Showing posts with label web. Show all posts
Showing posts with label web. Show all posts

Wednesday, August 24, 2011

How to Generate An SSL Certificate For Your Website

If you run a website which you need to serve via SSL, then this article is for you. The procedure for making your website SSL ready is quite simple. It involves -

  1. Generating a private key.
  2. Generating a Certificate Signing Request (CSR).
  3. Getting the CSR signed by a certificate authority - Verisign, Go Daddy, Thawt etc. (Be ready to shell out some money here).
  4. Uploading the private key, the CSR, and the certificate to your website.
  5. Configuring the SSL version of your site. And finally ...
  6. Enabling the SSL for your website.

ScoutApp has a nice article that explains the above steps in detail. Check it out.

Tq http://linuxhelp.blogspot.com

Monday, August 22, 2011

How to Encrypt any webmail text message with encipher.it

Encrypt Gmail, Hotmail and Yahoo email

Encipher.it will encrypt and password protect your text messages using symmetric encryption implemented with AES256 and PDBKF2 (Password-Based Key Derivation Function) for key generation, the site itself uses a SSL digital certificate to protect against MITM (Man In The Middle) attacks, the best part is that it works with all services, you can encrypt your webmail messages no matter who your provider is, another possible use is posting of encrypted messages on Usenet or your Facebook account, encryption and decryption is performed in your browser using javascript, no data leaves your browser in plain text. To encrypt the messages you use a bookmarklet that takes you to the encipher.it website, there you will find a box where to enter text, the same box is used for encryption and decryption, when the recipient gets a coded message a one line phrase with a link link tells them where to decrypt it, the bad news is that they will need to know the password too, this should have been transmitted previously through a secure channel, attachments can not be encrypted.

Encipher.it webmail encryption

Encipher.it webmail encryption

Encipher.it can be used anywhere, i.e. Internet cafes and libraries, but anything you type in the keyboard of a computer that isn’t yours could easily be recorded, when you use a public computer you should not trust anything on it, if the website were to become too popular it might be easily blocked by an authoritarian regime ISP but that isn’t likely because copycats would then sprout around.

I would only be happy to use this browser based symmetric encryption system if the other part is very lazy about security or doesn’t want to learn about it and the security needs are low. Encrypting text, even with something as simple as ROT13 will leave the average computer users scratching their heads and it will fool email services that scan email messages to introduce contextual advertising on them, like Gmail, for serious security it is better using a public key encryption based system, i.e. PGP, what encipher.it has on its favour is convenience and easy of use.

Visit Encipher.it website


Tq http://www.hacker10.com

Sunday, August 7, 2011

5 Ways to Create or Convert into Mobile Phone Website

People hooked to internet via their mobile phones is on the rise but only few websites offer mobile compatible format of their websites. Do you want to offer mobile version of your website or blog? Don’t worry, this does not involve learning any programming language or formatting/recreating your existing computer based website.

Here are few tools that will make this creation or conversion easier than expected. Your website is designed for screens 15″ or greater, these tools let you make mobile website for screens 3″ or less.
  1. Google’s Conversion Utility - This is as simple as it gets. Just need to enter the URL of your website, check the option for ‘No Images’ if you do not want images to appear, then click on ‘GO’ button. Mobile version of your website will pop up, add the link to your faovrites for browsing website on mobile. You can even insert Google Mobile Ads to earn some money.
  2. Zinadoo - Using this web service you can easily create, publish and share you mobile website. Besides you can also colour the website, create a page that site visitors can email you from or request that you call/email them back, create a guestbook page, create a comments page and much more.
  3. Winksite -Winksite is mobile Website builder that also includes RSS-driven content deployment and mobile-tuned community features such as forum, chat, and polls. No need to install software, do everything online. You also monetize your website with Google Mobile Adsense.
  4. MobiSiteGalore - Let you build websites that will work consistently across all mobile phones as they 100% comply with W3C’s mobile web standards. You can host website wherever you want. This service is completely FREE and is supported by donations.
  5. MoFuse -Use your RSS feed to power your mobile blog. Design your mobile blog with WYSIWYG editor. Automatically redirect your mobile visitors to your mobile blog. You can also enroll in revenue sharing program and earn 50% of all advertising profits using Google AdSense Mobile and AdMob.
Now getting hooked to your website or blog on mobile phone wont be that difficult. I am sure above tools will help you create your place on mobile web, what say?

