Preventing web attacks with Apache

&Ldquo;Ryan Barnett has raised the bar in terms of running Apache securely. If you run Apache, stop right now and leaf through this book; you need this information.” –Stephen Northcutt, The SANS Institute € The only end-to-end guide to securing Apache Web servers and Web appl...

Full description

Bibliographic Details
Main Author: Barnett, Ryan C.
Format: eBook
Language:English
Published: Upper Saddle River, NJ Addison-Wesley 2005
Subjects:
Online Access:
Collection: O'Reilly - Collection details see MPG.ReNa
LEADER 03968nmm a2200457 u 4500
001 EB001940242
003 EBX01000000000000001103144
005 00000000000000.0
007 cr|||||||||||||||||||||
008 210123 ||| eng
020 |a 9780132702287 
020 |a 0321321286 
020 |a 9780321321282 
050 4 |a TK5105.8885.A63 
100 1 |a Barnett, Ryan C. 
245 0 0 |a Preventing web attacks with Apache  |c Ryan C. Barnett 
260 |a Upper Saddle River, NJ  |b Addison-Wesley  |c 2005 
300 |a 1 online resource 
653 |a Serveurs Web / Logiciels 
653 |a Sites Web / Sécurité / Mesures / Logiciels 
653 |a Electrical & Computer Engineering / hilcc 
653 |a Web servers / Computer programs / fast 
653 |a Apache (Computer file : Apache Group) / http://id.loc.gov/authorities/names/no97023874 
653 |a Web sites / Security measures / Computer programs 
653 |a Telecommunications / hilcc 
653 |a Web servers / Computer programs / http://id.loc.gov/authorities/subjects/sh00009716 
653 |a Apache (Computer file : Apache Group) / fast 
653 |a Engineering & Applied Sciences / hilcc 
041 0 7 |a eng  |2 ISO 639-2 
989 |b OREILLY  |a O'Reilly 
776 |z 9780321321282 
776 |z 0321321286 
776 |z 9780321321282 
856 4 0 |u https://learning.oreilly.com/library/view/~/0321321286/?ar  |x Verlag  |3 Volltext 
082 0 |a 384 
082 0 |a 500 
082 0 |a 620 
082 0 |a 005.8 
520 |a &Ldquo;Ryan Barnett has raised the bar in terms of running Apache securely. If you run Apache, stop right now and leaf through this book; you need this information.” –Stephen Northcutt, The SANS Institute € The only end-to-end guide to securing Apache Web servers and Web applications € Apache can be hacked. As companies have improved perimeter security, hackers have increasingly focused on attacking Apache Web servers and Web applications. Firewalls and SSL won’t protect you: you must systematically harden your Web application environment. Preventing Web Attacks with Apache brings together all the information you’ll need to do that: step-by-step guidance, hands-on examples, and tested configuration files. € Building on his groundbreaking SANS presentations on Apache security, Ryan C. Barnett reveals why your Web servers represent such a compelling target, how significant exploits are performed, and how they can be defended against.  
520 |a € With this book, you will learn to Address the OS-related flaws most likely to compromise Web server security Perform security-related tasks needed to safely download, configure, and install Apache Lock down your Apache httpd.conf file and install essential Apache security modules Test security with the CIS Apache Benchmark Scoring Tool Use the WASC Web Security Threat Classification to identify and mitigate application threats Test Apache mitigation settings against the Buggy Bank Web application Analyze an Open Web Proxy Honeypot to gather crucial intelligence about attackers Master advanced techniques for detecting and preventing intrusions 
520 |a Exploits discussed include: buffer overflows, denial of service, attacks on vulnerable scripts and programs, credential sniffing and spoofing, client parameter manipulation, brute force attacks, web defacements, and more. € Barnett introduces the Center for Internet Security Apache Benchmarks, a set of best-practice Apache security configuration actions and settings he helped to create. He addresses issues related to IT processes and your underlying OS; Apache downloading, installation, and configuration; application hardening; monitoring, and more. He also presents a chapter-length case study using actual Web attack logs and data captured “in the wild.” € For every sysadmin, Web professional, and security specialist responsible for Apache or Web application security.