Apache as intranet webserver on a windows dominated intranet

Apache as intranet webserver on a windows dominated intranet

Post by Peter Michael Jense » Thu, 19 Sep 2002 03:45:35



Hi

I am about to install a Linux box with a apache webser application on my
company's intranet (99,9% windows boxes).

Which serurity issues do you see in this situation? The intranet is of
cource behind firewalls etc. The apache webserver will not be visible from
the internet. All windows boxes are running the latest anti-virus software
regulary.

How can I obtain a secure intranet web service concerning windows viruses,
etc.?

All comments are more than welcome

Regards
Peter

 
 
 

Apache as intranet webserver on a windows dominated intranet

Post by Christopher Brown » Thu, 19 Sep 2002 05:43:55



Quote:> I am about to install a Linux box with a apache webser application
> on my company's intranet (99,9% windows boxes).

> Which serurity issues do you see in this situation? The intranet is
> of cource behind firewalls etc. The apache webserver will not be
> visible from the internet. All windows boxes are running the latest
> anti-virus software regulary.

> How can I obtain a secure intranet web service concerning windows
> viruses, etc.?

> All comments are more than welcome

It's a lot like "interspecies disease transmission," namely that it
hardly ever happens.

If the Windows boxes are rife with RedCode or Nimda viruses, you'll
doubtless see entries in Apache's logs indicating that there were
attempts to run Windows .EXE files on the Linux box; none of it will
actually _work_, you're totally safe from that sort of thing.

If there's nothing there to attack the box, then there should be very
few security issues.  

You might want to stick a "rootkit checker" and maybe the "Tiger" set
of security auditing tools on the box; if there's someone inside the
network specifically trying to crack into Unix-like boxes, you might
catch them.  But if that scenario sounds as implausible to you as it
does to me, it's certainly not something you'd /expect/.

If you're running Sendmail (or some other such MTA) on the box, and
forwarding mail to anyone, it /might/ be worth putting some sort of
virus checker in to make sure you don't pass on "evil mail," but
again, it's unlikely to be a problem unless you're either accepting
mail from outside, or there's (again) the "someone inside that's out
to get you."

The Linux box is immune to the viruses that would be attacking the
Windows systems, and unless it specifically gets cracked by an
adversary (again, the "someone inside the network that's out to get
you" scenario), it's not going to pass anything evil on to anyone
else.
--

http://cbbrowne.com/info/security.html
Talk a lot, don't you?

 
 
 

Apache as intranet webserver on a windows dominated intranet

Post by Bill Unr » Thu, 19 Sep 2002 20:06:11



]Hi

]I am about to install a Linux box with a apache webser application on my
]company's intranet (99,9% windows boxes).

]Which serurity issues do you see in this situation? The intranet is of
]cource behind firewalls etc. The apache webserver will not be visible from
]the internet. All windows boxes are running the latest anti-virus software
]regulary.

Well, since you assure us that the web server is not visible except from inside, insider
attacks are the threat. Who is writing the web pages being put up on that site? Are they
going to be writing attack web pages?

Who has access tot hat server?
Make sure that you keep up to date with all the security patches for whatever OS you are
running. Make sure you can trust the people who have access to that server, and who set
up web pages.

]How can I obtain a secure intranet web service concerning windows viruses,
]etc.?

 
 
 

1. Linux/Apache webserver linked to win98 intranet problem

Hi there !

I've got Red Hat Linux 7.1 running apache sitting in an intranet, which is
really just the Linux and a Win98 box connected thru a hub.

I can view my web pages from the linux box a-ok, and can ping the win98
box, as well as ping the linux box from the win98.

My problem is that I cannot see the webpages from the win98 machine...what
gives ? Any help would be appreciated.

        Dana

2. Routing problems?

3. *** Intranet unaccessible to Intranet!!! ***

4. Network setup

5. pointer for simple Intranet webserver setup?

6. Login Access to a Linux computer

7. Getting off the intranet with Linux laptop under Windows network ...

8. How do I Setup a special Linux Server

9. Linux Internet Server enabling ICQ into Windows Intranet clients

10. How to configure DHCP on Slackware linux with cable + intranet of Windows m/c

11. apache proxy inter-/intranet

12. Apache intranet config ?

13. intranet domain naming with apache server