tq http://www.tothepc.com/archives/5-ways-to-create-or-convert-into-mobile-phone-website/

Tuesday, January 25, 2011

14 Ways to Be the World's Worst Web Project Manager

There are a great number of ways to manage website projects, but regardless of your management style, there are behaviours that you should learn to avoid as much as possible. Steering clear of these pitfalls will not only allow you to get through projects on time and on budget, but will leave a very good impression on your clients, and win you more work in the future.

Let Interruptions Dictate Your Schedule

Too often we allow ourselves to be distracted from what we need to be focusing on right now. Mostly it's unnecessary to jump on every new e-mail immediately; issues can usually wait until we're done with the current task.

As a project manager, you'll most likely be in charge of multiple projects and employees at the same time. It's important to have a system that allows you to have a lot on your plate and still be on top of things. This could include creating a priority list when you check your e-mail/voicemail messages, or when you're available for meetings. The key here is to make sure you get done what needs to be done.

Tim Ferriss wrote a great blog post on the topic called 'The Not-To-Do List: 9 Habits to Stop Now'; I highly recommend you check it out.

Don't Communicate Clearly With Your Clients

The way you communicate through e-mail and voicemail will be reflected in how clients perceive you. This can include both the clarity and conciseness of your writing, as well as spelling and grammar. Often I'll re-read an e-mail three to five times before I send it out, just to make sure I catch any remaining glitches.

Keep in mind that clients typically respond better to shorter e-mails and voicemails. Write short, focused messages that communicate key information and action points. Sometimes you need a long e-mail to clearly explain an involved concept or process, but as a general rule make a consistent effort to trim the fat.

When I have a choice between a phone call and an e-mail, I usually stick to e-mails, as they provide a communication trail that I can access later on. This is especially valuable when dealing with clients who are busy and forget to read the e-mail, because you can go back and resend it at a later time if necessary.

Keep Your Clients Guessing

Nobody likes to feel out of the loop. The more time you spend in making it clear to your clients what your team is working on, the more they'll appreciate your work.

All this usually takes is an e-mail letting them know what you achieved today or in the last few days, and what your team is going to work on next. I also find this is a great opportunity to remind the client of anything you're still waiting to receive from them (content or images, for example), and the timeframe within which you need to receive it in order to avoid holding up your process.

If You're Not Going to Meet a Deadline, Don't Tell the Client

As I outlined in the previous point, this scenario can be prevented by doing a good job of keeping the client in the loop. If you do find you're going to be unable to meet a deadline, make it very clear to the client why this is happening.

Say that you originally thought that integrating a new API was going to take two hours, and it ended up taking eight hours. The client should be made aware of this as soon as it happens. You could word it like this: "We originally thought integrating X was going to take 2 hours, but we had issues making their examples work and it ended up taking much longer than we anticipated. I do apologise for the delay, but we'll do our best in making up the lost time."

The client should be made aware of any delays that will affect a deadline well before that deadline. If you end up telling the client this on the day of the deadline, then you've spent too little time planning and communicating to the customer what your team is doing or of any delays you've encountered.

Always Underestimate the Resources Needed for a Project

The scenario: Client A wants a website "just like Facebook," but is only willing to pay $5,000 for it. We think we can cut a few corners to make this happen, and so we agree to do it for $5,000 to keep the client happy. What happens is that the project takes much more time than we'd originally thought it would, and either our company ends up wearing the cost of the extra time spent on the project, or we displease the client when they receive a finished product at odds with what they expected.

This can be prevented by doing a good job in estimating the time and cost of each element in a project, and being honest about the scenario when speaking with the client. If your client thinks you can build a site like Facebook for $5,000, perhaps you could be doing a better job helping them understand how much time goes into various elements of site design and development.

Another option is to present them with a realistic estimate of what can be done with their proposed budget, and possibly come up with a plan that includes a series of development phases. This way, they can kick-start their project with the budget they have, and then expand on it later when more funds are available.

If a Client is Being Rude, Respond in Kind

It's always in the best interest of your company to be professional. If a client is growing agitated over the phone, it's advisable to say something like: "I'm sorry to hear that this is happening. My team will look into it immediately and get back to you." Having a shouting match with your client will usually end badly, and could potentially land you in trouble with your boss.

Knowing when you're becoming too worked up takes a level of maturity and professionalism. By realising your error at the time, you can make amends to turn the situation around and please the customer.

Never Admit to Making a Mistake

Most clients won't be upset with you if you make a mistake, as long as you're honest about it and take steps to avoid the same problem happening again. They understand that you're human and will make mistakes. The key is to avoid making the same mistakes over and over again; otherwise, your apologies will be hollow.

Usually, just explaining to the client in an e-mail what happened is enough to satisfy them. Making sure to fix the issue immediately will give you bonus points in the eyes of your client, because that communicates that you care about what you do.

If you're giving your client access to an area that you're still working on, or that you know has bugs, you should clearly communicate to them that it's a staging area, and that your team is still ironing out the bugs. If there are major bugs, it's a good idea to let the client know about them specifically, so that they won't have a panic attack when they come across them.

Shift Blame to Someone on Your Team

If you're a project manager, you're responsible for your team. If a team member makes a mistake and you fail to catch it before the client, it's ultimately your fault. Your instinct to shift blame might come from trying to protect the client's image of you personally, but more frequently it will have the opposite effect. Trying to shift responsibility for mistakes just makes it look like you're not paying attention to your team's work.

You should, however, still talk to the team member about their mistake. But think about it from the client's perspective: they just need to know that you're in control of your team. The occasional slipup won't hurt the client's perception of you in any significant way. But pay very close attention to the mistakes your team members make, and ensure they're learning from them.

Furthermore, each and every person on your team needs to earn your trust, so that you feel comfortable taking full responsibility for their work in your dealings with clients.

Don't Double-check Your Team's Work

We're all human, and on occasion we'll make mistakes. But part of being a project manager, as I've already outlined, is taking responsibility for the team's work. And that means ensuring that as well as being bug-free, the site also works the way the client expects it to work.

Project managers need to connect the dots in ways that their team may miss. Does the gallery do everything the client wants it to do? What exactly is listed for this area in the agreement? Is the site compatible with the major browsers? Running through a simple checklist like this will not only make sure that the project meets the specifications of the agreement, but allows us to improve on the work that our team produces, which ultimately reflects on us.

Spend Very Little Time Writing E-mails

A quickly written e-mail to which little attention was paid can be easy to misinterpret.

You want to ensure that you're clear and concise in your e-mails. If you need the client to send you anything, make sure to outline everything you need in a numbered list. The same goes for any questions you have. This makes it easy for them to respond via e-mail, because they can reference each of your inquiries by number. Never put a bunch of questions or requests in a paragraph, as they'll frequently be missed.

If you need to receive an item before you can continue work on part of the project, make this very clear in your communication with the client. In fact, I suggest bringing this up multiple times. If these factors will affect a deadline, make that clear to the client. For example, you could word it as follows: "Please keep in mind that if we're still going to make the 10/10/2010 launch, we'll need to receive the content for the website by 2/10/2010."

I always aim to sound gracious when writing to a customer via e-mail. It might take a little bit more time to achieve the right tone, so that you're sure it won't be misread, but avoiding misunderstandings with your clients is well worth the effort.

