ModSecurity is a module running on Apache and is based on linux server. It will help users learn about various computer security vulnerabilities like SQL injection, cross-site scripting attacks, cross-site request forgeries, null byte attacks, and many more so that one knows how attackers operate. It will also help one find the geographical location of an attacker and send alert emails when attacks are discovered.
You can read an exclusive chapter here:http://www.packtpub.com/files/4749-modsecurity-sample-chapter-3-performance.pdf
Real-life case studies are used to illustrate the dangers on the Web today – you will for example learn how the recent worm that hit Twitter works, and how you could have used ModSecurity to stop it in its tracks. The mechanisms behind these and other attacks are described in detail, and you will learn everything you need to know to make sure your server and web application remain unscathed on the increasingly dangerous web. Have you ever wondered how attackers figure out the exact web server version running on a system? They use a technique called HTTP fingerprinting, and you will learn about this in depth and how to defend against it by flying your web server under a “false flag”.
Users can learn to compile ModSecurity from source and install it on a Linux system and also find out how to prevent the source code of their web application being shown to the world if something goes wrong with their server configuration They would also discover the real IP address of an attacker using ModSecurity, even if the attacker is behind a proxy server.
With lots of easy to follow examples and step-by-step instructions, this book is perfect for system administrators or anyone running an Apache web server who wants to learn how to secure their server. The book is out now and available at Packt. To read more about it, please visit: http://www.packtpub.com/modsecurity-2-5/book
Badminton Equipment