The maintenance of Apache

Source: Internet
Author: User
Tags server installation and configuration version

Review

This article discusses security issues with the Apache Web server installation and configuration under the UNIX platform. We assume that the system administrator reading this article has selected the relevant modules for their own site, and that they are able to configure, create, and troubleshoot problems. The main purpose of this article is to help you resume a secure Apache crooked neck (Web:P) server.

In many Web server products, Apache is one of the most widely used products, but also a very safe design program. However, like other applications, Apache also has a security flaw. This article focuses on three security flaws, including: Denial-of-service attacks using the HTTP protocol (Denial of service), 3 buffer overflow attacks, and the attacker obtaining root privileges. Note: A reasonable configuration protects Apache from multiple attacks, but denial of service attacks on the network layer are not able to be prevented by tuning Apache configuration. This article deals with denial of service attacks using the HTTP (application tier) protocol.

The main flaws of Apache

http Denial of service

The attacker has some means of denying the server the answer to HTTP. This will increase the demand for system resources (CPU time and memory) in Apache, eventually causing the system to become slow or even completely paralyzed.

• Buffer Overflow

The attacker uses some of the bugs written by the program to deflect the program from its normal process. The program uses statically allocated memory to hold the request data, and an attacker can send an extra long request to overflow the buffer. Like some Perl-written gateway script that handles user requests. Once the buffer overflows, an attacker can execute its malicious instructions or cause the system to go down.

• The victim is given root privileges

Apache typically runs as root (the parent process), and the attacker obtains root permissions and then controls the entire system.

Get the latest Apache

Using the safest version is critical to securing your Apache Web server.

You can get the latest version of Apache from the official Apache website http://www.apache.org.

Protection of configuration files



Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.