Nathan wrote in earlier with attempts to exploit PHP file inclusion that his server had automatically thwarted. He's promoting the use of mod_security, mod_evasive, fail2ban and suhosin in a Apache/PHP environment. Since knowledge and experience is a way to win from the bad guys, how about sharing your favorite setup for Apache/PHP security (Basically a "LAMP" environment although I'd rather not focus on the OS part in there) and we'll summarize on this page. Also let us know what you like of the components you use, why they are your favorite etc. . The link for this article located at SANS is no longer available. . The link for this article located at SANS is no longer available.. nathan, wrote, earlier, attempts, exploit, inclusion, server, automaticall. . LinuxSecurity.com Team
Applicure announced today the release of dotDefender 2.0 for Solaris and Linux Web servers. dotDefender secures websites against a broad range of HTTP-based attacks, including Session attacks (e.g. Denial of Service, Session Hijacking), Web application attacks (e.g. SQL injection, Cross-site scripting, and known attack signatures), as well as requests originating from known attack sources (e.g. spammer bots and compromised servers). . dotDefender 2.0, a powerful security software solution for web server and database, protects against a broad range of attacks, including: Denial of Service, SQL Injection, Cross-site Scripting, Cookie Tampering, Path Traversal, Probes, Session Hijacking and known attack sources. Applicure Technologies, a pioneering provider of advanced application security solutions for the Web environment, announced today the release of dotDefender 2.0 - an advanced security solution that analyzes incoming HTTP requests and blocks embedded attacks from penetrating the Web environment. dotDefender 2.0 is a cost-effective, software-based solution that deploys quickly on the Web host with a preconfigured, automatically updated rule set that enables it to protect the Web environment immediately upon installation with virtually no administrator intervention. Based on Applicure’s groundbreaking TotalShield technology, dotDefender resides on the Web server, where it intercepts and analyzes incoming HTTP requests: those that are found to violate the defined rules are blocked – ensuring that malicious attacks seeking to compromise mission-critical Web applications or data assets are denied entry into the Web environment. “Whether an organization is small, medium, or large, the Web has become an indispensable component of its business IT infrastructure – and protecting the corporate Web environment from increasingly frequent attacks has become a mission-critical imperative. dotGuardian 3.1 protects Unix & BSD systems from web-oriented assaults, providing proactive measures against avariety of dangers.. Web Server Protection, Application Security, DotDefender, Solaris Security, Linux Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.