Network Security Consulting Agency Since 1989 - Specialized in Unix, Windows, TCP/IP and Internet
You are here
:
Home
>
Resources
>
Lectures
> Apache and web servers security
Search
:
Services
Skills & Expertise
Consulting
ISO 27001 services
Vulnerabilities monitoring
Audit & Assessment
Penetration tests
Vunerability assessment (TSAR)
Technical assistance
Training courses
E-learning
Conferences
Agenda
Past events
Tutorials
Resources
Thematic index
Tips
Lectures
Courses
Articles
Tools (download)
Vulnerability watch
Company
Hervé Schauer
Job opportunities
Credentials
History
Partnerships
Associations
Press and
communication
HSC Newsletter
Press review
Press releases
Publications
Contacts
How to reach us
Specific inquiries
Directions to our office
Hotels near our office
Apache and web servers security
Access to the content
Beginning of the presentation
PDF version
[1,7MB]
Description
Web servers security and reasons to use apache. Secure installation. Apache as a reverse proxy. Web application security and HTTPS.
Context & Dates
Talk made during Linux Expo Paris 2002, on 1
st
February 2002.
Author
Frédéric Lavécot
Type
27 slides [
-
]
Abstract &
Table of content
Flyleaf
Plan
Apache - présentation
Apache - aujoud'hui
Achape - forces
La sécurisation est un processus
Mises à jour de sécurité
Se tenir au courant
Informations de sécurité généralistes
Installation d'Apache 1/2
Installation d'Apache 2/2
Posibiltés de configuration avancées
Authentification
HTTPS
HTTPS n'est pas une sécurité contre :
Exemple d'attaque sur HTTPS 1/2
Exemple d'attaque sur HTTPS 2/2
Reverse Proxy
Filtrage d'URL et de contenu
mod_rewrite
mod_rewrite : Exemples 1/2
mod_rewrite : Exemples 2/2
CGI wrapper
Autres possibilités
Sécurité des applications
Gestion des sessions
Rappel de ce qui a été traité
Related documents
Apache
Webshells, real threat for information systems ?
[1 December 2009 -
]
Configuring and using modsecurity2
[24 April 2007 -
]
Presentation of Apache ModSecurity module
[14 June 2006 -
]
Apache and module management
[17 October 2003 - ]
HTTP/HTTPS authentication methods
[10 March 2003 -
]
Apache: Virtual hosts and SSL (mod_ssl)
[21 December 2001 -
]
Apache as a reverse proxy
[11 November 2000 -
]
Web
Web Servers and applications Security
Webshells, real threat for information systems ?
[1 December 2009 -
]
Security issue seen in enterprises web applications
[27 November 2008 -
]
Application security
[23 October 2008 -
]
Feedback from PHP applications assessment
[21 November 2007 -
]
Evolution of Cross-Site Request Forgery Attacks
[1 June 2007 -
]
Encrypting hostile Web content over HTTP
[31 May 2007 -
]
Web 2.0 : more ergonomic... and less secure ?
[22 May 2007 -
]
Configuring and using modsecurity2
[24 April 2007 -
]
Presentation of Apache ModSecurity module
[14 June 2006 -
]
Database and ERP security
[15 June 2005 -
]
SSL VPN connection multiplexing techniques
[7 April 2005 -
]
PHP and security
[27 November 2003 -
]
Web Services and Security
[10 September 2003 -
]
HTTP/HTTPS authentication methods
[10 March 2003 -
]
The cross-site scripting
[27 February 2003 -
]
DBMS and security
[1 April 2002 -
]
Implementing filtering on a reverse HTTP proxy using mod_eaccess
[3 September 2001 -
]
Subweb tool
[HTTP reverse proxy -
]
Babelweb tool
[Automatic information retrieving from of a web server -
]
Universal CGI wrapper
[5 August 2001 -
]
Why HTTPS is not web security
[7 May 2001 -
]
Filtering URLs in a reverse proxy
[5 May 2001 -
]
Hacking web servers
[14 March 2001 -
]
Why a reverse proxy
[13 February 2001 -
]
Apache as a reverse proxy
[11 November 2000 -
]
Secure internet services (email, DNS, web) under Linux
[26 September 2000 -
]
Secure internet services (email, DNS, web) under Linux
[26 April 2000 -
]
Secure Internet services (email, DNS, web) under Linux
[1 February 2000 -
]
Netscape
[16 January 1996 -
]
Network Services
Secure internet services (email, DNS, web) under Linux
[26 September 2000 -
]
Secure internet services (email, DNS, web) under Linux
[26 April 2000 -
]
Secure Internet services (email, DNS, web) under Linux
[1 February 2000 -
]
Copyright
© 2002, Hervé Schauer Consultants, all rights reserved.
Last modified on 14 January 2003 at 12:09:15 CET - webmaster@hsc.fr
Information on this server
- © 1989-2010 Hervé Schauer Consultants