{"id":36340,"date":"2023-09-09T20:54:18","date_gmt":"2023-11-17T14:00:38","guid":{"rendered":"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/"},"modified":"2024-05-03T22:57:39","modified_gmt":"2024-05-03T14:57:39","slug":"apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/","title":{"rendered":"Apache\u5b89\u5168\u914d\u7f6e"},"content":{"rendered":"<h1>\u7efc\u8ff0<\/h1>\n<p>\u603b\u7ed3\u4e86\u53ef\u4ee5\u5728Apache\u914d\u7f6e\u4e2d\u901a\u7528\u7684\u5b89\u5168\u8bbe\u7f6e\u53ca\u5176\u5404\u4e2a\u9879\u76ee\u3002<\/p>\n<h2>\u8bbe\u5b9a\u793a\u4f8b\u3002<\/h2>\n<h3>\u5fc5\u987b\u8bbe\u7f6e<\/h3>\n<pre class=\"post-pre\"><code>cat &lt;&lt; _EOF_ &gt; \/etc\/httpd\/conf.d\/security.conf\r\n<span class=\"c\"># \u30d0\u30fc\u30b8\u30e7\u30f3\u60c5\u5831\u306e\u96a0\u853d<\/span>\r\n<span class=\"nc\">ServerTokens<\/span> Prod \r\n<span class=\"ss\">Header<\/span> <span class=\"ss\">unset<\/span> \"X-Powered-By\"\r\n<span class=\"c\"># httpoxy \u5bfe\u7b56<\/span>\r\n<span class=\"nc\">RequestHeader<\/span> <span class=\"ss\">unset<\/span> <span class=\"ss\">Proxy<\/span>\r\n<span class=\"c\"># \u30af\u30ea\u30c3\u30af\u30b8\u30e3\u30c3\u30ad\u30f3\u30b0\u5bfe\u7b56<\/span>\r\n<span class=\"nc\">Header<\/span> <span class=\"ss\">append<\/span> X-Frame-Options SAMEORIGIN\r\n<span class=\"c\"># XSS\u5bfe\u7b56<\/span>\r\n<span class=\"nc\">Header<\/span> <span class=\"ss\">set<\/span> X-XSS-Protection \"1; mode=block\"\r\n<span class=\"nc\">Header<\/span> <span class=\"ss\">set<\/span> X-Content-Type-Options nosniff\r\n<span class=\"c\"># XST\u5bfe\u7b56<\/span>\r\n<span class=\"nc\">TraceEnable<\/span> <span class=\"ss\">Off<\/span>\r\n\r\n<span class=\"p\">&lt;<\/span><span class=\"nl\">Directory<\/span><span class=\"sr\"> \/var\/www\/html<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"c\"># .htaccess \u306e\u6709\u52b9\u5316<\/span>\r\n    <span class=\"nc\">AllowOverride<\/span> <span class=\"ss\">All<\/span>\r\n    <span class=\"c\"># \u30d5\u30a1\u30a4\u30eb\u4e00\u89a7\u51fa\u529b\u306e\u7981\u6b62<\/span>\r\n    <span class=\"nc\">Options<\/span> -Indexes\r\n    <span class=\"c\"># Apache 2.2\u4ee5\u524d\u306e\u5bfe\u7b56<\/span>\r\n    <span class=\"p\">&lt;<\/span><span class=\"nl\">IfVersion<\/span><span class=\"sr\"> &lt; 2.3<\/span><span class=\"p\">&gt;\r\n<\/span>        <span class=\"c\"># \u30d0\u30fc\u30b8\u30e7\u30f3\u60c5\u5831\u306e\u96a0\u853d<\/span>\r\n        <span class=\"nc\">ServerSignature<\/span> <span class=\"ss\">Off<\/span>\r\n        <span class=\"c\"># ETag\u306einode\u60c5\u5831\u306e\u96a0\u853d<\/span>\r\n        <span class=\"nc\">FileETag<\/span> <span class=\"ss\">MTime<\/span> <span class=\"ss\">Size<\/span>\r\n    <span class=\"p\">&lt;\/<\/span><span class=\"nl\">IfVersion<\/span><span class=\"p\">&gt;\r\n&lt;\/<\/span><span class=\"nl\">Directory<\/span><span class=\"p\">&gt;\r\n<\/span>\r\n<span class=\"p\">&lt;<\/span><span class=\"nl\">Directory<\/span><span class=\"sr\"> \"\/var\/www\/cgi-bin\"<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"p\">&lt;<\/span><span class=\"nl\">IfVersion<\/span><span class=\"sr\"> &lt; 2.3<\/span><span class=\"p\">&gt;\r\n<\/span>        <span class=\"nc\">ServerSignature<\/span> <span class=\"ss\">Off<\/span>\r\n        <span class=\"nc\">FileETag<\/span> <span class=\"ss\">MTime<\/span> <span class=\"ss\">Size<\/span>\r\n    <span class=\"p\">&lt;\/<\/span><span class=\"nl\">IfVersion<\/span><span class=\"p\">&gt;\r\n&lt;\/<\/span><span class=\"nl\">Directory<\/span><span class=\"p\">&gt;\r\n<\/span>_EOF_\r\n<\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"nb\">cat<\/span> \/dev\/null <span class=\"o\">&gt;<\/span> \/etc\/httpd\/conf.d\/autoindex.conf <span class=\"p\">;<\/span>\r\n<span class=\"nb\">cat<\/span> \/dev\/null <span class=\"o\">&gt;<\/span> \/etc\/httpd\/conf.d\/welcome.conf <span class=\"p\">;<\/span>\r\n<\/code><\/pre>\n<h4>\u8bf7\u6ce8\u610f\u8fd9\u4e9b\u4e8b\u9879<\/h4>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u5916\u90e8\u30b5\u30a4\u30c8\u304b\u3089iframe\u3067\u547c\u3073\u51fa\u3057\u3067\u304d\u306a\u304f\u306a\u308b<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Apache 2.2 \u306e\u5834\u5408 ServerSignature \u306f Directory \u30c7\u30a3\u30ec\u30af\u30c6\u30a3\u30d6\u5185\u3067\u6307\u5b9a\u3057\u306a\u3044\u3068\u4e0a\u66f8\u304d\u3055\u308c\u306a\u3044\u3002<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">\u73fe\u72b6\u306e\u4e0a\u8a18\u8a2d\u5b9a\u3067\u306f Apache 2.2 \u3067\u4ee5\u4e0b\u304c\u4e0a\u66f8\u304d\u3055\u308c\u306a\u3044<\/ul>\n<\/li>\n<\/ul>\n<p>Options -Indexes<br \/>\n&lt;Directory &#8220;\/var\/www\/cgi-bin&#8221;&gt;<\/p>\n<h3>\u96a8\u610f\u8a2d\u5b9a<\/h3>\n<pre class=\"post-pre\"><code>cat &lt;&lt; _EOF_ &gt; \/etc\/httpd\/conf.d\/security-strict.conf\r\n<span class=\"c\"># DoS \u653b\u6483\u5bfe\u7b56<\/span>\r\n<span class=\"nc\">LimitRequestBody<\/span> 10485760\r\n<span class=\"nc\">LimitRequestFields<\/span> 50\r\n<span class=\"c\"># slowloris \u5bfe\u7b56<\/span>\r\n<span