CARVIEW |
By Ivan Ristic
First Edition
February 2005
Pages: 420
ISBN 10: 0-596-00724-8 |
ISBN 13: 9780596007249
This all-purpose guide for locking down Apache arms readers with all the information they need to securely deploy applications. Administrators and programmers alike will benefit from a concise introduction to the theory of securing Apache, plus a wealth of practical advice and real-life examples. Topics covered include installation, server sharing, logging and monitoring, web applications, PHP and SSL/TLS, and more.
Full Description
- install and configure Apache
- prevent denial of service (DoS) and other attacks
- securely share servers
- control logging and monitoring
- secure custom-written web applications
- conduct a web security assessment
- use mod_security and other security-related modules
Featured customer reviews
Be the first person to review this book!
Media reviews
"...any Apache administrator or developer will benefit, in terms of increased security, from the information provided in this book. "
-- Robert Slade, Internet Review Project
"...I have found this book to be excellent. It is written in a teaching style, covering general security where appropriate, then linking each concept to the specific mutation within the http protocol that underlies web server operation. In order to create security techniques for a process or program, one really needs to understand the program and security. Ristic clearly does. The best part is his writing in a such a way that you learn as you read through the book. I have a special appreciation of techies who can communicate ideas...Apache Security certainly will go on my O'Reilly Apache bookshelf next to Apache The Definitive Guide and the Apache Cookbook. It is a highly recommended book for anyone, but especially for those who run (or want to run) an Apache web server."
--Robert Bruen, IEEE-Security.org, December 2005
"If you are responsible for rolling out Apache, you will benefit from the detailed coverage of the hardening process. Going well beyond the official documentation, Ivan explains the reasoning and benfits of each step. Similarly, the SSL how-to is followed by an analysis of the practical issues in SSL (eg. users lack awareness of browser warnings for SSL)... The book is peppered with interesting sidebars, from the informative one on Apache backdoors to the amusing one on the Alan Ralsky Denial of Service. This book is a must-read for Apache administrators; web developers will also enjoy Ivans direct writing..."
--Palisade Application Security Intelligence, August 2005
"A number of books in the last couple of years have specifically addressed Apache security, but I was particularly impressed with Ivan Ristic's Apache Security. Rather than just providing an expanded description of the Apache documentation, the author takes a problem-solution approach. The book goes into detail about why a particular issue is important, as well as why one would want to implement a given solution. The author gets into the background behind the issues, showing how things work, rather than just telling you what to configure."
--James Mohr, Linux-Magazine.com, June 2005
Read all reviews
About O'Reilly | Contact | Jobs | Press Room | How to Advertise | Privacy Policy
|
© 2008, O'Reilly Media, Inc. | (707) 827-7000 / (800) 998-9938
All trademarks and registered trademarks appearing on oreilly.com are the property of their respective owners.