undoubtedly well worth checking out[...]……