Apache Web Server Security

An increasing number of attacks on high-profile websites show that web security is still one of the most critical issues to be tackled by any business that has a web presence and conducts operations online.

If your web server and/or web applications are vulnerable to attacks, you can be giving a free access to hackers to access sensitive information stored in your backend database.

One of the elements of your network infrastructure that could be vulnerable to attacks is the web server program. A web server program or web server engine runs a service which listens for, and responds to, web requests made by users via their browser. The most widely used web server engines are Apache and Microsoft IIS. These web server programs could very well exhibit security flaws or vulnerabilities, which, for example, could allow a malicious remote user access to your operating system with privileges which are more wide-ranging than those normally provided to a web browser request.

Furthermore, Apache requires a server-side scripting engine (e.g., PHP, ASP, ASP.NET, JSP) if the website is dynamic or if, for example, certain pages require the user to submit personal information such as their name, email address and credit card details. Web security best practice requires regular auditing to check for scripting engine vulnerabilities, as well as, ensuring that users cannot input character combinations that could exploit these or other weaknesses to eventually gain access to sensitive data.

Acunetix Web Vulnerability Scanner and Web Server Security
Acunetix Web Vulnerability Scanner ensures website security by automatically checking for SQL injection, Cross site scripting , and Apache web server vulnerabilities. It checks password strength on authentication pages and automatically audits shopping carts, forms, dynamic content and other web applications. As the scan is being completed, the software produces detailed reports that highlight where these vulnerabilities exist. Take a product tour or download the Free edition today!

Articles on Website Security

Cross Site Scripting - XSS - The Underestimated Exploit
Microsoft UK Events Website Hacked
Web Applications: What are they? What of them?
The JavaScript Engine of Acunetix WVS
Payment Card Industry Data Security Standard (PCI) Compliance
Web hacking: An underestimated threat
Web Application Security
Web Server Security and Database Server Security
The True Nature of Web Application Security: The Role and Function of Black Box Scanners
Ajax security: Are AJAX applications vulnerable to hack attacks?
SQL Injection: What is it?
Web Security Scanning
IIS Web Server Security
How to check for SQL injection vulnerabilities
Cross Site Scripting Attack
CRLF Injection Attack
Directory Traversal Attacks
Authentication Hacking Attacks
Google hacking
PHP Security / SQL Security - Part 1
PHP / SQL Security - Part 2
PHP / SQL Security - Part 3
PHP / SQL Security - Part 4
PHP / SQL Security - Part 5
PHP / SQL Security - Part 6

White Papers on Web security

The Payment Card Industry Compliance - Securing both Merchant and Customer data.
Web Services - The Technology and its Security Concerns
SQL & PHP Security by Andrew J. Bennieston
Are AJAX Applications Vulnerable to Hack Attacks? The importance of Securing AJAX Web Applications
Auditing Your Web Site Security with Acunetix Web Vulnerability Scanner
The Importance of Web Application Scanning