Don't Get to Know Your Team

If you're managing a team, it's your responsibility to understand the strengths and weaknesses of the team, as a whole and of each member. Managing a project shouldn't be like a game like Russian roulette, where you're never sure what your team is going to produce. As project managers, we need to do put ourselves in a position to succeed. Below are a few questions that may help you:

  • What does this team member's code look like?
  • Will they be able to complete their part of the project on time?
  • How reliable have they been in the past?
  • If they fall behind, what is my backup plan?
  • Does it make sense to have this team member work on a project that is this complicated?
  • Have they worked on other projects with a similar level of responsibility?
  • Will it be more work for me to have them work on this?

Assume Your Team is on Schedule

A project that was on time last week could suddenly find itself well behind schedule, because an element that you thought was done properly turns out to have been botched, or because a team member misunderstood what needed to be done.

Set up firm deadlines for your team, but give them some cushion for any unexpected items that arise. Make sure that your team members clearly communicate with you if they're unable to meet a deadline, and train them to do this long before the deadline arrives. Make it very clear that you're okay with them asking you questions on a project, and that you would rather have them ask more questions than to assume.

With a big project, this becomes even more important, because being behind in one area could affect the whole project. Make sure you're doing a solid job on what should be prioritised. If half your team has to wait on one team member to achieve what they need to do, that item should be on top of your priority list so that no time is lost.

Don't Create a System to Remind You to Contact Clients

If you're managing many different projects, and you have a long list of clients that you've worked with in the past, it's easy to lose track of who's waiting on an e-mail from you. You need some kind of system that allows you to know who you need to contact. This could be as simple as having a folder or label in your e-mail system for e-mails that require a response. That way, when you want to play catch-up, it's very easy to determine who's still to be contacted.

It looks extremely bad if you constantly forget to respond to client e-mails, or if you're slow in getting back to people. Even if you're busy, you need to let your clients know when you expect to be able to deal with their query. I have found this method to be very effective, and it gives me some extra time to prioritise and figure out what I need to jump onto next.

Come into Meetings Ill-prepared

Even if it's difficult to be 100% prepared for everything in a meeting, you should never go into a meeting unsure of what you're going to say when they ask you about specifics on the project. If you're asked for a detail you're unsure of, let them know that you will look into it and get back to them later. Don't make promises that are impossible for you to keep, or that you're unsure about, even if they push you for answers. This includes deadlines and timeframes.

In whatever you're talking about, be confident. You're the expert in your field, not the client. But just make sure you're very deliberate in what comes out of your mouth. The main objective of the meeting should be to convince the client that you're in control, and that they made a good choice in going with you. Even if you're behind, or if something went wrong, how you word it can determine the success or failure of the meeting.

I have found that in most meetings that happen during the course of a project, the client is mainly looking for reassurance. Do not give them any reason to doubt that it's all under control, and you'll have a happy client who loves to work with you!

We all make mistakes, and the area of managing web projects is far from immune to human error. But if we're deliberate in learning from our mistakes, and learn how to improve on what we've done in the past, we can keep our clients, bosses, and team members happy, and lead our projects to success.


Tq http://www.projectsmart.co.uk/14-ways-to-be-the-worlds-worst-web-project-manager.html

Monday, October 11, 2010

How to Set Up SSL on IIS 7

Introduction

The steps for configuring Secure Sockets Layer (SSL) for a site are the same in IIS 7 and IIS 6.0, and include the following:

  • Get an appropriate certificate.
  • Create an HTTPS binding on a site.
  • Test by making a request to the site.
  • Optionally configure SSL options, that is, by making SSL a requirement.

This document provides some basic information on SSL, then shows how to enable SSL in many several different ways:

  • Using IIS Manager.
  • Using the AppCmd.exe command line tool.
  • Programmatically through Microsoft.Web.Administration.
  • Using WMI scripts.

This article contains the following sections:

SSL Configuration

The implementation of SSL changed from IIS 6.0 to IIS 7. In IIS 6.0 on Windows Server 2003, all SSL configuration was stored in the IIS metabase, and encryption/decryption occured in User mode (requiring a lot of kernel/user mode transitions). In IIS 7, HTTP.sys handles SSL encryption/decryption in kernel mode, resulting in up to 20% better performance for secure connections in IIS 7 than that experienced in IIS 6.0.

