On 2012-02-03 18:22, Silviu Andrica wrote:
Hi, I was wondering if you know any tool that checks how secure an Apache configuration is. I know about Nikto and W3AF, but those tools aretargeted at web applications. I'm more interested in tools that targetweb servers. Also, can you recommend some Apache configurations / setups where Nikto and W3AF are effective?
'Security' is not black and white like that. The perception of security is always a moving target.
Some recommended reading: http://www.schneier.com/book-sandl.html -- Message sent via my webmail account. --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx