Have one to sell? Sell yours here
Professional Apache Security (Programmer to Programmer)
 
See larger image
 
Tell the Publisher!
I'd like to read this book on Kindle

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.

Professional Apache Security (Programmer to Programmer) [Illustrated] [Paperback]

Sandip Bhattacharya (Author), Paul Weinstein (Author)
5.0 out of 5 stars  See all reviews (1 customer review)


Available from these sellers.



Book Description

Programmer to Programmer January 2003
Apache is the epitome of free software that is both the standard in a critical area (the Web), and widely accepted by proprietary software companies. With increased usage, server security becomes an issue of paramount importance.

Security is one of the most important factors that Apache administrators need to consider. Determining who is allowed access to what, verifying that people and systems are who they say they are, and eliminating security holes that could allow crackers to gain unauthorized access to a system are all issues that the conscientious web server administrator needs to worry about on a daily basis.

Apache provides many features that can be used to either compromise server security or gather information about a server that the administrator would prefer kept secret. Of course, these features aren't there to create security holes, but the more complex the configuration the more chances we have of creating an unanticipated use of the server. Understanding what is and what is not expected behavior is essential, both when creating the server configuration and detecting possible misuse.

There is no such thing as a totally one hundred percent secure server, but in this book we'll delve into crucial aspects of Apache security and practical ways to setting up a safer, more secure implementation of an Apache server.


Editorial Reviews

From the Publisher

Apache has seized an unchallenged superiority over other web servers. Its strength lies in its modular, scalable, robust architecture. Today the Apache server manages 66% of the all web-based Internet traffic, which means that any breach in Apache security directly affects the majority of the web servers deployed worldwide! Powerful web servers like Apache have many complex features that make security a challenging task. Furthermore, the growth in e-commerce has also brought the realization that reputation damage from a security breach is one of the fastest ways to erode customer and industry trust. This book provides an in-depth discussion on how to secure Apache. It provides comprehensive information on planning and implementing security at protocol, application and system levels. In addition, this book provides an overview of strategic defense against would-be crackers. This book is a tutorial, a resource, and a reference for Apache administrators, security analysts, web developers and system architects, who want to secure Apache on UNIX and its variant platforms. Here is the book in a nutshell:

- Overview of a secure Apache installation and configuration process

- Dissection of the effects of HTTP and URL on server security

- Coverage of authentication and authorization

- Security at protocol, application, and system level

- Usage of chrooting, CGI scripts, logging, and session tracking

- Coverage of DoS attacks, cookies, and cryptography

- Implementation and use of SSL to enable security at the transport layer

- Setting up a secure Apache server for an E?Commerce web site

About the Author

Tony Mobily is a technical writer and technical editor who manages the Italian computer magazine "Login", and works daily with many Internet technologies. He is a senior system administrator and a security expert, and has lots of fun playing with buffer overflows, DOS attacks, and firewalls.

Paul Weinstein devotes his energies to developing and integrating web-based systems. He has become knowledgeable in the detail workings of many tools of the trade including, Apache, Perl, PHP, SSL, mySQL, and Linux. Currently, he works as Chief Consultant for Waubonsie Consulting, spending a good amount of his time communicating his past experience in technical articles and presentations to others.

Mark Wilcox is the senior integration specialist with WebCT, Inc. the leading provider of higher education e-learning solutions. His areas of expertise includes LDAP, authentication, security, and application integration.

Brian P. Rickabaugh is a senior systems architect for a global conglomerate in the financial, manufacturing and media industries. He is also president of StrayCat Incorporated, a small business focused primarily on software consulting services. He has been developing web-centric object-oriented software in C/C++ and Java for six years. He is also a huge proponent of open source software and the positive impact it can have on small, medium and large organizations. His current focus is on XML and implementing Web Services technologies for internal and external systems integration.

Debashish Bhattacharjee is a principal consultant with IBM Global Services. His areas of expertise are systems integration and project management. He has served as chief architect and led technical teams tasked with the implementation of e-commerce applications, portal implementations, web infrastructure, ERP, and client-server applications.

Sandip Bhattacharya is an open source enthusiast and an active participant in various open source communities in India, especially his local LUG at Delhi(ILUGD). He has been professionally involved in open source based technologies for the past three years. He is currently a freelance programmer and consults businesses on ways to use the open source revolution to their advantage.