Using SSL in kernel mode requires storing SSL binding information in two places. First, the binding is stored in %windir%\System32\inetsrv\config\applicationHost.config for your site. When the site starts, IIS 7 sends the binding to HTTP.sys, and HTTP.sys starts listening for requests on the specified IP:Port (this works for all bindings). Second, the SSL configuration associated with the binding is stored in the HTTP.sys configuration. Use the netsh command at a command prompt to view SSL binding configuration stored in HTTP.sys as in the following example:

netsh http show sslcert

When a client connects and initiates an SSL negotiation, HTTP.sys looks in its SSL configuration for the IP:Port pair to which the client connected. The HTTP.sys SSL configuration must include a certificate hash and the name of the certificate store before the SSL negotiation will succeed.

Troubleshooting Tip: If you're having trouble with an SSL binding, verify that the binding is configured in ApplicationHost.config, and that the HTTP.sys store contains a valid certificate hash and store name for the binding.

Choosing a Certificate

When choosing a certificate, consider the following: Do you want end users to be able to verify your server's identity with your certificate? If yes, then either create a certificate request and send that request to a known certificate authority (CA) such as VeriSign or GeoTrust, or obtain a certificate from an online CA in your intranet domain. There are three things that a browser usually verifies in a server certificate:

  1. That the current date and time is within the "Valid from" and "Valid to" date range on the certificate.
  2. That the certificate's "Common Name" (CN) matches the host header in the request. For example, if the client is making a request to http://www.contoso.com/, then the CN must also be http://www.contoso.com/.
  3. That the issuer of the certificate is a known and trusted CA.

If one or more of these checks fails, the browser prompts the user with warnings. If you have an Internet site or an intranet site where your end users are not people you know personally, then you should always ensure that these three parameters are valid.

Self-signed certificates are certificates created on your computer. They're useful in environments where it's not important for an end user to trust your server, such as a test environment.

Using AppCmd

You cannnot request or create a certificate by using AppCmd.exe. You also cannot use AppCmd.exe to create an SSL binding.

Configure SSL Settings

You can use AppCmd.exe to configure a site to accept only server HTTPS connections by modifying the sslFlags attribute in the Access section. For example, you can configure this setting for the "Default Web Site" in the ApplicationHost.config file (for example, commitPath:APPHOST) by using the following command:

%windir%\system32\inetsrv>AppCmd set config "Default Web Site" -commitPath:APPHOST -section:access -sslFlags:Ssl

If successful, the following message is displayed:

Applied configuration changes to section "system.webServer/security/access" for "MACHINE/WEBROOT/APPHOST/Default Web Site" at configuration commit path "MACHINE/WEBROOT/APPHOST"

Note: To require 128-bit SSL, change the sslFlags value to Ssl128.

The following example demonstrates how to view the section settings for the Default Web Site. The sslFlags attribute has been set successfully.

%windir%\system32\inetsrv>AppCmd list config "Default Web Site" -section:access

Executing the command results in the following entry in the ApplicationHost.config file:

<system.webServer>

<security>
<access flags="Script, Read" sslFlags="Ssl" />
security>
system.webServer>

Using WMI

You cannot request or create a certificate by using the WebAdministration WMI namespace.

Create an SSL Binding

The following script demonstrates how to create a new SSL binding and how to add the appropriate configuration for both HTTP.sys and IIS 7:

Set oIIS = GetObject("winmgmts:root\WebAdministration")

'''''''''''''''''''''''''''''''''''''''''''''
' CREATE SSL BINDING
'''''''''''''''''''''''''''''''''''''''''''''

oIIS.Get("SSLBinding").Create _
"*", 443, "4dc67e0ca1d9ac7dd4efb3daaeb15d708c9184f8", "MY"
'''''''''''''''''''''''''''''''''''''''''''''

' ADD SSL BINDING TO SITE
'''''''''''''''''''''''''''''''''''''''''''''

Set oBinding = oIIS.Get("BindingElement").SpawnInstance_
oBinding.BindingInformation = "*:443:"
oBinding.Protocol = "https"

Set oSite = oIIS.Get("Site.Name='Default Web Site'")
arrBindings = oSite.Bindings
ReDim Preserve arrBindings(UBound(arrBindings) + 1)
Set arrBindings(UBound(arrBindings)) = oBinding
oSite.Bindings = arrBindings
Set oPath = oSite.Put_

Note: The certificate hash and store must reference a real, functional certificate on your server. If the certificate hash and/or store name are bogus, an error is returned.