class=\"nc\">RequestReadTimeout<\/span> header=20-40,MinRate=500 body=20,MinRate=500\r\n\r\n<span class=\"c\"># HTTP\u30e1\u30bd\u30c3\u30c9\u306e\u5236\u9650<\/span>\r\n<span class=\"p\">&lt;<\/span><span class=\"nl\">Directory<\/span><span class=\"sr\"> \/var\/www\/html<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"p\">&lt;<\/span><span class=\"nl\">IfVersion<\/span> <span class=\"p\">&gt;<\/span> 2.4&gt;\r\n        <span class=\"nc\">Require<\/span> method GET POST\r\n    <span class=\"p\">&lt;\/<\/span><span class=\"nl\">IfVersion<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"p\">&lt;<\/span><span class=\"nl\">IfVersion<\/span><span class=\"sr\"> &lt; 2.3<\/span><span class=\"p\">&gt;\r\n<\/span>        <span class=\"p\">&lt;<\/span><span class=\"nl\">Limit<\/span><span class=\"sr\"> GET POST<\/span><span class=\"p\">&gt;\r\n<\/span>            <span class=\"nc\">Order<\/span> allow,deny\r\n            <span class=\"nc\">Allow<\/span> <span class=\"ss\">from<\/span> <span class=\"ss\">all<\/span>\r\n        <span class=\"p\">&lt;\/<\/span><span class=\"nl\">Limit<\/span><span class=\"p\">&gt;\r\n<\/span>        <span class=\"p\">&lt;<\/span><span class=\"nl\">LimitExcept<\/span><span class=\"sr\"> GET POST<\/span><span class=\"p\">&gt;\r\n<\/span>            <span class=\"nc\">Order<\/span> deny,allow\r\n            <span class=\"nc\">Deny<\/span> <span class=\"ss\">from<\/span> <span class=\"ss\">all<\/span>\r\n        <span class=\"p\">&lt;\/<\/span><span class=\"nl\">LimitExcept<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"p\">&lt;\/<\/span><span class=\"nl\">IfVersion<\/span><span class=\"p\">&gt;\r\n&lt;\/<\/span><span class=\"nl\">Directory<\/span><span class=\"p\">&gt;\r\n<\/span>\r\n<span class=\"p\">&lt;<\/span><span class=\"nl\">Directory<\/span><span class=\"sr\"> \"\/var\/www\/cgi-bin\"<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"p\">&lt;<\/span><span class=\"nl\">IfVersion<\/span> <span class=\"p\">&gt;<\/span> 2.4&gt;\r\n        <span class=\"nc\">Require<\/span> <span class=\"ss\">all<\/span> denied\r\n    <span class=\"p\">&lt;\/<\/span><span class=\"nl\">IfVersion<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"p\">&lt;<\/span><span class=\"nl\">IfVersion<\/span><span class=\"sr\"> &lt; 2.3<\/span><span class=\"p\">&gt;\r\n<\/span>        <span class=\"nc\">Order<\/span> allow,deny\r\n        <span class=\"nc\">Deny<\/span> <span class=\"ss\">from<\/span> <span class=\"ss\">all<\/span>\r\n    <span class=\"p\">&lt;\/<\/span><span class=\"nl\">IfVersion<\/span><span class=\"p\">&gt;\r\n&lt;\/<\/span><span class=\"nl\">Directory<\/span><span class=\"p\">&gt;\r\n<\/span>_EOF_\r\n<\/code><\/pre>\n<h4>\u8bf7\u6ce8\u610f\u7684\u4e8b\u9879<\/h4>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">GET\/POST \u4ee5\u5916\u4f7f\u3048\u306a\u304f\u306a\u308b<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">cgi-bin \u304c\u4f7f\u3048\u306a\u304f\u306a\u308b<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\u73fe\u72b6\u306e\u4e0a\u8a18\u8a2d\u5b9a\u3067\u306f Apache 2.2 \u3067 &lt;Directory &#8220;\/var\/www\/cgi-bin&#8221;&gt; \u304c\u4e0a\u66f8\u304d\u3055\u308c\u306a\u3044<\/ul>\n<h2>\u5e0c\u671b\u8bbe\u5b9a\u4e00\u4e2a\u73af\u5883<\/h2>\n<p>\u672c\u6587\u4e3b\u8981\u662f\u5173\u4e8e\u4f7f\u7528CentOS\u7684Yum\u5b89\u88c5Apache\u7684\u4fe1\u606f\uff0c\u5047\u8bbe\u8fdb\u884c\u9002\u5f53\u7684\u73af\u5883\u8c03\u6574\u3002\u76ee\u6807Apache\u7248\u672c\u4e3a\u5f53\u524d\u652f\u6301\u76842.4\u548c2.2.\u6709\u5173\u8be6\u7ec6\u4fe1\u606f\uff0c\u8bf7\u53c2\u8003Apache HTTP Server\u7684\u652f\u6301\u671f\u9650\u3002<\/p>\n<h3>\u9ed8\u8ba4\u503c\u9a8c\u8bc1\u7684\u73af\u5883\u4fe1\u606f<\/h3>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">CentOS 7.2.1511 (CentOS-7-x86_64-Minimal-1511.iso)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Apache 2.4.6 (yum install httpd)<\/ul>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<ul class=\"post-ul\">PHP 5.4.16 (yum install php)<\/ul>\n<h2>\u653f\u7b56<\/h2>\n<ul class=\"post-ul\">\n<li style=\"list-style-type: none;\">\n<ul class=\"post-ul\">Yum \u306b\u3088\u308b\u30d1\u30c3\u30b1\u30fc\u30b8\u7ba1\u7406<\/ul>\n<\/li>\n<\/ul>\n<p>\u30bd\u30fc\u30b9\u304b\u3089\u30b3\u30f3\u30d1\u30a4\u30eb\uff1f\u305d\u3093\u306a\u3082\u306e\u30a6\u30c1\u306b\u306f\u306a\u3044\u3088\u3002<\/p>\n<p>\u30c7\u30d5\u30a9\u30eb\u30c8\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u306b\u6975\u529b\u624b\u3092\u5165\u308c\u306a\u3044<br \/>\n\u30b3\u30b9\u30c8\u30d1\u30d5\u30a9\u30fc\u30de\u30f3\u30b9\u512a\u5148<\/p>\n<p>\u6210\u7acb\u306e\u53ef\u80fd\u6027\u304c\u4f4e\u3044\u8106\u5f31\u6027\u3078\u306e\u5bfe\u5fdc\u3067\u6c4e\u7528\u6027\u3084\u30b7\u30f3\u30d7\u30eb\u3055\u304c\u5931\u308f\u308c\u308b\u3088\u3046\u306a\u8a2d\u5b9a\u306f\u907f\u3051\u308b<\/p>\n<h1>\u8bbe\u5b9a\u9879\u76ee<\/h1>\n<h2>\u9690\u85cf\u60c5\u62a5<\/h2>\n<p>\u5173\u4e8e\u9690\u85cf\u7248\u672c\u7b49\u4fe1\u606f\u7684\u8ba8\u8bba\uff0c\u5927\u81f4\u5b58\u5728\u4e0e\u5b89\u5168\u63aa\u65bd\u7684\u6709\u6548\u6027\u76f8\u5173\u7684\u4e89\u8bba\u3002<\/p>\n<h3>\u7248\u672c\u4fe1\u606f\uff08ServerTokens\uff09<\/h3>\n<pre