Join Amazon Prime and ship Two-Day for free and Overnight for $3.99. Already a member? Sign in.
Apache Security and over 300,000 other books are available for Amazon Kindle – Amazon’s new wireless reading device. Learn more

 

or
Sign in to turn on 1-Click ordering.
 
 
More Buying Choices
24 used & new from $21.42

Have one to sell? Sell yours here
 
   
Apache Security
 
 
Start reading Apache Security on your Kindle in under a minute.

Don’t have a Kindle? Get yours here.
 
  
4.8 out of 5 stars See all reviews (14 customer reviews)

List Price: $34.95
Price: $23.07 & eligible for FREE Super Saver Shipping on orders over $25. Details
You Save: $11.88 (34%)
In Stock.
Ships from and sold by Amazon.com. Gift-wrap available.

Want it delivered Tuesday, July 7? Choose One-Day Shipping at checkout. Details
15 new from $23.07 9 used from $21.42
Also Available in: List Price: Our Price: Other Offers:
Kindle Edition (Kindle Book) $15.39
Like this book? Find similar titles from O'Reilly and Partners in our O'Reilly Bookstore.

Best Value

Buy Apache Security and get Apache Cookbook: Solutions and Examples for Apache Administrators at an additional 5% off Amazon.com's everyday low price.

Apache Security + Apache Cookbook: Solutions and Examples for Apache Administrators
Buy Together Today: $45.01

Show availability and shipping details


Customers Who Bought This Item Also Bought

Pro Apache, Third Edition (Expert's Voice)

Pro Apache, Third Edition (Expert's Voice)

by Peter Wainwright
4.6 out of 5 stars (7)  $31.49
Preventing Web Attacks with Apache

Preventing Web Attacks with Apache

by Ryan C. Barnett
4.6 out of 5 stars (7)  $38.49
Essential PHP Security

Essential PHP Security

by Chris Shiflett
3.8 out of 5 stars (16)  $19.77
Apache: The Definitive Guide (3rd Edition)

Apache: The Definitive Guide (3rd Edition)

by Ben Laurie
2.5 out of 5 stars (13)  $26.37
High Performance MySQL: Optimization, Backups, Replication, and More

High Performance MySQL: Optimization, Backups, Replication, and More

by Baron Schwartz
4.6 out of 5 stars (17)  $31.49
Explore similar items

Editorial Reviews

Product Description
With more than 67% of web servers running Apache, it is by far the most widely used web server platform in the world. Apache has evolved into a powerful system that easily rivals other HTTP servers in terms of functionality, efficiency, and speed. Despite these impressive capabilities, though, Apache is only a beneficial tool if it's a secure one.

To be sure, administrators installing and configuring Apache still need a sure-fire way to secure it--whether it's running a huge e-commerce operation, corporate intranet, or just a small hobby site.

Our new guide, "Apache Security," gives administrators and webmasters just what they crave--a comprehensive security source for Apache. Successfully combining Apache administration and web security topics, "Apache Security" speaks to nearly everyone in the field. What's more, it offers a concise introduction to the theory of securing Apache, as well as a broad perspective on server security in general.

But this book isn't just about theory. The real strength of "Apache Security" lies in its wealth of interesting and practical advice, with many real-life examples and solutions. Administrators and programmers will learn how to:

install and configure Apache

prevent denial of service (DoS) and other attacks

securely share servers

control logging and monitoring

secure custom-written web applications

conduct a web security assessment

use mod_security and other security-related modules

And that's just the tip of the iceberg, as mainstream Apache users will also gain valuable information on PHP and SSL/ TLS. Clearly, "Apache Security" is packed and to the point, with plenty of details for locking down this extremely popular and versatile web server.

About the Author
Ristic is a web security specialist and the founder of Thinking Stone, which offers products and services related to web application security.


Product Details

  • Paperback: 432 pages
  • Publisher: O'Reilly Media, Inc.; illustrated edition edition (May 11, 2009)
  • Language: English
  • ISBN-10: 0596007248
  • ISBN-13: 978-0596007249
  • Product Dimensions: 9 x 7 x 1 inches
  • Shipping Weight: 1.2 pounds (View shipping rates and policies)
  • Average Customer Review: 4.8 out of 5 stars See all reviews (14 customer reviews)
  • Amazon.com Sales Rank: #124,020 in Books (See Bestsellers in Books)

    Popular in these categories: (What's this?)