Configure SSL Settings

The following script demonstrates how to set SSL settings by using the IIS 7 WMI provider. You can find this value in the IIS_Schema.xml file.

CONST SSL = 8
Set oIIS = GetObject("winmgmts:root\WebAdministration")
Set oSection = oIIS.Get( _
"AccessSection.Path='MACHINE/WEBROOT/APPHOST',Location='Default Web Site'")
oSection.SslFlags = oSection.SslFlags OR SSL
oSection.Put_

IIS Manager

Obtain a Certificate

Select the server node in the treeview and double-click the Server Certificates feature in the listview:

Click Create Self-Signed Certificate... in the Actions pane.

Enter a friendly name for the new certificate and click OK.

Now you have a self-signed certificate. The certificate is marked for "Server Authentication" use; that is, it uses as a server-side certificate for HTTP SSL encryption and for authenticating the identity of the server.

Create an SSL Binding

Select a site in the tree view and click Bindings... in the Actions pane. This brings up the bindings editor that lets you create, edit, and delete bindings for your Web site. Click Add... to add your new SSL binding to the site.

The default settings for a new binding are set to HTTP on port 80. Select https in the Type drop-down list. Select the self-signed certificate you created in the previous section from the SSL Certificate drop-down list and then click OK.


Now you have a new SSL binding on your site and all that remains is to verify that it works.

Verify the SSL Binding

In the Actions pane, under Browse Web Site, click the link associated with the binding you just created.

Internet Explorere (IE) 7 will display an error page because the self-signed certificate was issued by your computer, not by a trusted Certificate Authority (CA). IE 7 will trust the certificate if you add it to the list of Trusted Root Certification Authorities in the certificates store it on the local computer, or in Group Policy for the domain.
Click Continue to this website (not recommended).

Configure SSL Settings

Configure SSL settings if you want your site to require SSL, or to interact in a specific way with client certificates. Click the site node in the tree view to go back to the site's home page. Double-click the SSL Settings feature in the middle pane.


Summary

In this walkthrough, we successfully used the command-line tool AppCmd.exe, the scripting provider WMI, and IIS Manager to set up SSL on IIS 7.

Thursday, July 22, 2010

HowTo: Secure your Ubuntu Apache Web Server

Setting up a web server with Apache on a Linux distribution is a very quick process, however to make it a secure setup takes some work. This article will show you how to make your Apache web server more secure from an attack by effectively using Access control and authentication strategies.

All the examples below assumes that you are using Ubuntu 7.10 with a basic Apache configuration setup. However, these examples will help any user running an Apache server to make it more secure since the concepts will still apply. This HOWTO should be used on a test server then once that is secure migrated to a production web server.

File Permissions and Access Control

Users and groups:

One of the first things to ensure is that Apache does not run as root because if Apache is cracked then an attacker could get control of the root account. Lets take a look at what user and group Apache is running as.

Run the following command:

# ps auwwfx | grep apache www-data 25675 0.0 0.0 10348 508 ? S Jan21 0:00 \_ /usr/sbin/apache2 -k start
www-data 25686 0.0 0.2 231816 2208 ? Sl Jan21 0:00 \_ /usr/sbin/apache2 -k start
www-data 25688 0.0 0.2 231816 2200 ? Sl Jan21 0:00 \_ /usr/sbin/apache2 -k start

As you can see www-data is the user running Apache. However if it's not then you need to edit your Apache configurations and create a new user and group by:

# groupadd www-data
# useradd -g www-data www-data
# vi /etc/apache2/apache2.conf

Change:

