This manual provides comprehensive guidance for securing Apache Web servers and Web applications. It addresses the increasing focus of cyberattacks on these platforms, emphasizing the necessity of systematic hardening beyond perimeter security measures like firewalls and SSL. The content draws on expert presentations to explain why Web servers are attractive targets, detail common exploit methods, and offer robust defense strategies.
The manual covers a wide range of critical security topics, including buffer overflows, denial of service attacks, vulnerabilities in scripts and programs, credential sniffing, client parameter manipulation, brute force attacks, and web defacements. It introduces the Center for Internet Security Apache Benchmarks and delves into IT processes, operating system considerations, Apache installation and configuration, application hardening, and monitoring. A detailed case study using real-world attack data is also included, making this an essential resource for system administrators, web professionals, and security specialists.
The only end-to-end guide to securing Apache Web servers and Web applications
Apache can be hacked. As companies have improved perimeter security, hackers have increasingly focused on attacking Apache Web servers and Web applications. Firewalls and SSL won’t protect you: you must systematically harden your Web application environment. Preventing Web Attacks with Apache brings together all the information you’ll need to do that: step-by-step guidance, hands-on examples, and tested configuration files.
Building on his groundbreaking SANS presentations on Apache security, Ryan C. Barnett reveals why your Web servers represent such a compelling target, how significant exploits are performed, and how they can be defended against. Exploits discussed include: buffer overflows, denial of service, attacks on vulnerable scripts and programs, credential sniffing and spoofing, client parameter manipulation, brute force attacks, web defacements, and more.
Barnett introduces the Center for Internet Security Apache Benchmarks, a set of best-practice Apache security configuration actions and settings he helped to create. He addresses issues related to IT processes and your underlying OS; Apache downloading, installation, and configuration; application hardening; monitoring, and more. He also presents a chapter-length case study using actual Web attack logs and data captured “in the wild.”
For every sysadmin, Web professional, and security specialist responsible for Apache or Web application security.
Author: Barnett, Ryan C.
Publisher: Addison-Wesley Professional
Illustration: n
Language: ENG
Title: Preventing Web Attacks with Apache
Pages: 00624 (Encrypted EPUB) / 00000 (Encrypted PDF)
On Sale: 2006-01-27
SKU-13/ISBN: 9780321321282
Category: Computers : Web - General
Category: Computers : Networking - Vendor Specific
The only end-to-end guide to securing Apache Web servers and Web applications
Apache can be hacked. As companies have improved perimeter security, hackers have increasingly focused on attacking Apache Web servers and Web applications. Firewalls and SSL won’t protect you: you must systematically harden your Web application environment. Preventing Web Attacks with Apache brings together all the information you’ll need to do that: step-by-step guidance, hands-on examples, and tested configuration files.
Building on his groundbreaking SANS presentations on Apache security, Ryan C. Barnett reveals why your Web servers represent such a compelling target, how significant exploits are performed, and how they can be defended against. Exploits discussed include: buffer overflows, denial of service, attacks on vulnerable scripts and programs, credential sniffing and spoofing, client parameter manipulation, brute force attacks, web defacements, and more.
Barnett introduces the Center for Internet Security Apache Benchmarks, a set of best-practice Apache security configuration actions and settings he helped to create. He addresses issues related to IT processes and your underlying OS; Apache downloading, installation, and configuration; application hardening; monitoring, and more. He also presents a chapter-length case study using actual Web attack logs and data captured “in the wild.”
For every sysadmin, Web professional, and security specialist responsible for Apache or Web application security.
Author: Barnett, Ryan C.
Publisher: Addison-Wesley Professional
Illustration: n
Language: ENG
Title: Preventing Web Attacks with Apache
Pages: 00624 (Encrypted EPUB) / 00000 (Encrypted PDF)
On Sale: 2006-01-27
SKU-13/ISBN: 9780321321282
Category: Computers : Web - General
Category: Computers : Networking - Vendor Specific