<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>opuntia.biz &#187; Apache</title>
	<atom:link href="http://opuntia.biz/tag/apache/feed/" rel="self" type="application/rss+xml" />
	<link>http://opuntia.biz</link>
	<description>Piccoli appunti per grandi appassionati di sistemi open source ...</description>
	<lastBuildDate>Thu, 31 May 2012 07:51:52 +0000</lastBuildDate>
	<language>it</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='opuntia.biz' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>opuntia.biz &#187; Apache</title>
		<link>http://opuntia.biz</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://opuntia.biz/osd.xml" title="opuntia.biz" />
	<atom:link rel='hub' href='http://opuntia.biz/?pushpress=hub'/>
		<item>
		<title>Redirect ad una pagina/sito tramite PHP</title>
		<link>http://opuntia.biz/2010/02/15/redirect-ad-una-paginasito-tramite-php/</link>
		<comments>http://opuntia.biz/2010/02/15/redirect-ad-una-paginasito-tramite-php/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 08:11:11 +0000</pubDate>
		<dc:creator>BoB</dc:creator>
				<category><![CDATA[Linux tips]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://opuntia.biz/?p=406</guid>
		<description><![CDATA[A chi non è capitato di avere la necessità di effettuare un redirect ad un altro sito. Magari fare in modo che chi accedeva alla &#8220;document root&#8221; di un server veniva re-indirizzato a un sito diverso &#8230; Con PHP è semplicissimo: basta creare nella document root del server (sotto /var/www/html) un file index.php ed inserire <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=opuntia.biz&#038;blog=8227010&#038;post=406&#038;subd=rpennol&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A chi non è capitato di avere la necessità di effettuare un redirect ad un altro sito.<br />
Magari fare in modo che chi accedeva alla &#8220;document root&#8221; di un server veniva re-indirizzato a un sito diverso &#8230;<br />
Con PHP è semplicissimo: basta creare nella document root del server (sotto /var/www/html) un file index.php ed inserire le seguenti righe di codice:</p>
<p>&lt;?PHP<br />
header(&#8220;location: <a href="http://www.server.it/">http://www.server.it</a>&#8220;);<br />
?&gt;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rpennol.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rpennol.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rpennol.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rpennol.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rpennol.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rpennol.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rpennol.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rpennol.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rpennol.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rpennol.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rpennol.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rpennol.wordpress.com/406/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rpennol.wordpress.com/406/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rpennol.wordpress.com/406/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=opuntia.biz&#038;blog=8227010&#038;post=406&#038;subd=rpennol&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://opuntia.biz/2010/02/15/redirect-ad-una-paginasito-tramite-php/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f61ec7465405898a903989b59eb20a4f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BoB</media:title>
		</media:content>
	</item>
		<item>
		<title>Mettere in sicurezza un server Linux</title>
		<link>http://opuntia.biz/2010/02/01/mettere-in-sicurezza-un-server-linux/</link>
		<comments>http://opuntia.biz/2010/02/01/mettere-in-sicurezza-un-server-linux/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 11:04:08 +0000</pubDate>
		<dc:creator>BoB</dc:creator>
				<category><![CDATA[InfoSEC]]></category>
		<category><![CDATA[Linux tips]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[httpd.conf]]></category>
		<category><![CDATA[portmap]]></category>
		<category><![CDATA[rpc]]></category>
		<category><![CDATA[www]]></category>

		<guid isPermaLink="false">http://opuntia.biz/?p=371</guid>
		<description><![CDATA[&#8220;Alzare&#8221; un server linux oggi è una operarazione tutto sommato alla portata dei più. Metterlo in sicurezza sicuramente risulta più complesso. Per agevolare i niubbi (e, per certi versi, i &#8220;dopolavoristi&#8221; come dice l&#8217;amico 0disse0) pubblico qualche info per evitare di essere &#8220;bucati&#8221; dopo poco tempo. P.s.: per scoprire le vulnerabilità del proprio server si <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=opuntia.biz&#038;blog=8227010&#038;post=371&#038;subd=rpennol&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>&#8220;Alzare&#8221; un server linux oggi è una operarazione tutto sommato alla portata dei più.<br />
Metterlo in sicurezza sicuramente risulta più complesso.<br />
Per agevolare i niubbi (e, per certi versi, i &#8220;dopolavoristi&#8221; come dice l&#8217;amico 0disse0) pubblico qualche info per evitare di essere &#8220;bucati&#8221; dopo poco tempo.<br />
