Apache Security Secrets: Revealed (Again)

Mark J. Cox · 2003

Some of the press say that the Apache Web server is more secure than IIS, others that it has had as many incidents as competitive Web servers, but are either of these statements true? In this paper which accompanies a presentation at ApacheCon 2003 we don’t directly answer those questions but instead take a look through the security vulnerabilities that have affected Apache to date, looking at how they work, which are relevant, and categorising their severity and exploitability. We look at how important it is to be prepared for a vulnerability in the Apache web server and come up with a framework for a security policy.

Read the paper · More papers on PaperTik