    #6 in  Books > Computers & Internet > Web Development > Web Servers > Apache
    #40 in  Books > Computers & Internet > Business & Culture > Security
    #81 in  Books > Computers & Internet > Business & Culture > Hacking

Inside This Book (learn more)



Tags Customers Associate with This Product

 (What's this?)
Click on a tag to find related items, discussions, and people.
Check the boxes next to the tags you consider relevant or enter your own tags in the field below.

Your tags: Add your first tag
 
Help others find this product — tag it for Amazon search
No one has tagged this product for Amazon search yet. Why not be the first to suggest a search for which it should appear?

 

Customer Reviews

14 Reviews
5 star:
 (11)
4 star:
 (3)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
4.8 out of 5 stars (14 customer reviews)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

 
11 of 11 people found the following review helpful:
5.0 out of 5 stars The single best Apache security book in print, September 27, 2006
I recently received copies of Apache Security (AS) by Ivan Ristic and Preventing Web Attacks with Apache (PWAWA) by Ryan Barnett. I read AS first, then PWAWA. Both are excellent books, but I expect potential readers want to know which is best for them. The following is a radical simplification, and I could honestly recommend readers buy either (or both) books. If you are more concerned with a methodical, comprehensive approach to securing Apache, choose AS. If you want more information on offensive aspects of Web security, choose PWAWA.

Before I go further, I must mention that Ivan Ristic cites me and my books twice, on pages 2 and 229. While humbling, I tried not to let this fact influence my review.

AS is an extremely well-thought-out book. My favorite aspect of AS is the decision to start with a blank httpd.conf file, rather than accepting the file packaged with Apache and making edits as needed. By building up httpd.conf from scratch, the author shows exactly what components are needed in a very clear manner. This was not the approach used by PWAWA. I would like to see other technical books adopt this teaching method.

AS includes better coverage of several topics which I believe are core to securing Apache. I liked AS' discussion of chroot environments and jails, although the author should distinguish between chroot on Linux or BSD and jail on BSD alone. AS features a whole chapter on proper PHP deployment (Ch 3), and a whole chapter on SSL/TLS (Ch 4). AS devotes another chapter to explaining how to host multiple Web sites on one host (Ch 6), which is critical to many Apache environments. AS' chapter on Web infrastructure (CH 9) also covers topics not found in PWAWA.

AS is also less explicitly Linux-centric than PWAWA. As a primary FreeBSD user, I found AS' approach more applicable to my environment. PWAWA seemed to assume everyone was running Red Hat Linux. It's fine to use a single OS for all examples, but I had to personally identify tools and techniques that would probably only work on Red Hat.

I had very little trouble with any of the text in AS. My main concerns involve Ch 1, where the author spends time on certain security concepts. I would consider the following with regards to threat modeling on p. 5: (asset) what might be compromised; (motivation) why compromise; (vulnerabilities) where compromised; (attack) how compromised; (threat) who compromised you; (risk) threat X vulnerability X asset value. On pp 9-10 the author should also have used the risk equation just mentioned.

Overall, I really liked AS. The book really is about Apache security, so if you are more interested in attacking Apache you might prefer PWAWA. If you want to learn about Web application hacking in general, your best bets are probably Hacking Exposed: Web Applications, 2nd Ed, and Professional Pen Testing for Web Applications. I will read and review those two books shortly.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
5 of 5 people found the following review helpful:
5.0 out of 5 stars Comprehensive, task-oriented web security cookbook, April 10, 2005
By Kiwi (Atsugi-city, JAPAN) - See all my reviews
This comprehensive, systematic, task-oriented book covers all the alternative approaches to securing servers -- from secure to paranoid -- complete with examples to demonstrate vulnerabilities such as session management, (Javascript) cross-site scripting, and SQL injection. Subjects such as hardening PHP, shared-server vulnerabilities, and logging/monitoring, each get a whole chapter. This up-to-date, well-written (concise yet encyclopedic) book will be indispensible to system designers, administrators and programmers.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)



 
4 of 4 people found the following review helpful:
5.0 out of 5 stars Used every morning with coffee, February 4, 2006
I recently heard about a new book out that is just about Apache Security written by Ivan Ristic. I haven't ever really found many books on this topic and wondered why since its such a widely popular web server. Ivan Ristic is well known for being the single man behind an invaluable tool for web servers called mod_security.

So many security related books are very expensive and thousands of pages long, which is great if you have lots of time but no system admin does. Apache Security is both thorough and quick to get through while walking you through the most imporant issues you'll encounter or never thought about until now.



