| View previous topic :: View next topic |
| Author |
Message |
bobthebob1234 LXF regular

Joined: Thu Jan 03, 2008 9:38 pm Posts: 1360 Location: A hole in a field
|
Posted: Wed Mar 30, 2011 7:57 pm Post subject: Some (random) server admin related questions |
|
|
Right I have had a boring afternoon so I have been think about a lot of random stuff, and a couple of questions have come to mind, but they don't each deserve their own topics.
Please answer if you have an answer to any!
Here we go!
- I have two servers, both with LAMP stacks on, serving different websites. Would it be better to have one running MySQL and one apache, then I can concentrate on hardening them individually rather than doing something on one and not the other.
- Anyone know of any good online tutorials or books for
- MySQL security/hardening
- Apache security/hardening
- General linux server admin/security/hardening
- Anyone got The Official Ubuntu Server Book (Aug 2010); is it any good (or am I being stupid not checking the subs area for a review)
- Thankfully I have forgotten the rest
- EditRemembered some: Anyone know any good books or tutorials for sql injections and web app security testing (testing mine, not others!)
- How do (PHP) PDO objects stand up to sql injections and other attacks?
_________________ For certain you have to be lost to find the places that can't be found. Elseways, everyone would know where it was
Last edited by bobthebob1234 on Wed Mar 30, 2011 8:21 pm; edited 1 time in total |
|
| Back to top |
|
 |
Dutch_Master LXF regular
Joined: Tue Mar 27, 2007 2:49 am Posts: 2359
|
Posted: Wed Mar 30, 2011 8:17 pm Post subject: |
|
|
1) No, as Apache and mySQL interact locally. It might be possible in theory, but I wonder if the prevention would be worse then the cure then...
2) http://www.google.com
3) Don't learn Ubuntu, learn Linux! ISBN: 978-0-13-148005-6 Admittedly not the cheapest book, but if you take in account the non-necessity of purchasing additional books on various subjects it's quite good value for money!
4) Nothing a quick Google can't solve 
Last edited by Dutch_Master on Wed Mar 30, 2011 8:25 pm; edited 1 time in total |
|
| Back to top |
|
 |
bobthebob1234 LXF regular

Joined: Thu Jan 03, 2008 9:38 pm Posts: 1360 Location: A hole in a field
|
Posted: Wed Mar 30, 2011 8:24 pm Post subject: |
|
|
Thanks
2)i've been googling all afternoon, just wondering if anybody has any personal recommendations
3)I've got a birthday coming up...  _________________ For certain you have to be lost to find the places that can't be found. Elseways, everyone would know where it was |
|
| Back to top |
|
 |
Dutch_Master LXF regular
Joined: Tue Mar 27, 2007 2:49 am Posts: 2359
|
Posted: Wed Mar 30, 2011 8:34 pm Post subject: |
|
|
Can't help you with items 5 and 6, but I've put in a link to the publishers website, listing it at a smidgen below 44 quid. For that you get over 1,300 pages of advice, history and explanations, so do the maths yourself. I have it, and recommend it for study on any serious ICT course... Hunt around for better deals though  |
|
| Back to top |
|
 |
bobthebob1234 LXF regular

Joined: Thu Jan 03, 2008 9:38 pm Posts: 1360 Location: A hole in a field
|
Posted: Wed Mar 30, 2011 8:42 pm Post subject: |
|
|
half price on amazon  _________________ For certain you have to be lost to find the places that can't be found. Elseways, everyone would know where it was |
|
| Back to top |
|
 |
towy71 Moderator

Joined: Wed Apr 06, 2005 3:11 pm Posts: 4176 Location: wild West Wales
|
Posted: Wed Mar 30, 2011 8:53 pm Post subject: |
|
|
I was about to post that exact same comment  _________________ still looking for that door into summer |
|
| Back to top |
|
 |
Arthur_Dent LXF regular
Joined: Mon Jan 02, 2006 11:05 am Posts: 199 Location: London
|
Posted: Thu Mar 31, 2011 11:50 am Post subject: |
|
|
2 & 5 ) I presume you use ModSecurity on your webserver. If not you really should.
I believe that Ivan Ristic's book "Modsecurity Handbook" is very good on the subject of Apache hardening in general and ModSecurity in particular - Although I must stress I haven't read it myself. |
|
| Back to top |
|
 |
bobthebob1234 LXF regular

Joined: Thu Jan 03, 2008 9:38 pm Posts: 1360 Location: A hole in a field
|
Posted: Thu Mar 31, 2011 3:47 pm Post subject: |
|
|
I was going to 'install' (if thats the word) it during easter, I have the book with the ninja on, but must confess I haven't read it yet cos I left it at home  _________________ For certain you have to be lost to find the places that can't be found. Elseways, everyone would know where it was |
|
| Back to top |
|
 |
| View previous topic :: View next topic |
|