Book review: Hardening Apache by Tony Mobily
Short URL: http://fsmsh.com/1276
- 2006-02-12
- Published on web | Easy
-
Write a full post in response to this!
A recent Netcraft survey found that approximately 67% of websites (two-thirds of the entire internet!) are served with Apache. With such a large number of administrators using Apache on their servers it stands to reason that a large number of crackers will focus their attentions on cracking it. That’s where “Hardening Apache”, a book by Free Software Magazine’s own excellent and keen-eyed Editor In Chief, Tony Mobily, comes in (it was just a little plug). The book lists ways to make your server more secure, and how to keep good server administration habits that will keep your server protected.
The contents
This book is very in-depth and technical, it shows that Tony has researched this subject very well. Everything an administrator would need to get their Apache server nailed down is discussed; with specifics on what to do, and why to do it. This isn’t just a reference to the Apache documentation, it’s a all-out reference manual unto its own. Topics such as GnuPG, compiling Apache, editing the Apache configuration, installing modules, and security modules are discussed. This book let’s you jump right on in, extensively detailing the information administrators will need.
Ken Coar himself wrote the foreword and sums up why this book is so in need:
Despite the foregoing and the popularity of the Apache web server, there is a surprising dearth of authoritative and complete documents providing instructions for making an Apache installation as secure as possible… Enter “Hardening Apache”—Ken Coar (Apache Software Foundation)
Tony Mobily pulls together the critical parts of Apache security information and puts them all in one compact book. This is a must for all Apache administrators, and will probably be for some time to come
This 270 page book is separated into seven chapters. In the first chapter installation and configuration are discussed. The second chapter outlines some common attacks against Apache and how to prevent them. The third chapter describes both local and remote logging and various scripts that can make your server logging easier. The entire fourth chapter deals with cross-site scripting attacks (aka. XSS) and methods of preventing them. Chapters five and six deal with Apache security modules and running Apache in a jail, respectively. Finally, in the seventh chapter, several bash automation scripts you can use to track your server are introduced.
On top of all that there are also three appendices that outline Apache resources and explain how Apache interacts with the “web” in general. There’s also a list of all the “checkpoints” from the chapters so you can make sure you’re up to speed on your security. That’s quite a lot packed into one book!
Who’s this book for?
This book is ideal for all *nix system administrators. Even if you think you know all there is about Apache security, you need this book! This book would be a perfect addition to any administrator’s bookshelf, just the time-saving Bash scripts alone make this book a worthwhile addition (or gift) for administrators or part time hobbyists (you know who you are).
Relevance to free software
This book describes the hows and whys of Apache, and since Apache itself is free software, this book inherits that. For those that want to use the Apache free software server, this is for you! A proprietary module is described, although the great majority of the modules described are considered under the realm of free software.
Pros
Tony Mobily pulls together the critical parts of Apache security information and puts them all in one compact book. This will be a must for all Apache administrators, and will probably be for some time to come. Just for the sake of making absolutely sure your server is secure, you’ll want this book!
Cons
It’s very in-depth and technical, and probably won’t be helpful to those not familiar with the Apache server software. New administrators should probably read an introduction to Apache and then start on this book. This book is also directed mainly toward *nix based systems, so Windows and Mac users may find the examples and suggestions won’t work on their operating system.
| Title | Hardening Apache |
| Author | Tony Mobily |
| Publisher | Apress |
| ISBN | 1590593782 |
| Year | 2004 |
| Pages | 270 |
| CD included | No |
| FS Oriented | 10 |
| Over all score | 9 |
In short
Write a full post in response to this!
Similar articles
Do you like this post?
Vote for it!
Copyright information
This article is made available under the "Attribution-NonCommercial-NoDerivs" Creative Commons License 3.0 available from http://creativecommons.org/licenses/by-nc-nd/3.0/.
Biography
Robin Monks: Robin Monks is a volunteer contributor to Mozilla, Drupal, GMKing and Free Software Magazine and has been helping free software development for over three years. He currently works as an independent contractor for CivicSpace LLC
Best voted contents
Buzz authors
Free Software news
- RT @turicas: The #Arduino #HackNBeer yesterday with @maddoghall at #UFF (in Niterói/RJ - Brazil) was amazing! \o/ #freesoftware #FTW
- Second Sole of Ohio | marymoome: http://tinyurl.com/25y6nzv #coolest #freesoftware #freesoftware Amor no respeta l... http://bit.ly/azeueY
- http://tinyurl.com/25y6nzv #coolest #freesoftware #freesoftware Amor no respeta ley ni obedece a rey A diario una manzana es cosa sana
- via @Developpez A new font for easier code writing: http://bit.ly/9AADsE under #OpenFontLicense #freesoftware
- RT @turicas: The #Arduino #HackNBeer yesterday with @maddoghall at #UFF (in Niterói/RJ - Brazil) was amazing! \o/ #freesoftware #FTW
Similar entries
Other sites
- The Top 10 Everything (Dave). The good, the bad and the ugly.
- Free Software news (Dave & Bridget). All about free software -- free as in freedom!
- Book Reviews: Illiterarty (Bridget). Book reviews, blogs, and short stories.
Hot topics - last 60 days
-
10 years on: free software wins, but you have nowhere to install it
Tony Mobily, 2010-07-29 -
Tales From the Front: in Search of APT-GET UNDO
Rosalyn Hunter, 2010-08-13 -
Finding Free Music for a Free Film with Jamendo, VLC, and K3B
Terry Hancock, 2010-07-13 -
The Jargon of Freedom: 60 Words and Phrases with Context
Terry Hancock, 2010-07-24 -
MediaWiki and Script Translation for the Morevna Project
Terry Hancock, 2010-07-07
Hot topics - last 21 days
-
Net Neutrality: what does the Google Verizon proposal mean for GNU Linux?
Gary Richmond, 2010-08-16 -
The Bizarre Cathedral - 78
Ryan Cartwright, 2010-08-16 -
The Bizarre Cathedral - 79
Ryan Cartwright, 2010-08-24 -
Flip: A Simple Camera Done Right
Terry Hancock, 2010-08-31
Free Software Magazine uses Apollo project management and CRM for its everyday activities!