P.s.: per scoprire le vulnerabilità del proprio server si consiglia di utilizzare Nessus &#8230;</p>
<p><strong>httpd.conf</strong> (Apache/WWW)<br />
<a href="http://httpd.apache.org/docs/2.0/mod/core.html#traceenable">TraceEnable</a> off<br />
This directive overrides the behavior of TRACE for both the core server and mod_proxy. The default TraceEnable on permits TRACE requests per RFC 2616, which disallows any request body to accompany the request. TraceEnable off causes the core server and mod_proxy to return a 405 (Method not allowed) error to the client.<br />
Finally, for testing and diagnostic purposes only, request bodies may be allowed using the non-compliant TraceEnable extended directive. The core (as an origin server) will restrict the request body to 64k (plus 8k for chunk headers if Transfer-Encoding: chunked is used). The core will reflect the full headers and all chunk headers with the response body. As a proxy server, the request body is not restricted to 64k.<br />
<strong><a href="http://httpd.apache.org/docs/2.2/mod/core.html#servertokens">ServerTokens</a></strong><br />
This directive controls whether Server response header field which is sent back to clients includes a description of the generic OS-type of the server as well as information about compiled-in modules.<br />
Si consiglia di commentare il parametro &#8220;<a href="http://httpd.apache.org/docs/2.0/mod/core.html#servertokens">ServerTokens</a>&#8221; in questo modo:<br />
#ServerTokens OS<br />
e di settare da :<br />
ServerSignature Off<br />
a<br />
ServerSignature On<br />
il parametro &#8220;<a href="http://httpd.apache.org/docs/2.0/mod/core.html#serversignature">ServerSignature</a>&#8220;</p>
<p><a href="http://oldsite.to.infn.it/groups/group4/mirror/linux/AppuntiLinux/AL-6.19.85.html"><strong>RPC (Remote procedure control)</strong></a><br />
RPC, acronimo di Remote Procedure Call, è un meccanismo generale per la gestione di applicazioni client/server. Il sistema si basa su un demone, il portmapper, e un file che elenca i servizi disponibili associati al demone relativo. Il portmapper è un classico esempio di un programma che gestisce un servizio di rete in modo autonomo, cioè senza essere controllato da inetd<br />
Si consiglia di stoppare il servizio (service portmap stop) e di non attivare il servizio all&#8217;avvio del server &#8230;</p>
<p><strong>SSLv2 vs. SSLv3</strong><br />
Editare il file /etc/httpd/conf.d/ssl.conf e modificare:</p>
<p>da<br />
SSLProtocol all -SSLv2<br />
a<br />
SSLProtocol -ALL +SSLv3 +TLSv1</p>
<p>da<br />
SSLCipherSuite ALL:!ADH:!EXPORT:!SSLv2:RC4+RSA:+HIGH:+MEDIUM:+LOW<br />
a<br />
SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM</p>
<p>Fare ripartire i servizi che si appoggiano a SSL (Dovecot, Apache ed eventualmente Postfix)<br />
Per testare la funzionalità di SSLv3:</p>
<p> openssl s_client -ssl3 -connect localhost:443<br />
 openssl s_client -tls1 -connect localhost:443</p>
<p>Per controllare se il protocollo SSLv2 è stato correttamente disattivato digitare:</p>
<p> openssl s_client -ssl2 -connect localhost:443</p>
<p>Se correttamente disattivato dovrebbe comparire: </p>
<p><em>CONNECTED(00000003)<br />
29102:error:1407F0E5:SSL routines:SSL2_WRITE:ssl handshake failure:s2_pkt.c:428:</em></p>
<p><strong>/etc/squid.conf</strong> (Squid/Proxy server)<br />
Disabilitare il protocollo gopher<br />
#acl Safe_ports port 70         # gopher</p>
<p><a href="http://www.postfix.org/postconf.5.html#smtp_tls_mandatory_protocols"><strong>/etc/postfix/main.conf</strong></a> (Postfix/SMTP)<br />
Abilitare i protocolli SSLv3 e TLSv1 (sono se si usa autenticazione)</p>
<p>smtp_tls_mandatory_protocols = !SSLv3, !TLSv1</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rpennol.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rpennol.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rpennol.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rpennol.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/rpennol.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/rpennol.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/rpennol.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/rpennol.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rpennol.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rpennol.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rpennol.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rpennol.wordpress.com/371/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rpennol.wordpress.com/371/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rpennol.wordpress.com/371/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=opuntia.biz&#038;blog=8227010&#038;post=371&#038;subd=rpennol&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://opuntia.biz/2010/02/01/mettere-in-sicurezza-un-server-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f61ec7465405898a903989b59eb20a4f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">BoB</media:title>
		</media:content>
	</item>
	</channel>
</rss>