class=\"post-pre\"><code>Server: Apache\/2.4.6 (CentOS) PHP\/5.4.16\r\n<\/code><\/pre>\n<p>Apache 2.23 \/ 2.44\u7684ServerTokens\u6307\u4ee4\u7684\u9ed8\u8ba4\u503c\u90fd\u662fFull\uff0c\u56e0\u6b64\u5728HTTP\u5934\u4e2d\u4f1a\u8f93\u51faApache\u7684\u7248\u672c\u4fe1\u606f\u5982\u4e0a\u6240\u793a\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nc\">ServerTokens<\/span> Prod\r\n<\/code><\/pre>\n<p>\u901a\u8fc7\u5728 ServerTokens \u6307\u4ee4\u4e2d\u8bbe\u7f6e\u4e3a Prod \u6216 ProductOnly\uff0c\u53ef\u4ee5\u9690\u85cf Apache \u7684\u7248\u672c\u4fe1\u606f\uff0c\u5982\u4e0b\u6240\u793a\u3002<\/p>\n<pre class=\"post-pre\"><code>Server: Apache\r\n<\/code><\/pre>\n<h3>\u670d\u52a1\u5668\u7b7e\u540d<\/h3>\n<pre class=\"post-pre\"><code>Apache\/2.2.15 (CentOS) Server at 192.168.56.101 Port 80\r\n<\/code><\/pre>\n<p>ServerSignature\u6307\u4ee4\u7528\u4e8e\u914d\u7f6e\u670d\u52a1\u5668\u5728\u751f\u6210\u6587\u6863\uff08\u9519\u8bef\u6d88\u606f\u3001mod_proxy\u4e2d\u7684FTP\u76ee\u5f55\u5217\u8868\u3001mod_info\u7684\u8f93\u51fa\u7b49\uff09\u7684\u6700\u540e\u4e00\u884c\u6dfb\u52a0\u4e0a\u8ff0\u8f93\u51fa\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nc\">ServerSignature<\/span> <span class=\"ss\">Off<\/span>\r\n<\/code><\/pre>\n<p>Apache 2.25 \/ 2.46 \u7684\u9ed8\u8ba4\u503c\u5747\u4e3a\u5173\u95ed\u72b6\u6001\uff0c\u4f46\u662f CentOS 6.x \u4e0a\u7684 Apache 2.2 \u6839\u636e\u53d1\u884c\u7248\u7684\u8bbe\u7f6e\u800c\u9ed8\u8ba4\u4e3a\u5f00\u542f\uff0c\u56e0\u6b64\u9700\u8981\u8fdb\u884c\u4fee\u6539\u3002<\/p>\n<p>\u5982\u679c\u6ca1\u6709\u66f4\u6539 httpd.conf \u7684\u8bbe\u7f6e\uff0c\u90a3\u4e48\u5728 &lt;Directory &#8220;\/var\/www\/html&#8221;&gt; \u4e2d\u672a\u6307\u5b9a\u5219\u65e0\u6cd5\u5de5\u4f5c\u3002<\/p>\n<h3>\u7981\u7528TRACE\u65b9\u6cd5\uff08XST\u4fdd\u62a4\uff09<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nc\">TraceEnable<\/span> <span class=\"ss\">Off<\/span>\r\n<\/code><\/pre>\n<p>\u5bf9\u4e8e\u7ed3\u5408\u4e86XSS\u548cTRACE\u65b9\u6cd5\u7684XST\uff08\u8de8\u7ad9\u8ddf\u8e2a\uff09\u653b\u51fb\u7684\u9632\u8303\u63aa\u65bd\u3002<br \/>\n\u867d\u7136\u5b58\u5728\u6cc4\u6f0f\u57fa\u672c\u8ba4\u8bc1ID\u548c\u5bc6\u7801\u7b49\u7684\u5371\u9669\uff0c\u4f46\u653b\u51fb\u6210\u7acb\u6761\u4ef6\u53d7\u9650\u4e8e\u652f\u6301\u5df2\u7ec8\u6b62\u7684\u65e7\u64cd\u4f5c\u7cfb\u7edf\u7b49\u60c5\u51b5\uff0c\u4ec5\u9650\u4e8e\u7279\u5b9a\u60c5\u51b57 8\u3002<br \/>\n\u53e6\u5916\uff0cTRACE\u65b9\u6cd5\u65e0\u6cd5\u901a\u8fc7\u6216\u6307\u4ee4\u52a0\u4ee5\u9650\u5236\u30029<\/p>\n<h3>\u5b9e\u4f53\u6807\u7b7e\uff08ETag\uff09<\/h3>\n<p>\u7531\u4e8e\u8fc7\u53bb\u7684 Apache \u5728\u8f93\u51fa\u5230 HTTP \u5934\u4e2d\u7684 ETag \u4e2d\u5f3a\u5236\u4f7f\u7528 inode \u53f7\uff0c\u56e0\u6b64\u5b58\u5728\u4ece ETag \u5934\u83b7\u53d6\u6587\u4ef6 inode \u53f7\u7684\u98ce\u9669\u3002<br \/>\n\u7136\u800c\uff0c\u7ecf\u9a8c\u8bc1\u548c\u8c03\u67e5\u53d1\u73b0\uff0c\u4ece Apache 2.4.0 \u5f00\u59cb\uff0cMTime Size \u6210\u4e3a\u9ed8\u8ba4\u7684\u503c\uff0c\u56e0\u6b64\u5728 2.4 \u7cfb\u5217\u4e2d\uff0c\u5bf9\u4e8e\u5b89\u5168\u6027\u65b9\u9762\uff0c\u4e0d\u9700\u8981\u62c5\u5fc3\u6b64\u8bbe\u7f6e\u3002<br \/>\n\u5bf9\u4e8e 2.2 \u7cfb\u5217\uff0c\u5efa\u8bae\u6307\u5b9a FileETag MTime Size \u6216 FileETag None\u3002<\/p>\n<p>\u5982\u679c\u5220\u9664ETag\u5e76\u4f7f\u7528Last-Modified\u6807\u5934\uff0cHTTP\u6807\u5934\u7684\u5927\u5c0f\u4f1a\u76f8\u5e94\u51cf\u5c11\u3002\u4e0d\u8f93\u51faETag\u7684\u8bbe\u7f6e\u5982\u4e0b\uff1a<\/p>\n<pre class=\"post-pre\"><code><span class=\"nc\">FileETag<\/span> <span class=\"ss\">None<\/span>\r\n<\/code><\/pre>\n<p>\u5982\u679c\u5728\u4e0a\u8ff0\u8bbe\u7f6e\u4e2dETag\u65e0\u6cd5\u6b63\u5e38\u6d88\u9664\uff0c\u4e5f\u53ef\u4ee5\u901a\u8fc7\u4ee5\u4e0b\u65b9\u5f0f\u6d88\u9664\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nc\">Header<\/span> <span class=\"ss\">unset<\/span> ETag\r\n<\/code><\/pre>\n<h4>\u6587\u4ef6ETag\u8bbe\u7f6e\u7684\u884c\u4e3a\u9a8c\u8bc1<\/h4>\n<div>\n<div class=\"post-table\">FileETagETag(\u672a\u6307\u5b9a)&#8221;220-529841bdd9a78&#8243;MTime Size&#8221;220-529841bdd9a78&#8243;All&#8221;905069-220-529841bdd9a78&#8243;INode&#8221;905069&#8243;MTime&#8221;529830adcea90&#8243;Size&#8221;220&#8243;<\/div>\n<\/div>\n<p>\u516c\u5f0f\u53c2\u8003\u503c\u4ecd\u7136\u88ab\u6807\u8bb0\u4e3aFileETag INode MTime Size\uff0c\u4f46\u5728\u9a8c\u8bc1\u73af\u5883\u4e2d\u9a8c\u8bc1\u65f6\uff0c\u9ed8\u8ba4\u4e3aMTime Size\u3002\u8fd9\u53ef\u80fd\u662f\u7531\u4e8e\u53c2\u8003\u503c\u7684\u66f4\u65b0\u9057\u6f0f\uff0c\u6216\u8005\u53ef\u80fd\u662f\u5728\u53d1\u5e03\u8f6f\u4ef6\u5305\u4e2d\u66f4\u6539\u4e86\u9ed8\u8ba4\u503c\u3002\u5728Hatebu\u4e0a\u6709\u4eba\u63d0\u5230\u4e86\u8fd9\u4e00\u70b9\uff0c\u6240\u4ee5\u6211\u67e5\u770b\u4e86\u6e90\u4ee3\u7801\uff0c\u53d1\u73b0Apache\u672c\u4f53\u7684\u9ed8\u8ba4\u503c\u4ece2.4.0\u5f00\u59cb\u5df2\u7ecf\u6539\u53d8\uff0c\u770b\u6765\u786e\u5b9e\u662f\u53c2\u8003\u503c\u7684\u66f4\u65b0\u9057\u6f0f\u3002\uff08\u6839\u636e@matuu\u7684\u8bf4\u6cd5\uff0c\u82f1\u6587\u7248\u672c\u5df2\u7ecf\u6b63\u786e\u4fee\u590d\uff09<\/p>\n<pre class=\"post-pre\"><code><span class=\"gd\">-&lt;default&gt;FileETag INode MTime Size&lt;\/default&gt;\r\n<\/span><span class=\"gi\">+&lt;default&gt;FileETag MTime Size&lt;\/default&gt;\r\n<\/span> &lt;contextlist&gt;&lt;context&gt;server config&lt;\/context&gt;&lt;context&gt;virtual host&lt;\/context&gt;\r\n &lt;context&gt;directory&lt;\/context&gt;&lt;context&gt;.htaccess&lt;\/context&gt;\r\n &lt;\/contextlist&gt;\r\n &lt;override&gt;FileInfo&lt;\/override&gt;\r\n<span class=\"gi\">+&lt;compatibility&gt;The default used to be \"INode&amp;nbsp;MTime&amp;nbsp;Size\" in 2.3.14 and\r\n+earlier.