<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[沧海一粟]]></title> 
<link>http://www.dzhope.com/index.php</link> 
<description><![CDATA[Web系统架构与服务器运维,php开发]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[沧海一粟]]></copyright>
<item>
<link>http://www.dzhope.com/post//</link>
<title><![CDATA[安装mod_security加强apache2安全防sql 注入]]></title> 
<author>jed &lt;jed521@163.com&gt;</author>
<category><![CDATA[服务器技术]]></category>
<pubDate>Sun, 16 Jan 2011 07:42:47 +0000</pubDate> 
<guid>http://www.dzhope.com/post//</guid> 
<description>
<![CDATA[ 
	安装modsecurity（mod_security 可以加强apache的安全性特别是在防sql 注入上有很好的效果。）：<br/><div class="code"><br/># tar zxvf<br/>modsecurity-apache-1.9.tar.gz<br/># cd modsecurity-apache-1.9/apache2/ <br/># /apache2/bin/apxs -cia mod_security.c <br/></div><br/><br/>打开httpd.conf加入<br/>查看是否有<br/>LoadModule security_module&nbsp;&nbsp;&nbsp;&nbsp;modules/mod_security.so<br/>如没有则加上去<br/><br/>添加一段mod_security的配置文件<br/><div class="code"><br/>&lt;IfModule mod_security.c&gt;<br/>SecFilterEngine On<br/>SecFilterCheckURLEncoding<br/>On<br/>SecFilterDefaultAction &quot;deny,log,status:500&quot;<br/>#SecFilterForceByteRange<br/>32 126<br/>#SecFilterScanPOST On<br/>SecAuditLog<br/>logs/audit_log<br/>###<br/>SecFilter &quot;&#92;.&#92;./&quot;<br/>#####<br/>SecFilter<br/>/etc/*passwd<br/>SecFilter /bin/*sh<br/><br/>#for css attack<br/>SecFilter &quot;&lt;( &#124;<br/>)*script&quot;<br/>SecFilter &quot;&lt;(.&#124; )+&gt;&quot;<br/>#for sql attack<br/>SecFilter &quot;delete&#91;<br/>&#93;+from&quot;<br/>SecFilter &quot;insert&#91; &#93;+into&quot;<br/>SecFilter &quot;select.+from&quot;<br/>SecFilter<br/>&quot;union&#91; &#93;+from&quot;<br/>SecFilter &quot;drop&#91; &#93;&quot;<br/>&lt;/IfModule&gt;<br/><br/></div><br/>Tags - <a href="http://www.dzhope.com/tags/apache/" rel="tag">apache</a> , <a href="http://www.dzhope.com/tags/mod_security/" rel="tag">mod_security</a>
]]>
</description>
</item><item>
<link>http://www.dzhope.com/post//#blogcomment</link>
<title><![CDATA[[评论] 安装mod_security加强apache2安全防sql 注入]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.dzhope.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>