当前位置:网站首页>全国职业院校技能大赛网络安全竞赛——Apache安全配置详解
全国职业院校技能大赛网络安全竞赛——Apache安全配置详解
2022-07-24 18:28:00 【旺仔Sec】
Apache安全配置
任务环境说明:
- 服务器场景:A-Server
- 服务器场景操作系统: Linux
- 服务器用户名:root;密码:123456
- 打开服务器场景(A-Server),通过命令行清除防火墙规则。在服务器场景上查看apache版本,将查看到的服务版本字符串完整提交;
Flag=Apache/2.2.23 (Unix)

- 检测服务器场景中此版本apache是否存在显示banner信息漏洞,如果验证存在,修改配置文件将此漏洞进行加固,并重启Apache服务,将此加固项内容字符串(不包含状态)作为flag提交;
Flag=ServerSignature
![]()

- 检测服务器场景配置是否可以浏览系统目录,如果验证存在将此漏洞在Apache配置文件中进行加固,寻找系统根目录/var/www 的配置属性,对该属性的原内容进行权限删除的方式加固,并重启Apache服务,将此加固项删减字符串作为flag提交;
Flag=Indexes


- 合理配置服务器场景apache的运行账户,并在httpd.conf中寻找运行帐户,将本服务配置的账户名称作为flag提交;
Flag=nobody

- 配置服务器场景中httpd.conf,限制禁止访问的文件夹,验证是否可以访问 /var/www/data 目录下index.php,如存在在此漏洞需进行加固,将此加固后完整字符串作为flag提交;(提示:(<Directory /var/www/data>)***</Directory>*号为需要添加内容)
Flag=Deny from all

- 配置服务器场景中httpd.conf,限制一些特殊目录的特定ip访问,如内部接口等。修改对data 目录的配置,重新启动apache 服务。将加固项固定部分作为flag提交;
Flag=allow from

边栏推荐
- 剑指 Offer 21. 调整数组顺序使奇数位于偶数前面
- 1. Typeof view variable type?
- 16. What is the difference between target and currenttarget?
- Mysql——》BufferPool相关信息
- Inoic4 learning notes 2
- 数组扁平化.flat(Infinity)
- A practical scheme of realizing 0.5px on mobile terminal
- File upload vulnerability -.User.ini and.Htaccess
- Tree chain partition board
- Highcharts chart and report display, export data
猜你喜欢

QT—动画框架

Simulation implementation vector

7. Character coding?

jmeter --静默运行

Go language interface and type

Rookie colleagues cost me 2K. Did you recite the secret of salary increase? (collect it quickly!)

4. Basic type and reference type?

Getting started with MySQL database

MySQL - bufferpool related information

Calling startActivity() from outside of an Activity context requires the FLAG_ ACTIVITY_ NEW_ TASK flag
随机推荐
Guess JWT keyword
Icml2022 Best Paper Award: learning protein reverse folding from millions of predicted structures
Tree chain partition board
The difference between KIB and MIB and KB and MB
Simulation implementation vector
Wechat applet
【校验】只能输入数字(正负数)
Template syntax [easy to understand]
1. Typeof view variable type?
Ionic4 learning notes 7 -- UI component 1 (no practice, direct excerpt)
Inoic4 learning notes 2
Windowing function (1) - top three employees of department salary
JMeter -- silent operation
About the writing method of interface 1 chain interpretation 2. Method execution (finally) must be executed
jmeter -- prometheus+grafana服务器性能可视化
How to prepare for hyperinflation
A practical scheme of realizing 0.5px on mobile terminal
奶头乐理论介绍及个人感悟
缺失值处理
Pytoch's Journey 2: gradient descent