Nathan wrote in earlier with attempts to exploit PHP file inclusion that his server had automatically thwarted. He's promoting the use of mod_security, mod_evasive, fail2ban and suhosin in a Apache/PHP environment.
Since knowledge and experience is a way to win from the bad guys, how about sharing your favorite setup for Apache /PHP security (Basically a "LAMP" environment although I'd rather not focus on the OS part in there) and we'll summarize on this page. Also let us know what you like of the components you use, why they are your favorite etc. mod_securitymod_evasivehttp://www.zdziarski.com/projects/mod_evasive/ fail2banNathan used this tool to ban IP addresses doing repeated 404/501 error results. He catches attempts to hack forums based on PHP this way, and was able to trace it back to owned servers doing those attacks towards him. suhosinhttp://www.hardened-php.net/suhosin.127.html -- |
Swa 760 Posts Feb 4th 2007 |
Thread locked Subscribe |
Feb 4th 2007 1 decade ago |
Sign Up for Free or Log In to start participating in the conversation!