User root
Group root

To:

User www-data
Group www-data

Do a reload to make sure the changes take effect:

# /etc/init.d/apache2 reload

Permissions to serve files:

One of the most overlooked security practices is correctly using the chmod command. For example, we just created a index.cgi in our Apache html root directory but when we go to open the file in our browser we get the error message permission denied. To get our index.cgi file working we do a chmod 777 index.cgi. Before you try this, every Apache administrator should think to themselves' is this secure? The answer should be NO! But how do we make the permissions secure enough and allow the index.cgi script to work?

chmod:

Apache needs to have permission to execute the index.cgi file. However, we don't want everyone to read and write to index.cgi. The owner of the file should have permission to read and write to the file. We do this by:

# chmod 755 index.cgi

Files outside the web root should not be served:

It's very important to have the following lines in your apache.conf:


Options FollowSymLinks
AllowOverride None

Notes
1.The above lines prevent Apache from having access to files outside of its web root.
2.Some distributions have better default security configuration then others. EnGarde Secure Linux is one example where they include the above lines in their Apache configuration file by default.

We don't want users running CGI scripts anywhere on the filesystem but we do need them to run in the web root. The solution to this problem is the "Options ExecCGI" directive.

Example:
Add the following lines to /etc/apache2/apache2.conf:


AllowOverride None
Options ExecCGI
Order allow,deny
Allow from all

Reload apache:

# /etc/init.d/apache2 reload

What if your have resources that should only be accessed by a certain network or IP address?
A solution to this problem is using our Apache configuration to enforce it for you.

Example only allow access to network 192.168.0.0.

Change the following lines in your /etc/apache2/apache2.conf:


AllowOverride None
Options ExecCGI
Order allow,deny
Allow from all

To:


AllowOverride None
Options ExecCGI
Order Deny,Allow
Deny from all
Allow from 192.168.0.0/16

Do a reload to make sure the changes take effect:

# /etc/init.d/apache2 reload

Now only users on you internal network can run CGI script in "/home/username/public_html/cgi-bin"

Authentication

How can we allow only users with the correct password and username to have access to a part of our web root? The following steps will show you how to do this securely.

Basic authentication:

Enable .htaccess

# vi /etc/apache2/apache2.conf

Change:

AllowOverride None

To:

AllowOverride AuthConfig

Do a reload to make sure the changes take effect:

# sudo /etc/init.d/apache2 reload

Create a password file:

# mkdir /var/www/misc
# chmod a+rx /var/www/misc
# cd /var/www/misc
# htpasswd -bc private.passwords username password
Adding password for user username

Create .htaccess

# cd /home/username/public_html/cgi-bin
# vi .htaccess

Add the below in .htaccess

AuthName My Private Area"
AuthType Basic
AuthUserFile /var/www/misc/private.passwords
AuthGroupFile /dev/null require valid-user

Change:


AllowOverride None
Options ExecCGI
Order Deny,Allow
Deny from all
Allow from 192.168.0.0/16

To:


AllowOverride .htaccess
Options ExecCGI
Order Deny,Allow
Deny from all
Allow from 192.168.0.0/16

Do a reload to make sure the changes take effect:

# /etc/init.d/apache2 reload

Digest authentication:

Another method for authentication is called digest authentication. With digest authentication your password is never sent across the network in the clear because they are always transmitted as an MD5 digest of the user's password. This way passwords cannot be determined by sniffing network traffic:

Create a password file:

# mkdir /var/www/misc
# chmod a+rx /var/www/misc
# cd /var/www/misc
# htdigest -c private.passwords realm username
Adding password for username in realm realm.
New password:

Create .htaccess

# cd /home/username/public_html/cgi-bin
# vi .htaccess

Add the below in .htaccess

AuthName "My Private Area"
AuthType Digest
AuthUserFile /var/www/misc/private.passwords
AuthGroupFile /dev/null require valid-user



Tq http://www.linuxsecurity.com/content/view/133913/171/

Enjoy ubuntu... ;)

kunkun-laptop .... ;)