<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
<channel>
<title><![CDATA[沧海一粟]]></title> 
<link>http://www.dzhope.com/index.php</link> 
<description><![CDATA[Web系统架构与服务器运维,php开发]]></description> 
<language>zh-cn</language> 
<copyright><![CDATA[沧海一粟]]></copyright>
<item>
<link>http://www.dzhope.com/post//</link>
<title><![CDATA[Apache+Php Web安全配置全攻略]]></title> 
<author>jed &lt;jed521@163.com&gt;</author>
<category><![CDATA[服务器技术]]></category>
<pubDate>Fri, 01 Apr 2011 03:11:58 +0000</pubDate> 
<guid>http://www.dzhope.com/post//</guid> 
<description>
<![CDATA[ 
	apache方面:<br/><br/>1.编译源代码，修改默认的banner<br/><br/>2.修改默认的http状态响应码404,503等默认页面<br/><br/>3.访问特殊目录需要密码.htaccess<br/><br/>4.关闭索引目录options -Indexes<br/><br/>5.关闭CGI执行程序options -ExecCGI<br/><br/>6.apache限制目录php_admin_value open_basedir /var/www<br/><br/>7.apache的php扩展名解析漏洞<br/>apache配置文件，禁止.php.这样的文件执行，配置文件里面加入<br/><div class="code"><br/>&lt;Files ~ “&#92;.(php.&#124;php3.)”&gt;<br/>Order Allow,Deny<br/>Deny from all<br/>&lt;/Files&gt;<br/></div><br/>8.apache设置上传目录无执行权限<br/>关闭路径/www/home/upload的php解析：<br/><div class="code"><br/>&lt;Directory “/www/home/upload”&gt;<br/>&lt;Files ~ “.php”&gt;<br/>Order allow,deny<br/>Deny from all<br/>&lt;/Files&gt;<br/>&lt;/Directory&gt;<br/></div><br/>PHP方面:<br/><br/>1.配置文件php.ini设置register_globals = Off。（防止变量滥用）<br/><br/>2.magic_quotes_gpc=On还是必须的了，咱可以程序处理好，客户不能- – ！！<br/><br/>3.safe_mode是唯一PHP_INI_SYSTEM属性，必须通过php.ini或httpd.conf来设置。要启用safe_mode，只需修改php.ini：safe_mode = On（避免本地包含、文件打开、命令执行）<br/><br/>4.如非特殊需要，一定要关闭PHP的远程文件打开功能。修改php.ini文件（避免远程包含漏洞）<br/><br/>5.防注入,在php.ini中，找到此节：<br/><div class="code"><br/>; Automatically add files before or after any PHP document.<br/>;auto_prepend_file = “phpids.php”<br/>;auto_append_file = “alert.php”<br/></div><br/>默认是空，请添加所包含的文件。<br/>同时找到：<br/><div class="code"><br/>; UNIX: “/path1:/path2″<br/>;include_path = “.:/php/includes”<br/>;<br/>; Windows: “&#92;path1;&#92;path2″<br/>include_path = “.;F:&#92;PHPnow&#92;htdocs”<br/></div><br/>6.修改display_errors = Off(关闭警告及错误信息,爆路径)<br/><br/>7.disable_function要屏蔽的<br/><div class="code"><br/>disable_functions = phpinfo,exec,system,passthru,shell_exec,escapeshellarg,escapeshellcmd,proc_close,proc_open,dl,popen,show_source<br/></div><br/>8.disable_classes可以禁用某些类，如果有多个用逗号分隔类名，看情况所需<br/><br/>Tags - <a href="http://www.dzhope.com/tags/web%25E5%25AE%2589%25E5%2585%25A8/" rel="tag">web安全</a> , <a href="http://www.dzhope.com/tags/apache/" rel="tag">apache</a> , <a href="http://www.dzhope.com/tags/php/" rel="tag">php</a>
]]>
</description>
</item><item>
<link>http://www.dzhope.com/post//#blogcomment</link>
<title><![CDATA[[评论] Apache+Php Web安全配置全攻略]]></title> 
<author> &lt;user@domain.com&gt;</author>
<category><![CDATA[评论]]></category>
<pubDate>Thu, 01 Jan 1970 00:00:00 +0000</pubDate> 
<guid>http://www.dzhope.com/post//#blogcomment</guid> 
<description>
<![CDATA[ 
	
]]>
</description>
</item>
</channel>
</rss>