Penguin Power!
Buy Linux distributions at discount prices!
Linux| Perl| PHP| Webserv| Databases| Sysadmin| Programming| Filesystems| Java| Webprog
News from Slashdot
The World's Spookiest Weapons

NSF Research Reveals Chain Letter Travel Patterns

US Senate Asks for National Security Letter Explanation

A Baseball Hat That Reads Your Mind

Amputee Sprinter Wins Olympic Appeal to Compete

$100 Laptop Platform Moves On

Lockheed Martin Awarded GPSIII

Senators OK $1 Billion for Online Child Porn Fight

Shape-Shifting Malware Hits the Web

Dutch Voting Machines De-Certified


Related products:

Apache Cookbook Apache Cookbook

Apache: The Definitive Guide (3rd Edition) Apache: The Definitive Guide (3rd Edition)


Linux Server Security Linux Server Security

High Performance MySQL High Performance MySQL

Web Servers

Apache Security

Web Servers
Format: Paperback
Author: Ivan Ristic
ReleaseDate: 15 March, 2005
Publisher: O'Reilly Media
Rating:

Review of "Apache Security" by Ivan Ristic
The chapters on PHP and logging are especially useful. Excellent book.


Used every morning with coffee
I haven't ever really found many books on this topic and wondered why since its such a widely popular web server. I recently heard about a new book out that is just about Apache Security written by Ivan Ristic. Ivan Ristic is well known for being the single man behind an invaluable tool for web servers called mod_security.

So many security related books are very expensive and thousands of pages long, which is great if you have lots of time but no system admin does. Apache Security is both thorough and quick to get through while walking you through the most imporant issues you'll encounter or never thought about until now.



First off go buy the book, don't bother to read this review at http://www. webhostgear. com/313. html It's really that good. I use it on a daily basis and keep a copy at the office and at home. I advise anyone that owns a server or works with Apache to get this book, you won't be disappointed. It's not
for somoene that's completely a newbie to web servers, I recommend it more for someone with a bit of experience or advanced user of Linux. Since this isn't a book on dummy installations but about security so you need a basic understanding of file permissions and so on. .


Great book, useful for all Apache users
I remember how I was eagerly waiting to receive more new chapters from the publisher. I thoroughly enjoyed Ivan's "Apache Security", even when I was a reviewer for an unfinished book.

The book contains a nice combination of generic web stuff and Apache stuff. It starts with the discussion of security principles, such as defense-in-depth and minimum access privilege. Although not new, they are useful for those just entering the field, such as for beginner apache admins.

The chapter on Apache's installation and configuration sounds boring and many might be tempted to skip it. But it does contain a gem: a guide on setting Apache in a chroot jail!

PHP, a main web application platform for Apache at the time of this writing, is covered as well. I found some tips on PHP hardening that I didn't know previously. While the last PHP application I deployed was configured to be 'hackable' (it was a honeypot deployment, after all!), I found the tips to be practical.

One entertaining chapter is on denial-of-service attacks. There are many ways to overwhelm a network server, and Apache is now exception. It's a must-read for those running highly-available sites, where downtime costs a lot.

An important chapter covers Apache access control, from basic auth to single sign-on. Of course, of particular interest to me was a chapter on logging and monitoring, as it is one of my favorite subjects. Ivan did a great job covering not only logging facilities available within the server, but also log centralization, log analysis for security, integrity monitoring and other stuff. Distributed logging with Spread kit is indeed 'cool', just as Ivan mentions.

A brief chapter covers the security of the underlying 'infrastructure', such as the OS that Apache runs on. I liked the overview since it is not 'generic', but covers material relevant to running Apache web server.

Chapter 10-12 are at the center of the book, providing the core of the new material. Those cover web application attacks, web security assessment and web intrusion detection,. The latter is based on Ivan's famous mod_security Apache module. While web attacks are covered in many places, I think the overview in the book is clear, focused and useful even for those who do web security for a living. As far as the mod_security chapter is concerned, I would read it with most care since it covers a lot of advanced usage tips, not available elsewhere.

The book is well written, easy to follow and displays clear writing style. I would strongly recommend it to everybody who is involved in running Apache web servers, web applications or has web security as part of his job responsibility. Obviously, everybody who thinks that this subject is fun should also read it :-) Also, check out www. apachesecurity. net for some free chapters, ToC, tools covered in the book, as well as a couple presentations given by Ivan. The book focuses on the defensive side, but mentions various attacks against web infrastructure as well.

Anton Chuvakin, Ph. D. , GCIA, GCIH, GCFA is a Security Strategist with a major security company. He is an author of the book "Security Warrior" and a contributor to "Know Your Enemy II" and the upcoming "Hacker's Challenge III". In his spare time, he maintains his security portal info-secure. org and his blog at O'Reilly. His next book will be about security log analysis.
.



Go to lyrics-now.com for music lyrics and song lyrics.
Bass and guitar tablatures: Fretplay.com, Guitar tabs, Bass tabs, Fresh tabs, How to read tabs
Plan your travel and holiday here: Travel Helper!