&lt;\/compatibility&gt;\r\n<\/span><\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"gd\">-#define ETAG_BACKWARD (ETAG_MTIME | ETAG_INODE | ETAG_SIZE)\r\n<\/span> #define ETAG_ALL   (ETAG_MTIME | ETAG_INODE | ETAG_SIZE)\r\n<span class=\"gi\">+\/* This is the default value used *\/\r\n+#define ETAG_BACKWARD (ETAG_MTIME | ETAG_SIZE)\r\n<\/span><\/code><\/pre>\n<pre class=\"post-pre\"><code>     if (ctx-&gt;finfo.filetype != APR_NOFILE) {\r\n          return apr_psprintf(ctx-&gt;pool, \"\\\"%\" APR_UINT64_T_HEX_FMT \"-%\"\r\n<span class=\"gd\">-                            APR_UINT64_T_HEX_FMT \"-%\" APR_UINT64_T_HEX_FMT \"\\\"\",\r\n<\/span><span class=\"gi\">+                            APR_UINT64_T_HEX_FMT \"\\\"\",\r\n<\/span><span class=\"gd\">-                            (apr_uint64_t) ctx-&gt;finfo.inode,\r\n<\/span>                             (apr_uint64_t) ctx-&gt;finfo.size,\r\n                             (apr_uint64_t) ctx-&gt;finfo.mtime);\r\n      }\r\n<\/code><\/pre>\n<h3>X-Powered-By \u6240\u63d0\u4f9b\u7684\u52a8\u529b<\/h3>\n<pre class=\"post-pre\"><code>X-Powered-By: PHP\/5.4.16\r\n<\/code><\/pre>\n<p>\u5982\u679c\u5728HTTP\u8bf7\u6c42\u5934\u4e2d\u8f93\u51fa\u4e86\u50cfPHP\u7248\u672c\u4e4b\u7c7b\u7684\u4fe1\u606f\uff0c\u53ef\u4ee5\u901a\u8fc7\u4ee5\u4e0b\u65b9\u5f0f\u5728Apache\u7aef\u5f3a\u5236\u5220\u9664\u8be5\u8bf7\u6c42\u5934\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nc\">Header<\/span> <span class=\"ss\">unset<\/span> X-Powered-By\r\n<\/code><\/pre>\n<p>\u5728PHP\u7684\u60c5\u51b5\u4e0b\uff0c\u53ef\u4ee5\u901a\u8fc7\u5728php.ini\u6587\u4ef6\u4e2d\u8bbe\u7f6eexpose_php\u6307\u4ee4\u4e3a14\u6765\u9690\u85cfPHP\u7248\u672c\u4fe1\u606f\uff0c\u4f46\u662f\u5728Apache\u670d\u52a1\u5668\u4e0a\u7edf\u4e00\u5f3a\u5236\u5220\u9664\u53ef\u80fd\u66f4\u597d\uff0c\u8fd9\u6837\u53ef\u4ee5\u907f\u514d\u914d\u7f6e\u9057\u6f0f\u7684\u98ce\u9669\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"py\">expose_php<\/span> <span class=\"p\">=<\/span> <span class=\"s\">Off<\/span>\r\n<\/code><\/pre>\n<h3>\u9009\u9879 -Indexes<\/h3>\n<pre class=\"post-pre\"><code><span class=\"p\">&lt;<\/span><span class=\"nl\">Directory<\/span><span class=\"sr\"> \/var\/www\/html<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"nc\">Options<\/span> -Indexes\r\n<span class=\"p\">&lt;\/<\/span><span class=\"nl\">Directory<\/span><span class=\"p\">&gt;\r\n<\/span><\/code><\/pre>\n<p>Apache 2.0\/2.2\/2.4 \u7684 Options \u9ed8\u8ba4\u503c\u90fd\u662f All\u3002<br \/>\n\u5f53\u5728\u76ee\u5f55\u4e2d\u6ca1\u6709\u6307\u5b9a\u7531 DirectoryIndex \u6307\u4ee4\u6240\u8bbe\u5b9a\u7684\u6587\u4ef6\uff08\u5982 index.html\uff09\u65f6\uff0cmod_autoindex \u4f1a\u6574\u7406\u5e76\u8fd4\u56de\u76ee\u5f55\u4e2d\u7684\u6587\u4ef6\u5217\u8868\u3002<\/p>\n<h3>\u81ea\u52a8\u7d22\u5f15\u914d\u7f6e\u6587\u4ef6\u3002<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nb\">cp<\/span> \/dev\/null \/etc\/httpd\/conf.d\/autoindex.conf\r\n<\/code><\/pre>\n<p>\u6216\u8005<\/p>\n<pre class=\"post-pre\"><code><span class=\"o\">&gt;<\/span> \/etc\/httpd\/conf.d\/autoindex.conf\r\n<\/code><\/pre>\n<p>\u5c3d\u7ba1\u8bb0\u5f55\u4e86\u6709\u5173icons\u7684\u914d\u7f6e\u7b49\u4fe1\u606f\uff0c\u4f46\u4e3a\u4e86\u4e0d\u663e\u793a\u76ee\u5f55\u5217\u8868\uff0c\u539f\u5219\u4e0a\u4e0d\u4f7f\u7528\uff0c\u56e0\u6b64\u5220\u9664\u5b83\u3002\u5982\u679c\u5220\u9664\u6587\u4ef6\u672c\u8eab\uff0c\u5219\u5728\u66f4\u65b0\u65f6\u4f1a\u91cd\u65b0\u521b\u5efa\uff0c\u56e0\u6b64\u5c06\u5176\u53d8\u4e3a\u7a7a\u6587\u4ef6\u3002<\/p>\n<h3>\u6b22\u8fce\u8bbe\u7f6e<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nb\">cp<\/span> \/dev\/null \/etc\/httpd\/conf.d\/welcome.conf\r\n<\/code><\/pre>\n<p>\u53c8\u6216\u8005<\/p>\n<pre class=\"post-pre\"><code><span class=\"o\">&gt;<\/span> \/etc\/httpd\/conf.d\/welcome.conf\r\n<\/code><\/pre>\n<p>\u5982\u679c\u5728\u6587\u6863\u6839\u76ee\u5f55\u4e2d\u6ca1\u6709index.html\u6587\u4ef6\u6216\u51fa\u73b0\u6743\u9650\u95ee\u9898\u7b49\u5bfc\u81f4\u88ab\u7981\u6b62\u8bbf\u95ee\u65f6\uff0cCentOS\u6b22\u8fce\u9875\u9762\u4f1a\u663e\u793a\u51fa\u6765\u3002\u4f46\u7531\u4e8e\u8fd9\u662f\u591a\u4f59\u7684\u4fe1\u606f\uff0c\u9700\u8981\u5220\u9664\u3002\u5982\u679c\u50cf\u5220\u9664autoindex.conf\u4e00\u6837\u5220\u9664\u5b83\uff0c\u4f1a\u5728\u66f4\u65b0\u65f6\u91cd\u65b0\u751f\u6210\uff0c\u6240\u4ee5\u9700\u8981\u5c06\u5176\u7f6e\u4e3a\u7a7a\u6587\u4ef6\u3002<\/p>\n<h2>\u5b89\u5168\u8bbe\u7f6e<\/h2>\n<h3>\u5141\u8bb8\u8986\u76d6<\/h3>\n<pre