APACHE SECURITY

APACHE SECURITY

APACHE SECURITY

RISTIC, IVAN

37,63 €
IVA incluido
🚫 No disponible
Editorial:
O´ REILLY
Materia
Informática en inglés
Ubicación
A1-3112
ISBN:
978-0-596-00724-9
37,63 €
IVA incluido
🚫 No disponible
Añadir a favoritos

. Great book, useful for all Apache users, November 3, 2005 Reviewer: Anton Chuvakin (NJ, USA) See all my reviews I thoroughly enjoyed Ivan`s Apache Security , even when I was a reviewer for an unfinished book. I remember how I was eagerly waiting to receive more new chapters from the publisher. The book contains a nice combination of generic web stuff and Apache stuff. It starts with the discussion of security principles, such as defenseindepth and minimum access privilege. Although not new, they are useful for those just entering the field, such as for beginner apache admins. The chapter on Apache`s installation and configuration sounds boring and many might be tempted to skip it. But it does contain a gem: a guide on setting Apache in a chroot jail! PHP, a main web application platform for Apache at the time of this writing, is covered as well. I found some tips on PHP hardening that I didn`t know previously. While the last PHP application I deployed was configured to be `hackable` (it was a honeypot deployment, after all!), I found the tips to be practical. One entertaining chapter is on denialofservice attacks. There are many ways to overwhelm a network server, and Apache is now exception. It`s a mustread for those running highlyavailable sites, where downtime costs a lot. An important chapter covers Apache access control, from basic auth to single signon. Of course, of particular interest to me was a chapter on logging and monitoring, as it is one of my favorite subjects. Ivan did a great job covering not only logging facilities available within the server, but also log centralization, log analysis for security, integrity monitoring and other stuff. Distributed logging with Spread kit is indeed `cool`, just as Ivan mentions. A brief chapter covers the security of the underlying `infrastructure`, such as the OS that Apache runs on. I liked the overview since it is not `generic`, but covers material relevant to running Apache web server. Chapter 1012 are at the center of the book, providing the core of the new material. Those cover web application attacks, web security assessment and web intrusion detection,. The latter is based on Ivan`s famous mod_security Apache module. While web attacks are covered in many places, I think the overview in the book is clear, focused and useful even for those who do web security for a living. As far as the mod_security chapter is concerned, I would read it with most care since it covers a lot of advanced usage tips, not available elsewhere. The book is well written, easy to follow and displays clear writing style. I would strongly recommend it to everybody who is involved in running Apache web servers, web applications or has web security as part of his job responsibility. Obviously, everybody who thinks that this subject is fun should also read it :) Also, check out www.apachesecurity.net for some free chapters, ToC, tools covered in the book, as well as a couple presentations given by Ivan. The book focuses on the defensive side, but mentions various attacks against web infrastructure as well. Anton Chuvakin, Ph.D., GCIA, GCIH, GCFA is a Security Strategist with a major security company. He is an author of the book Security Warrior and a contributor to Know Your Enemy II and the upcoming Hacker`s Challenge III . In his spare time, he maintains his security portal infosecure.org and his blog at O`Reilly. His next book will be about security log analysis.

Artículos relacionados

  • IOS 10 PROGRAMMING FUNDAMENTALS WITH SWIFT
    MATT NEUBURG
    ❌ Agotado

    57,30 €

  • QUANTUM COMPUTING FOR COMPUTER SCIENTISTS
    YANOFSKY, NOSON S
    🚫 No disponible

    107,55 €

  • BIG DATA
    MAYER-SCHÖNBERGER, VIKTOR
    A New York Times bestseller. Longlisted for the Financial Times/Goldman Sachs Business Book of the Year Award. Since Aristotle, we have fought to understand the causes behind everything. But this ideology is fading. In the age of big data, we can crunch an incomprehensible amount of information, providing us with invaluable insights about the what rather than the why. We're jus...
    🚫 No disponible

    23,00 €

  • THE CORE IOS DEVELOPER'S COOKBOOK
    SADUN, ERICA / WARDWELL, RICH
    ❌ Agotado

    48,75 €

  • DRIVEN BY DATA SCIENCE
    FOREMAN, JOHN
    🚫 No disponible

    55,00 €

  • FLIE SYSTEM FORENSIC ANALYSIS
    CARRIER, BRIAN
    Most digital evidence is stored within the computer`s file system, but understanding how file systems work is one of the most technically challenging concepts for a digital investigator because there exists little documentation. Now, security expert Brian Carrier has written the definitive reference for everyone who wants to understand and be able to testify about how file syst...
    🚫 No disponible

    54,28 €