Kapil Sharma is an Internet security and Unix consultant. He enjoys working on firewalls, Load Balancers, VPN, clustering, cryptography, white hat hacking, and various Unix flavours. He is actively involved in the open source community and has contributed many technical articles on system and network security.


Product Details

  • Paperback: 362 pages
  • Publisher: Wrox Press; First edition. edition (January 2003)
  • Language: English
  • ISBN-10: 1861007760
  • ISBN-13: 978-1861007766
  • Product Dimensions: 9 x 7.1 x 0.9 inches
  • Shipping Weight: 1.4 pounds
  • Average Customer Review: 5.0 out of 5 stars  See all reviews (1 customer review)
  • Amazon Best Sellers Rank: #2,701,494 in Books (See Top 100 in Books)

More About the Author

In 1985, Paul started down the road to working in the ever-growing computer industry when he learned his first programming language. He has yet to look back, bring his personal understanding of technology into a wide variety of computing environments ranging from public elementary schools and political campaigns to pioneering open source companies and local startups.

With the popularization of the Internet, Paul has devoted his energies to developing and integrating web-based systems. In doing so he has become knowledgeable in the workings of many tools of the trade; Linux, FreeBSD, Apache, Perl, PHP, PostgreSQL and MySQL among others.

Paul has also devoted part of his professional time to sharing his experience with other developers as time permits. In recent years, he has contributed his technical knowledge at formal and informal settings. Some formal settings include presenting at technical conferences such as LinuxWorld Conference & Expo, O'Reilly Open Source Convention and ApacheCon and writing technical articles for online journals such as Technorati, Apache Week, Daemon News, O'Reilly's ONLamp.com and LinuxDevCenter.com as well as contributing to print titles such as Professional Apache Security and Beginning Unix from Wrox. He has also maintains a personal website and blog.

 

Customer Reviews

1 Review
5 star:
 (1)
4 star:    (0)
3 star:    (0)
2 star:    (0)
1 star:    (0)
 
 
 
 
 
Average Customer Review
5.0 out of 5 stars (1 customer review)
 
 
 
 
Share your thoughts with other customers:
Most Helpful Customer Reviews

10 of 10 people found the following review helpful:
5.0 out of 5 stars Lots of value for the money, February 2, 2003
By 
Steve Hill (Western Australia) - See all my reviews
This review is from: Professional Apache Security (Programmer to Programmer) (Paperback)
When I bought this book, I wasn't quite sure it would be all that useful to me. Once I got into it, I discovered how good it was.

I didn't find the first two chapters particularly useful, but from the third onwards it was simply enlightening. Reading chapter 3 I finally understood what Cross Site Scripting attacks were, and made clear how important it is to know stuff (HTTP in particular) in if you are serious about security (and about system administration in general).

The chapter about configuring Apache in Jail was great, and so it was the chapter about mod_rewrite . In general, the whole book was fantastic, and explained so much about security and Apache. In general, I didn't think there was so much to know about security and Apache, until reading this book that showed them to me so clearly.

I would have liked more depth in some of the chapters (like "Logging", that is very interesting but probably not detailed enough), but overall this book was a great buy.

A colleague of mine is a very experienced system administrator and said that you would find out about all that stuff slowly, working and looking up stuff quite a lot. I found that this book put my on a different level, closer to a senior system administrator.

Good buy!

Help other customers find the most helpful reviews 
Was this review helpful to you? Yes No

Share your thoughts with other customers: Create your own review
 
 
 
Only search this product's reviews



Tag this product

 (What's this?)
Think of a tag as a keyword or label you consider is strongly related to this product.
Tags will help all customers organize and find favorite items.
Your tags: Add your first tag
 

Sell a Digital Version of This Book in the Kindle Store

If you are a publisher or author and hold the digital rights to a book, you can sell a digital version of it in our Kindle Store. Learn more

Customer Discussions

This product's forum
Discussion Replies Latest Post
No discussions yet

Ask questions, Share opinions, Gain insight
Start a new discussion
Topic:
First post:
Prompts for sign-in
 

Search Customer Discussions
Search all Amazon discussions
   


Listmania!


Create a Listmania! list

So You'd Like to...


Create a guide


Look for Similar Items by Category


Look for Similar Items by Subject