class=\"post-pre\"><code><span class=\"p\">&lt;<\/span><span class=\"nl\">Directory<\/span><span class=\"sr\"> \/var\/www\/html<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"nc\">AllowOverride<\/span> <span class=\"ss\">All<\/span>\r\n<span class=\"p\">&lt;\/<\/span><span class=\"nl\">Directory<\/span><span class=\"p\">&gt;\r\n<\/span><\/code><\/pre>\n<p>\u53ea\u6709\u5728 \/etc\/httpd\/conf.d\/userdir.conf \u7684 &lt;Directory &#8220;\/home\/*\/public_html&#8221;&gt; \u4e2d\u6307\u5b9a\u7684 AllowOverride \u4ee5\u5916\u90fd\u88ab\u8bbe\u7f6e\u4e3a None\uff0c\u6240\u4ee5\u4e3a\u4e86\u4f7f\u7528 .htaccess\uff0c\u9700\u8981\u5355\u72ec\u5141\u8bb8\u6587\u6863\u6839\u76ee\u5f55\u4e0b\u7684\u5185\u5bb9\u3002<\/p>\n<h3>\u9650\u5236HTTP\u65b9\u6cd5<\/h3>\n<pre class=\"post-pre\"><code><span class=\"p\">&lt;<\/span><span class=\"nl\">Directory<\/span><span class=\"sr\"> \/var\/www\/html<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"nc\">Require<\/span> method GET POST\r\n<span class=\"p\">&lt;\/<\/span><span class=\"nl\">Directory<\/span><span class=\"p\">&gt;\r\n<\/span><\/code><\/pre>\n<pre class=\"post-pre\"><code><span class=\"p\">&lt;<\/span><span class=\"nl\">Directory<\/span><span class=\"sr\"> \/var\/www\/html<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"p\">&lt;<\/span><span class=\"nl\">Limit<\/span><span class=\"sr\"> GET POST<\/span><span class=\"p\">&gt;\r\n<\/span>        <span class=\"nc\">Order<\/span> allow,deny\r\n        <span class=\"nc\">Allow<\/span> <span class=\"ss\">from<\/span> <span class=\"ss\">all<\/span>\r\n    <span class=\"p\">&lt;\/<\/span><span class=\"nl\">Limit<\/span><span class=\"p\">&gt;\r\n<\/span>    <span class=\"p\">&lt;<\/span><span class=\"nl\">LimitExcept<\/span><span class=\"sr\"> GET POST<\/span><span class=\"p\">&gt;\r\n<\/span>        <span class=\"nc\">Order<\/span> deny,allow\r\n        <span class=\"nc\">Deny<\/span> <span class=\"ss\">from<\/span> <span class=\"ss\">all<\/span>\r\n    <span class=\"p\">&lt;\/<\/span><span class=\"nl\">LimitExcept<\/span><span class=\"p\">&gt;\r\n&lt;\/<\/span><span class=\"nl\">IfVersion<\/span><span class=\"p\">&gt;\r\n<\/span><\/code><\/pre>\n<h3>\u70b9\u51fb\u52ab\u6301\u9632\u62a4\uff08X-Frame-Options\uff09<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nc\">Header<\/span> <span class=\"ss\">always<\/span> <span class=\"ss\">append<\/span> X-Frame-Options SAMEORIGIN\r\n<\/code><\/pre>\n<p>X-Frame-Options HTTP \u54cd\u5e94\u5934\u53ef\u4ee5\u6307\u793a\u6d4f\u89c8\u5668\u662f\u5426\u5141\u8bb8\u5c06\u9875\u9762\u663e\u793a\u5728 \u6216\u8005 <iframe> \u4e2d\u3002<br \/>\n\u8fd9\u662f\u4ece IE8 \u5f00\u59cb\u5b9e\u65bd\u7684\u9009\u9879\u5934\uff0c\u7528\u4e8e\u9632\u6b62\u70b9\u51fb\u52ab\u6301\u3002<br \/>\n\u5b83\u53ef\u4ee5\u786e\u4fdd\u81ea\u5df1\u7f51\u7ad9\u7684\u5185\u5bb9\u4e0d\u4f1a\u88ab\u5d4c\u5165\u5230\u5176\u4ed6\u7f51\u7ad9\u4e2d\u3002<\/p>\n<div>\n<div class=\"post-table\">\n<thead>\n<tr>\n<th>\u8a2d\u5b9a\u5024<\/th>\n<th>\u5185\u5bb9<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>DENY<\/code><\/td>\n<td>\u30b5\u30a4\u30c8\u5074\u306e\u610f\u56f3\u306b\u95a2\u308f\u3089\u305a\u3001\u30da\u30fc\u30b8\u3092\u30d5\u30ec\u30fc\u30e0\u5185\u306b\u8868\u793a\u3059\u308b\u3053\u3068\u306f\u3067\u304d\u306a\u3044\u3002\u540c\u3058\u30b5\u30a4\u30c8\u306e\u30da\u30fc\u30b8\u3092\u30d5\u30ec\u30fc\u30e0\u5185\u306b\u8aad\u307f\u8fbc\u3080\u3053\u3068\u3082\u4e0d\u53ef\u80fd\u306b\u306a\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td><code>SAMEORIGIN<\/code><\/td>\n<td>\u81ea\u8eab\u3068\u751f\u6210\u5143\u304c\u540c\u3058\u30d5\u30ec\u30fc\u30e0\u5185\u306b\u9650\u308a\u30da\u30fc\u30b8\u3092\u8868\u793a\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u308b\u3002\u5916\u90e8\u30b5\u30a4\u30c8\u306e\u30d5\u30ec\u30fc\u30e0\u5185\u306b\u30da\u30fc\u30b8\u3092\u8aad\u307f\u8fbc\u3080\u3053\u3068\u3092\u4e0d\u53ef\u80fd\u306b\u3059\u308b\u3002<\/td>\n<\/tr>\n<tr>\n<td><code>ALLOW-FROM uri<\/code><\/td>\n<td>\u6307\u5b9a\u3055\u308c\u305f\u751f\u6210\u5143\u306b\u9650\u308a\u3001\u30da\u30fc\u30b8\u3092\u30d5\u30ec\u30fc\u30e0\u5185\u306b\u8868\u793a\u3067\u304d\u308b\u3002Chrome\u3001Safari\u306f\u672a\u5bfe\u5fdc\u3002<sup id=\"fnref17\"><a href=\"#fn17\" title=\"Issue 511521 - chromium - &#96;X-Frame-Options&#96; does not support the &#96;allow-from&#96; directive. - Monorail\">17<\/a><\/sup><\/td>\n<\/tr>\n<\/tbody>\n<\/div>\n<\/div>\n<p>\u5bf9\u4e8e\u652f\u6301X-Frame-Options\u7684\u6d4f\u89c8\u5668\u7248\u672c\uff0c\u9700\u4e3aIE8\u53ca\u4ee5\u4e0a\u3001Firefox 3.6.9\u53ca\u4ee5\u4e0a\u3001Chrome 4.1.249.1042\u53ca\u4ee5\u4e0a\u3001Safari 4\u53ca\u4ee5\u4e0a\u3001Opera 