Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Secure Web Server?
From: long-morrow @ CS . YALE . EDU
Date: Fri, 13 Sep 1996 10:37:25 -0400 (EDT)
To: ChrisP @ steldyn . com, firewalls @ greatcircle . com

ChrisP @
 steldyn .
 com wrote:
>While we are on the subject of secure programs for firewalls, Does
>anybody have any strong feelings for a well coded, secure web server
>software?  I am looking for *nix variant to run on a Linux platform.
>This is intended to be a very tightly locked down machine with only
>http, smtp, and ftp ports open.  Everything else will be shut down and
>blocked.  I have worked with the Apache product and I was satisfied with
>it's performance, but I am wondering if there is anything else out there
>that is tighter and cleaner.  At this point I am not using any CGI so I
>don't need support for that.  > >Chris

Apache running as nobody without any CGI should be fairly secure.
I would also run it in a chroot()d environment (even on a locked down
machine).

Dr. Frederick B. Cohen ( fc @
 all .
 net ) wrote an http daemon last year
designed to be verifiably secure called thttpd.  It only consists of
a small number of lines of source code.  If you don't need a Web
server with lots of bells and whistles ( server side includes, 
server side Java, etc.) which tend to make the server less secure
you may want to look for it.  It should be under http://all.net/ or
http://all.net:8080/ though neither of these URLs is working for me
this morning.

- Morrow


Indexed By Date Previous: Re[3]: SYN floods - possible solution? (fwd)
From: kenng @ kpmg . com
Next: Re: SYN floods - possible solution? (fwd)
From: scs @ lokkur . dexter . mi . us (Steve Simmons)
Indexed By Thread Previous: Secure Web Server?
From: Chris Pugrud <ChrisP @ steldyn . com>
Next: Re: Secure Web Server?
From: Bill Stout <bill . stout @ hidata . com>

Google
 
Search Internet Search www.greatcircle.com