Frequently Asked Questions
9-5
Protecting Web Site From Hackers
There are many attacks, and new attacks are invented everyday. Following are some
general guidelines for securing your site. You can never be completely secure, but
you can avoid being an easy target.
■
Use a commercial firewall between your ISP and your Web server. Recognize,
however, that not all hackers are outside your organization.
■
Use switched ethernet to limit the amount of traffic a compromised server can
sniff. Use additional firewalls between Web server machines and highly
sensitive internal servers running database and enterprise applications.
■
Remove unnecessary network services such as RPC, Finger, telnet from your
server machine.
■
Carefully validate all input from Web forms. Be especially wary of long input
strings and input that contains non-printable characters, HTML tags, or
javascript tags.
■
Encrypt or randomize the contents of cookies that contain sensitive information.
For example, it should be difficult to guess a valid sessionID to prevent a hacker
from hijacking a valid session.
■
Check often for security patches for all your system and application software,
and install them as soon as possible. Be sure these patches come from bona fide
sources; download from trusted sites and verify the cryptographic checksum.
■
Use an intrusion detection package to monitor for defaced Web pages, viruses,
and presence of “rootkits” that indicate hackers have broken in. If possible,
mount system executables and Web content on read-only file systems.
■
Have a “forensic analysis” package on hand to capture evidence of a break in as
soon as detected. This aids in prosecution of the hackers.
Содержание HTTP Server
Страница 1: ...Oracle HTTP Server Administrator s Guide 10g Release 1 10 1 Part No B12255 01 December 2003 ...
Страница 12: ...xii ...
Страница 22: ...xxii ...
Страница 30: ...Starting Stopping and Restarting Oracle HTTP Server 1 8 Oracle HTTP Server Administrator s Guide ...
Страница 38: ...About htaccess Files 2 8 Oracle HTTP Server Administrator s Guide ...
Страница 52: ...Getting Information about Processes 4 8 Oracle HTTP Server Administrator s Guide ...
Страница 60: ...Configuring Reverse Proxies and Load Balancers 5 8 Oracle HTTP Server Administrator s Guide ...
Страница 70: ...Specifying Log Files 6 10 Oracle HTTP Server Administrator s Guide ...
Страница 164: ...Security Services Implemented Within Oracle HTTP Server 8 34 Oracle HTTP Server Administrator s Guide ...
Страница 170: ...9 6 Oracle HTTP Server Administrator s Guide ...
Страница 178: ...opmn xml A 8 Oracle HTTP Server Administrator s Guide ...
Страница 211: ...Glossary 9 X 509 Public keys can be formed in various data formats The X 509 v3 format is one such popular format ...
Страница 212: ...Glossary 10 ...
Страница 224: ...Index 12 ...