First off go buy the book, don't bother to read this review at http://www.webhostgear.com/313.html It's really that good. I use it on a daily basis and keep a copy at the office and at home. I advise anyone that owns a server or works with Apache to get this book, you won't be disappointed. It's not
for somoene that's completely a newbie to web servers, I recommend it more for someone with a bit of experience or advanced user of Linux. Since this isn't a book on dummy installations but about security so you need a basic understanding of file permissions and so on.
Comment Comment | Permalink | Was this review helpful to you? Yes No (Report this)


Share your thoughts with other customers: Create your own review
 
 
 
Most Recent Customer Reviews

5.0 out of 5 stars A very easy read, on what could have been a dry topic
In the almost four years since this book was published the area of security, and of web security in particular has continued to move on at a significant pace. Read more
Published 2 months ago by Brian P. Irwin

5.0 out of 5 stars Crucial reference for Apache web server admins
From my perspective: As a Linux / BSD sysadmin (but Apache httpd novice), I purchased this book a few months ago in hopes of supplementing my Apache learning. Read more
Published 3 months ago by sinbad

5.0 out of 5 stars Much more than just Apache Security
I found this book while browsing the programming section of Borders (the programming section of my local Borders is amazing!), and I've found it to be a real gem. Read more
Published 21 months ago by Ryan Stille

5.0 out of 5 stars super
Thanks a lot, we are very happy to have this book in our library!
Published on March 8, 2007 by E. Schnyder

5.0 out of 5 stars Excellent book...
This book is worth every single dollar. The examples are very clear and also provide invaluable information about security.

A must have for everybody using Apacge.
Published on August 1, 2006 by Gerardo Arroyo Arce

5.0 out of 5 stars Review of "Apache Security" by Ivan Ristic
Excellent book. The chapters on PHP and logging are especially useful.
Published on March 1, 2006 by Karl Vogel

5.0 out of 5 stars Great book, useful for all Apache users
I thoroughly enjoyed Ivan's "Apache Security", even when I was a reviewer for an unfinished book. I remember how I was eagerly waiting to receive more new chapters from the... Read more
Published on November 3, 2005 by Dr Anton Chuvakin

5.0 out of 5 stars Not just about Apache security
I'm sure it was tempting for the author to just concentrate on the Apache portions of the web application security world. Read more
Published on June 20, 2005 by Jack D. Herrington

4.0 out of 5 stars more dangerous attacks
Ideally, this book should not exist. Because no one would try to intrude onto your Apache server. Besides, you don't mind a stranger being able to to that anyway, eh? Read more
Published on April 13, 2005 by W Boudville

4.0 out of 5 stars I have to disagree slightly
I don't agree that this is detailed and comprehensive. Yes, it touches all the necessary ground, but it only touches, and left me quite confused at several points... Read more
Published on April 12, 2005 by Anthony Lawrence

Only search this product's reviews



Customer Discussions

 Beta (What's this?)
New! See all customer communities, and bookmark your communities to keep track of them.
This product's forum (0 discussions)
  Discussion Replies Latest Post
  No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
  [Cancel]


Active discussions in related forums
   


Product Information from the Amapedia Community

Beta (What's this?)


So You'd Like to...


Look for Similar Items by Category


Avon: Free Shipping

Avon Mark Just Pinched Instant Blush Tint
Get free shipping on all Avon orders of $25 or more. Shop Avon's award-winning makeup, skin care, bath & body items, and more.

Shop Avon now

 

Big Savings in Books

Bargain Books
Find great titles at fantastic prices in our Bargain Books Store.
 

Buy Three Books, Get a Fourth Free

4-for-3 Books
Order any four eligible books under $10 and get the lowest-price book free in our 4-for-3 Books Store. See more details.
 

Best Books

Best of the Month
See our editors' picks and more of the best new books on our Best of the Month page.
 

 

Feedback

If you need help or have a question for Customer Service, contact us.
 Would you like to update product info or give feedback on images?
Is there any other feedback you would like to provide?

Your comments can help make our site better for everyone.


Where's My Stuff?

Shipping & Returns

Need Help?

Your Recent History

  (What's this?)
You have no recently viewed items or searches.

After viewing product detail pages or search results, look here to find an easy way to navigate back to pages you are interested in.

Look to the right column to find helpful suggestions for your shopping session.

Continue shopping: Top Sellers
Paranoia
Paranoia by Joseph Finder
Glenn Beck's Common Sense
Glenn Beck's Common Sense
Darkfever
Darkfever by Karen Marie Moning

Conditions of Use | Privacy Notice © 1996-2009, Amazon.com, Inc. or its affiliates