10.50\u53ca\u4ee5\u4e0a\u300218\u5c81\u3002<\/p>\n<p>\u5728\u8c37\u6b4c\u3001\u63a8\u7279\u3001Yahoo! JAPAN\u7b49\u7f51\u7ad9\u4e0a\uff0c\u5df2\u7ecf\u6307\u5b9a\u4e86SAMEORIGIN\u3002\u800c\u5728Facebook\u4e0a\uff0c\u5219\u6307\u5b9a\u4e86DENY\u3002<\/p>\n<h3>X-XSS-Protection\uff08\u8de8\u7ad9\u811a\u672c\u653b\u51fb\u9632\u62a4\uff09<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nc\">Header<\/span> <span class=\"ss\">always<\/span> <span class=\"ss\">set<\/span> X-XSS-Protection \"1; mode=block\"\r\n<\/code><\/pre>\n<p>X-XSS-Protection \u662f\u7528\u4e8e\u63a7\u5236\u6d4f\u89c8\u5668\u7684 XSS \u8fc7\u6ee4\u5668\u529f\u80fd\u7684\u54cd\u5e94\u5934\u3002<br \/>\n0 \u8868\u793a\u7981\u7528\uff0c1 \u8868\u793a\u542f\u7528\uff08\u90e8\u5206\u4fee\u6539\uff09\uff0c1; mode=block \u8868\u793a\u542f\u7528\uff08\u5b8c\u5168\u505c\u6b62\u663e\u793a\uff09\u3002<br \/>\n\u5982\u679c\u7f51\u7ad9\u7684 XSS \u9632\u62a4\u6ca1\u6709\u95ee\u9898\uff0c\u5e76\u4e14\u5e0c\u671b\u6d88\u9664\u8bef\u62a5\uff0c\u5efa\u8bae\u6307\u5b9a\u4e3a 0\uff1b\u5982\u679c\u4e0d\u662f\u8fd9\u79cd\u60c5\u51b5\uff0c\u5219\u6307\u5b9a\u4e3a 1\uff1bmode=block \u662f\u7406\u60f3\u9009\u62e9\uff0c\u800c\u9ed8\u8ba4\u72b6\u6001\u7684 1 \u5e76\u4e0d\u7406\u60f3\u3002 19<\/p>\n<p>\u5728\u8c37\u6b4c\u3001Twitter\u3001Yahoo! JAPAN\u7b49\u5e73\u53f0\u4e0a\u8bbe\u5b9a\u4e86\u8fd9\u4e2a\u53c2\u6570\u3002<br \/>\n\u800c\u5728 Facebook \u4e0a\uff0c\u8bbe\u5b9a\u4e3a0\u3002<\/p>\n<h3>X-\u5185\u5bb9-\u7c7b\u578b-\u9009\u9879<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nc\">Header<\/span> <span class=\"ss\">always<\/span> <span class=\"ss\">set<\/span> X-Content-Type-Options nosniff\r\n<\/code><\/pre>\n<p>\u5f53\u5c06 X-Content-Type-Options \u54cd\u5e94\u5934\u8bbe\u7f6e\u4e3a nosniff \u5e76\u53d1\u9001\u65f6\uff0c\u53ef\u9632\u6b62Internet Explorer\u901a\u8fc7MIME Sniffing\u529f\u80fd\u7ed5\u8fc7content-type\u58f0\u660e\u300220<\/p>\n<p>\u5728Facebook\u3001Twitter\u3001Yahoo! JAPAN\u7b49\u5e73\u53f0\u4e0a\u6307\u5b9a\u4e86\u3002<\/p>\n<h3>\u5185\u5bb9\u5b89\u5168\u7b56\u7565 (CSP)<\/h3>\n<p>\u5bf9\u4e8e\u65b0\u624b\u6765\u8bf4\uff0c\u6211\u4e0d\u5efa\u8bae\u4f7f\u7528\u3002 (https:\/\/content-security-policy.com\/ and http:\/\/blog.hash-c.co.jp\/2013\/12\/Content-Security-Policy-CSP.html)<\/p>\n<h3>httpoxy\u4fdd\u62a4\u63aa\u65bd<\/h3>\n<p>\u5f53\u6211\u53d1\u9001\u4e00\u4e2a\u540d\u4e3a &#8220;Bar&#8221; \u7684\u5934\u90e8\u65f6\uff0c\u6839\u636eCGI\u7684\u89c4\u8303\uff0c\u5b83\u4f1a\u5c06\u5176\u8f6c\u6362\u4e3a HTTP_Foo = Bar\u3002\u7136\u800c\uff0c\u5982\u679c\u6211\u53d1\u9001\u4e00\u4e2a\u540d\u4e3a &#8220;PROXY: xxx&#8221; \u7684\u5934\u90e8\uff0c\u5b83\u53ef\u80fd\u4f1a\u88ab\u4fee\u6539\u4e3a HTTP_PROXY\uff0c\u8fd9\u5c31\u662f\u6240\u8c13\u7684HTTPOXY\u8106\u5f31\u6027\u3002\u4f60\u53ef\u4ee5\u4f7f\u7528HTTPOXY\u6f0f\u6d1e\u68c0\u6d4b\u5de5\u5177\u8fdb\u884c\u6d4b\u8bd5\u3002<br \/>\n\u4e0b\u9762\u7684\u8f6f\u4ef6\u53d7\u5230\u5f71\u54cd\u3002<\/p>\n<ul class=\"post-ul\">\nPHP (CVE-2016-5385)<br \/>\nGO (CVE-2016-5386)<br \/>\nApache HTTP Server (CVE-2016-5387)<br \/>\nApache Tomcat (CVE-2016-5388)<br \/>\nHHVM (CVE-2016-1000109)<br \/>\nPython (CVE-2016-1000110<\/ul>\n<h3>\u9650\u5236\u8bf7\u6c42\u4f53\u5927\u5c0f<\/h3>\n<p>\u6b64\u6307\u4ee4\u7528\u4e8e\u6307\u5b9a\u8bf7\u6c42\u4e3b\u4f53\u5141\u8bb8\u7684\u5b57\u8282\u6570\u3002<br \/>\n\u53ef\u4ee5\u5728\u6307\u4ee4\u6240\u4f4d\u4e8e\u7684\u4e0a\u4e0b\u6587\uff08\u670d\u52a1\u5668\u6574\u4f53\u3001\u76ee\u5f55\u3001\u6587\u4ef6\u3001\u4f4d\u7f6e\uff09\u5185\u9650\u5236\u5141\u8bb8\u7684HTTP\u8bf7\u6c42\u6d88\u606f\u4e3b\u4f53\u7684\u5927\u5c0f\u3002<br \/>\n\u9ed8\u8ba4\u503c\u4e3a0\uff0c\u5373\u65e0\u9650\u5236\u3002\u4e0a\u9650\u4e3a2147483647\uff082GB\uff09\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nc\">LimitRequestBody<\/span> 10485760\r\n<\/code><\/pre>\n<p>\u5982\u679c\u60f3\u8981\u9650\u5236\u4e3a10MiB\uff0c\u8bf7\u6309\u7167\u4ee5\u4e0a\u7684\u65b9\u5f0f\u8fdb\u884c\u63cf\u8ff0\u3002\u8fd9\u5bf9\u4e8e\u9632\u6b62 DoS \u653b\u51fb\u5728\u53c2\u8003\u6587\u732e\u4e2d\u662f\u6709\u6548\u7684\u3002<\/p>\n<p>\u53e6\u5916\uff0c\u7531\u4e8ePHP\u9ed8\u8ba4\u8bbe\u7f6e\u4e86\u4ee5\u4e0b\u6570\u503c\uff0c\u60a8\u4e5f\u53ef\u4ee5\u4e00\u5e76\u786e\u8ba4\u4e00\u4e0b\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"py\">memory_limit<\/span> <span class=\"p\">=<\/span> <span class=\"s\">128M<\/span>\r\n<span class=\"py\">post_max_size<\/span> <span class=\"p\">=<\/span> <span class=\"s\">8M<\/span>\r\n<span class=\"py\">upload_max_filesize<\/span> <span class=\"p\">=<\/span> <span class=\"s\">5M<\/span>\r\n<\/code><\/pre>\n<h3>\u9650\u5236\u8bf7\u6c42\u5b57\u6bb5<\/h3>\n<p>\u8fd9\u4e2a\u6307\u4ee4\u7528\u4e8e\u6307\u5b9a\u5728HTTP\u8bf7\u6c42\u4e2d\u5141\u8bb8\u7684\u8bf7\u6c42\u5934\u5b57\u6bb5\u6570\u3002\u9ed8\u8ba4\u503c\u4e3a100\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"nc\">LimitRequestFields<\/span> 50\r\n<\/code><\/pre>\n<p>\u5728\u53c2\u8003\u6587\u732e\u4e2d\u5199\u9053\uff1a&#8221;\u8bf7\u6c42\u5934\u5b57\u6bb5\u7684\u6570\u91cf\u5f88\u5c11\u4f1a\u8d85\u8fc7 20 \u4e2a\u3002 &#8221; 23\u3002\u6b64\u5916\uff0c\u8fd9\u4e5f\u88ab\u89c6\u4e3a\u6709\u6548\u5730\u907f\u514d DoS \u653b\u51fb\u3002<\/p>\n<p>\u53e6\u5916\uff0c\u6709\u4e00\u4efd\u62a5\u544a\u79f0\uff0c\u5982\u679c\u5c06\u503c\u8bbe\u5b9a\u4e3a20\uff0c\u5219\u5728\u7279\u5b9a\u7684\u7f51\u9875\u4e0a\uff0c\u4f7f\u7528Chrome\u6d4f\u89c8\u5668\u65f6\u4f1a\u8fd4\u56deBad Request\u9519\u8bef\u3002\u800c\u4e14\u6839\u636e\u6240\u53c2\u8003\u7684\u7f51\u9875\u548c\u6d4f\u89c8\u5668\u7684\u4e0d\u540c\uff0c\u884c\u4e3a\u4e5f\u6709\u53ef\u80fd\u4f1a\u6709\u6240\u4e0d\u540c\u3002<\/p>\n<h3>\u8bf7\u6c42\u8bfb\u53d6\u8d85\u65f6<\/h3>\n<pre class=\"post-pre\"><code><span class=\"nc\">RequestReadTimeout<\/span> header=20-40,MinRate=500 body=20,MinRate=500\r\n<\/code><\/pre>\n<p>\u57282.2.15\u7248\u672c\u4e4b\u540e\u5b9e\u65bd\u7684\u5bf9\u6297Slowloris\u653b\u51fb\u7684mod_reqtimeout\u6a21\u5757\u4e2d\u53ef\u4ee5\u4f7f\u7528\u7684\u6307\u4ee4\u3002<br \/>\n\u57282.3.15\u7248\u672c\u4e4b\u540e\u9ed8\u8ba4\u542f\u7528\u3002<\/p>\n<p>\u5982\u679c\u4f7f\u7528AWS\u7684ELB\uff0c\u5982\u679cELB\u7684Connection Settings: Idle Timeout\u7684\u503c\u5927\u4e8eApache\u7684RequestReadTimeout header\u7684\u6700\u4f4e\u503c\uff0c\u5c06\u4f1a\u5728Apache\u7684\u9519\u8bef\u65e5\u5fd7\u4e2d\u5927\u91cf\u8bb0\u5f55408\u9519\u8bef\u6d88\u606f\uff0c\u6240\u4ee5\u8bf7\u6ce8\u610f\u300226<\/p>\n<h2>\u5b89\u5168\u6d4b\u8bd5<\/h2>\n<p>\u5728CentOS 7.2.1511\u4e0a\u4f7f\u7528yum\u5b89\u88c5Apache\u5e76\u672a\u8fdb\u884c\u914d\u7f6e\u66f4\u6539\u7684\u60c5\u51b5\u4e0b\u8fdb\u884c\u4e86\u6d4b\u8bd5\uff0c\u5e76\u5f97\u51fa\u4e86\u7ed3\u679c\u3002<\/p>\n<pre class=\"post-pre\"><code><span class=\"o\">[<\/span>root@localhost program]# perl .\/nikto.pl <span class=\"nt\">-h<\/span> 127.0.0.1\r\n- <span class=\"k\">*****<\/span> SSL support not available <span class=\"o\">(<\/span>see docs <span class=\"k\">for <\/span>SSL <span class=\"nb\">install<\/span><span class=\"o\">)<\/span> <span class=\"k\">*****<\/span>\r\n- Nikto v2.1.6\r\n<span class=\"nt\">---------------------------------------------------------------------------<\/span>\r\n+ Target IP:          127.0.0.1\r\n+ Target Hostname:    127.0.0.1\r\n+ Target Port:        80\r\n+ Start Time:         2016-01-16 10:00:00 <span class=\"o\">(<\/span>GMT9<span class=\"o\">)<\/span>\r\n<span class=\"nt\">---------------------------------------------------------------------------<\/span>\r\n+ Server: Apache\/2.4.6 <span class=\"o\">(<\/span>CentOS<span class=\"o\">)<\/span> PHP\/5.4.16\r\n+ Server leaks inodes via ETags, header found with file \/, fields: 0x220 0x529841bdd9a78\r\n+ The anti-clickjacking X-Frame-Options header is not present.\r\n+ The X-XSS-Protection header is not defined. This header can hint to the user agent to protect against some forms of XSS\r\n+ The X-Content-Type-Options header is not set. This could allow the user agent to render the content of the site <span class=\"k\">in <\/span>a different fashion to the MIME <span class=\"nb\">type<\/span>\r\n+ PHP\/5.4.16 appears to be outdated <span class=\"o\">(<\/span>current is at least 5.6.9<span class=\"o\">)<\/span><span class=\"nb\">.<\/span> PHP 5.5.25 and 5.4.41 are also current.\r\n+ Apache\/2.4.6 appears to be outdated <span class=\"o\">(<\/span>current is at least Apache\/2.4.16<span class=\"o\">)<\/span><span class=\"nb\">.<\/span> Apache 2.2.31 is also current <span class=\"k\">for <\/span>the 2.x branch.\r\n+ Allowed HTTP Methods: GET, HEAD, POST, OPTIONS, TRACE\r\n+ OSVDB-877: HTTP TRACE method is active, suggesting the host is vulnerable to XST\r\n+ Retrieved x-powered-by header: PHP\/5.4.16\r\n+ OSVDB-3092: \/test.php: This might be interesting...\r\n+ 8225 requests: 0 error<span class=\"o\">(<\/span>s<span class=\"o\">)<\/span> and 10 item<span class=\"o\">(<\/span>s<span class=\"o\">)<\/span> reported on remote host\r\n+ End Time:           2016-01-16 10:00:11 <span class=\"o\">(<\/span>GMT9<span class=\"o\">)<\/span> <span class=\"o\">(<\/span>11 seconds<span class=\"o\">)<\/span>\r\n<span class=\"nt\">---------------------------------------------------------------------------<\/span>\r\n+ 1 host<span class=\"o\">(<\/span>s<span class=\"o\">)<\/span> tested\r\n<\/code><\/pre>\n<h1>Apache \u76f8\u5173\u6587\u7ae0<\/h1>\n<ul class=\"post-ul\">\nApache\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u8a2d\u5b9a<br \/>\nApache HTTP Server \u306e\u30b5\u30dd\u30fc\u30c8\u671f\u9650<br \/>\nApache \u306e\u30ed\u30b0\u3092\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u3067\u96c6\u8a08\u3059\u308b<br \/>\nApache \u306e\u60c5\u5831\u3092\u30b3\u30de\u30f3\u30c9\u30e9\u30a4\u30f3\u3067\u53d6\u5f97\u3059\u308b<br \/>\nIP\u30a2\u30c9\u30ec\u30b9\u304b\u3089\u56fd\u3084\u90fd\u5e02\u3092\u5224\u5225\u3059\u308b (GeoIP)<br \/>\nApache \u30c1\u30e5\u30fc\u30cb\u30f3\u30b0 \u30b9\u30af\u30ea\u30d7\u30c8<\/ul>\n<h1>\u53c2\u8003\u8d44\u6599<\/h1>\n<div>\u8fd9\u91cc\u63d0\u4f9b\u4e86\u4e00\u4e9b\u4e0e\u670d\u52a1\u5668\u7248\u672c\u3001Apache\u6a21\u5757\u3001HTTP\u5934\u90e8\u7b49\u76f8\u5173\u7684\u94fe\u63a5\uff0c\u5185\u5bb9\u5305\u62ec\u5b89\u5168\u6f0f\u6d1e\u3001\u6700\u4f73\u5b9e\u8df5\u548c\u6d4f\u89c8\u5668\u652f\u6301\uff0c\u53ef\u4ee5\u53c2\u8003\u3002<\/div>\n<p><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u7efc\u8ff0 \u603b\u7ed3\u4e86\u53ef\u4ee5\u5728Apache\u914d\u7f6e\u4e2d\u901a\u7528\u7684\u5b89\u5168\u8bbe\u7f6e\u53ca\u5176\u5404\u4e2a\u9879\u76ee\u3002 \u8bbe\u5b9a\u793a\u4f8b\u3002 \u5fc5\u987b\u8bbe\u7f6e cat &lt;&#038;lt [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-36340","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Apache\u5b89\u5168\u914d\u7f6e - Blog - Silicon Cloud<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/zh\/blog\/apache\u5b89\u5168\u914d\u7f6e\/\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apache\u5b89\u5168\u914d\u7f6e\" \/>\n<meta property=\"og:description\" content=\"\u7efc\u8ff0 \u603b\u7ed3\u4e86\u53ef\u4ee5\u5728Apache\u914d\u7f6e\u4e2d\u901a\u7528\u7684\u5b89\u5168\u8bbe\u7f6e\u53ca\u5176\u5404\u4e2a\u9879\u76ee\u3002 \u8bbe\u5b9a\u793a\u4f8b\u3002 \u5fc5\u987b\u8bbe\u7f6e cat &lt;&amp;lt [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/zh\/blog\/apache\u5b89\u5168\u914d\u7f6e\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-17T14:00:38+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-05-03T14:57:39+00:00\" \/>\n<meta name=\"author\" content=\"\u79d1, \u9896\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u79d1, \u9896\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/\",\"name\":\"Apache\u5b89\u5168\u914d\u7f6e - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\"},\"datePublished\":\"2023-11-17T14:00:38+00:00\",\"dateModified\":\"2024-05-03T14:57:39+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/8ca01ba7f7362ad4edb7da206a12f29e\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/zh\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apache\u5b89\u5168\u914d\u7f6e\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/8ca01ba7f7362ad4edb7da206a12f29e\",\"name\":\"\u79d1, \u9896\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8a6fb3cc7ba2f69d2189ba532aec4633ea7ed75ac0af162ec367cb3abc0fb2af?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8a6fb3cc7ba2f69d2189ba532aec4633ea7ed75ac0af162ec367cb3abc0fb2af?s=96&d=mm&r=g\",\"caption\":\"\u79d1, \u9896\"},\"url\":\"https:\/\/www.silicloud.com\/zh\/blog\/author\/keying\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Apache\u5b89\u5168\u914d\u7f6e - Blog - Silicon Cloud","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/zh\/blog\/apache\u5b89\u5168\u914d\u7f6e\/","og_locale":"zh_CN","og_type":"article","og_title":"Apache\u5b89\u5168\u914d\u7f6e","og_description":"\u7efc\u8ff0 \u603b\u7ed3\u4e86\u53ef\u4ee5\u5728Apache\u914d\u7f6e\u4e2d\u901a\u7528\u7684\u5b89\u5168\u8bbe\u7f6e\u53ca\u5176\u5404\u4e2a\u9879\u76ee\u3002 \u8bbe\u5b9a\u793a\u4f8b\u3002 \u5fc5\u987b\u8bbe\u7f6e cat &lt;&lt [&hellip;]","og_url":"https:\/\/www.silicloud.com\/zh\/blog\/apache\u5b89\u5168\u914d\u7f6e\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-11-17T14:00:38+00:00","article_modified_time":"2024-05-03T14:57:39+00:00","author":"\u79d1, \u9896","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"\u79d1, \u9896","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"5 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/","url":"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/","name":"Apache\u5b89\u5168\u914d\u7f6e - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website"},"datePublished":"2023-11-17T14:00:38+00:00","dateModified":"2024-05-03T14:57:39+00:00","author":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/8ca01ba7f7362ad4edb7da206a12f29e"},"breadcrumb":{"@id":"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/zh\/blog\/"},{"@type":"ListItem","position":2,"name":"Apache\u5b89\u5168\u914d\u7f6e"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#website","url":"https:\/\/www.silicloud.com\/zh\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/8ca01ba7f7362ad4edb7da206a12f29e","name":"\u79d1, \u9896","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8a6fb3cc7ba2f69d2189ba532aec4633ea7ed75ac0af162ec367cb3abc0fb2af?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8a6fb3cc7ba2f69d2189ba532aec4633ea7ed75ac0af162ec367cb3abc0fb2af?s=96&d=mm&r=g","caption":"\u79d1, \u9896"},"url":"https:\/\/www.silicloud.com\/zh\/blog\/author\/keying\/"},{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.silicloud.com\/zh\/blog\/apache%e5%ae%89%e5%85%a8%e9%85%8d%e7%bd%ae\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/36340","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/comments?post=36340"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/36340\/revisions"}],"predecessor-version":[{"id":94609,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/posts\/36340\/revisions\/94609"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/media?parent=36340"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/categories?post=36340"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/zh\/blog\/wp-json\/wp\/v2\/tags?post=36340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}