Guidelines for Securing Apache Web Servers
Network Security · 2002
Introduction The Apache Web server is currently the most frequently deployed Web server. After hearing about all the problems with Microsoft’s Internet Information Server (IIS), you may assume that Apache must be considerably easier to secure. This assumption is to some degree true — although Apache is by no means perfect from a security perspective, you will not have to do as many things to secure your Apache server(s). In fact, ensuring that scripts that run on your Web server are secure is likely to be your greatest challenge — creating secure scripts is a challenge, anyway, no matter what Web server you use. Still, you’ll have to do some work to make Apache able to resist most attacks. These guidelines present the measures needed to achieve baseline security in Apache Web servers. To secure your Apache Web server, you’ll need to pay attention to six major areas: • Obtaining as secure a version of Apache as possible. • Securing the underlying operating system. • Configuring your server correctly. • Running only the features and services that you genuinely need. • Ensuring that CGI or other scripts are written properly. • Ensuring that major vulnerabilities are patched.