Security issues

Gregor Mosheh stigmata_blackangel at YAHOO.COM
Wed May 25 14:51:46 EDT 2005


On 5/25/05, C J <susesuse at totalise.co.uk> wrote:
> How can I ensure that I limit the security risks
> involved with running MapServer on my webserver?

I agree with Camden about a hardware firewall. There
are many exploits against Windows itself, and a
hardware firewall really reduces those.

Now that you're behind a firewall, you probably wanted
to know about the security of Mapserver, Apache, PHP,
and so on because those are what's listening on port
80.

Sadly, it is true that these packages do have security
issues - Apache has bugs, PHP has holes, etc.
Fortunately, they fix them and release newer versions.
So check the Apache and PHP websites often and see if
there's a newer version, especially if it says "this
release fixes a security issue..."

The same goes for anything else you have that listens
on the Net, e.g. database servers. If you're not using
a firewall, or if your firewall does allow the DB to
be accessed from the Net, then the same goes for those
packages as well: check for updates, cuz bugs do get
found.




__________________________________
Do you Yahoo!?
Yahoo! Small Business - Try our new Resources site
http://smallbusiness.yahoo.com/resources/



More information about the mapserver-users mailing list