Howto Secure Apache
- Use the latest and most current version. Right now the latest is the Apache 2.2 series
- Make sure you’ve installed all the latest security patches
- Hide the Apache Version number, and other sensitive information
- Make sure apache is running under its own user account and group
- Ensure that files outside the web root are not served
- Turn off directory browsing (mod_autoindex)
- Turn off server side includes (SSI)
- Turn off CGI execution
- Don’t allow apache to use symbolic links
- Turning off multiple Options
- Turn off support for .htaccess files
- Use the Apache mod_security
- Disable all unnecessary modules
- Make sure only root has read access to apache’s config and binaries
- Lower the Timeout value
- Limiting large requests
- Limiting Concurrency
- Restricting Access by IP
- Adjusting KeepAlive settings
- Run Apache in a Chroot environment
Feel free to post suggestions or corrections
Related posts:
- Varnish : Simple and Fast HTTP Acceleration
- Howto Recover a Linux Root Password
- Howto PHP / Java bridge on Debian
- Howto Upgrade Joomla
- PHP 5.2 and APC (Alternative PHP Cache) Performance
- Optimize MySQL for Low Memory Use
- Xen Howto: Install Windows
- Block referer spam easily
- Apache gained 1.09% market share in October
- Xorg 7.3 and 3D Acceleration with Nvidia Cards
Popular Related Items »
Incoming search terms
- securing apache 2 2
- secure apache 2 2
- secure apache ubuntu
- ubuntu secure apache
- how to secure apache
- ubuntu secure apache2
- how to secure apache 2 2
- lenny apache2 chroot
- apache chroot lenny
- secure apache2
- secure apache2 ubuntu
- secure debian lenny
- ubuntu apache chroot
- apache2 chroot lenny
- secure apache2 debian
- apache secure
- apache chroot ubuntu
- securing apache windows
- securing apache ubuntu
- apache chroot debian
- securing apache on ubuntu
- chroot ubuntu apache
- debian apache secure
- turn off directory browsing ubuntu
- debian lenny apache chroot
- ubuntu apache directory browsing
- securing apache2
- fedora apache secure
- securing apache2 ubuntu
- debian secure apache2
- ubuntu jail apache
- secure apache lenny
- secure apache on windows
- lenny apache chroot
- debian apache chroot
- ubuntu 9 10 secure apache
- secure apache fedora
- securing apache ubuntu 9 10
- secure apache debian
- howto secure apache
- securing apache2 debian
- secure apache
- securing apache2 on ubuntu
- debian secure apache
- securing apache2 ubuntu 9 10
