Nathan wrote in earlier with attempts to exploit PHP file inclusion that his server had automatically thwarted. He's promoting the use of mod_security, mod_evasive, fail2ban and suhosin in a Apache/PHP environment. Since knowledge and experience is a way to win from the bad guys, how about sharing your favorite setup for Apache/PHP security (Basically a "LAMP" environment although I'd rather not focus on the OS part in there) and we'll summarize on this page. Also let us know what you like of the components you use, why they are your favorite etc. . The link for this article located at SANS is no longer available. . The link for this article located at SANS is no longer available.. nathan, wrote, earlier, attempts, exploit, inclusion, server, automaticall. . LinuxSecurity.com Team
Tips on securing apache for use with virtual hosts. "There is no best way to do this except to be paranoid about every detail, pay attention to security alerts and trust no one. Fortunately, Apache has some recommendations. Here is how . . . . Tips on securing apache for use with virtual hosts. "There is no best way to do this except to be paranoid about every detail, pay attention to security alerts and trust no one. Fortunately, Apache has some recommendations. Here is how to put them in practice for AllCommerce. The basic procedure is to start by nailing *everything* down to the most secure configuration. Then, as needed, enable individual capabilities. Let's start with the Apache server file ownership and permissions. " The link for this article located at OpenSales is no longer available. . Enhance your Apache web server security by updating regularly, configuring SSL, setting proper permissions, and implementing security headers and logging. Apache Security, Configuring Virtual Hosts, Server Best Practices. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.