Cyber Security · मराठी आवृत्ती
Static web server चे basic hardening
या page मध्ये
Site चालू झाली की अनावश्यक माहिती आणि access कमी करू. Hardening म्हणजे सुरक्षित configuration: version details कमी करणे, directory listing बंद ठेवणे, योग्य response headers आणि sensitive dot-files serve होऊ न देणे. हे updates किंवा application security ची जागा घेत नाही.
Nginx आणि Apache settings
# Nginx – in the http { } block of nginx.conf
server_tokens off; # hide version number
# in each server block
autoindex off;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
location ~ /\.(?!well-known) { deny all; } # block .git, .env, .htaccess
# Apache – /etc/httpd/conf.d/security.conf (Ubuntu: conf-available/security.conf)
ServerTokens Prod
ServerSignature Off
TraceEnable Off
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "SAMEORIGIN"
<DirectoryMatch "/\.(?!well-known)">
Require all denied
</DirectoryMatch>
curl -I http://localhost # check: no version in the Server header, new headers present
Nginx मध्ये server_tokens http context मध्ये; autoindex, headers आणि dot-file location योग्य server block मध्ये. Apache मध्ये corresponding security config वापरा. Ubuntu Apache वर headers module साठी sudo a2enmod headers लागतो. Config test करूनच reload करा.
nosniff browser चं MIME sniffing मर्यादित करतो. SAMEORIGIN compatible browsers मध्ये दुसऱ्या origin कडून framing मर्यादित करतो. Referrer-Policy cross-origin requests मध्ये किती referrer information द्यायची ते नियंत्रित करतो. Application ची embedding गरज असेल तर policy त्यानुसार ठरवा.
Amazon Linux Nginx: before/after
Chapter 8.2 मधली mysite config आणि योग्य public IP/Host गृहीत धरून:
# 0. keep a copy of both files before you edit
sudo cp /etc/nginx/nginx.conf /etc/nginx/nginx.conf.bak
sudo cp /etc/nginx/conf.d/mysite.conf /etc/nginx/conf.d/mysite.conf.bak
# 1. note the headers BEFORE (Host header = public IP, so our server block answers)
IP=$(curl -s https://checkip.amazonaws.com)
curl -I http://localhost -H "Host: $IP"
# 2. hide the version: add server_tokens off; inside the http { } block
sudo vi /etc/nginx/nginx.conf
# 3. in the server { } block of mysite.conf add: autoindex off; the three add_header lines;
# and the location block that denies dot-files (see the Nginx block above)
sudo vi /etc/nginx/conf.d/mysite.conf
# 4. test the syntax, then reload only if the test passes
sudo nginx -t && sudo service nginx reload
# 5. check AFTER
curl -I http://localhost -H "Host: $IP"
आधी backup आणि existing headers नोंदवा. योग्य contexts मध्ये settings द्या. Syntax test → reload → त्याच Host ने headers तपासा. NAT मागे असल्यास checkip output ऐवजी आपल्या actual domain/Host ची value वापरा.
Amazon Linux Apache साठी आवश्यक असल्यास httpd install करा, वरील Apache directives /etc/httpd/conf.d/security.conf मध्ये द्या आणि sudo apachectl configtest && sudo service httpd reload करा.
Example 1: Mauli Dairy, Pune—काल्पनिक
पुण्यातल्या काल्पनिक dairy ची price-list site Nginx वर आहे. Before/after तुलना:
| Hardening आधी | Hardening नंतर | |
|---|---|---|
| Status line | HTTP/1.1 200 OK |
HTTP/1.1 200 OK |
| Server | nginx/<version number> |
nginx (no version) |
| X-Content-Type-Options | – | nosniff |
| X-Frame-Options | – | SAMEORIGIN |
| Referrer-Policy | – | strict-origin-when-cross-origin |
ग्राहकाला page तसाच दिसतो. पण response मधला exact Nginx version कमी झाला, nosniff आला आणि cross-origin framing वर मर्यादा आली. यामुळे काही माहिती leak/ब्राउझर गैरवापर कमी होऊ शकतो; site पूर्ण सुरक्षित झाल्याची हमी नाही.
Example 2: Nashik Valley Grapes—काल्पनिक
Developer ने repository थेट web root मध्ये clone केल्यामुळे .git आणि dummy .env file public झाली, असं या lab मध्ये समजा. स्वतःच्या test server वर तपासा:
curl -I http://<PUBLIC_IP>/.git/config # before: 200 OK (anyone can download it)
curl -I http://<PUBLIC_IP>/.env # before: 200 OK
# ... add the dot-file location block, nginx -t, reload ...
curl -I http://<PUBLIC_IP>/.git/config # after: 403 Forbidden
curl -I http://<PUBLIC_IP>/.env # after: 403 Forbidden
curl -I http://<PUBLIC_IP>/.well-known/acme-challenge/test.txt # still allowed (Certbot needs it, Chapter 13)
Before 200 आणि after 403 ही या lab ची अपेक्षित तुलना आहे; server च्या विद्यमान config नुसार before response आधीच blocked असू शकतो. location ~ /\.(?!well-known) हा regex dot-path match करून deny करतो. हा source pattern “well-known” prefix ला exception देतो; अत्यंत अचूक path boundary policy हवी असल्यास regex स्वतंत्र review करा. .well-known/acme-challenge मार्ग Certbot validation साठी लागू पडतो; test file नसल्यास 404 येणं स्वाभाविक आहे.
खरा प्राथमिक उपाय म्हणजे web root मध्ये फक्त public files ठेवणे. Dot-file blocking हा अतिरिक्त बचाव आहे; secrets तिथे ठेवण्याची परवानगी नाही.
add_header inheritance चा trap
प्रचलित/default Nginx inheritance behavior मध्ये location ला स्वतःचा add_header दिला तर parent चे add_header आपोआप inherit होत नाहीत. त्यामुळे:
location ~* \.(jpg|png|css)$ {
add_header Cache-Control "public, max-age=86400"; # now ONLY this header is sent for images and CSS
}
Image/CSS response वर फक्त Cache-Control येऊन security headers सुटू शकतात. तुमच्या installed version/config मधले inheritance options तपासा. त्या location मध्ये आवश्यक security headers repeat/include करून config test/reload करा. मग actual CSS/image URL वर curl -I ने तपासा. Example चा /style.css path तुमच्या file शी जुळतो का पाहा; आपल्या sample मध्ये CSS /css/style.css आहे.
Practice
Hardening आधी/नंतर public site चे headers compare करा. Lab root मध्ये फक्त dummy text असलेली .env test file तयार करा आणि request blocked आहे का पाहा. Test झाल्यावर dummy file काढा; खरे passwords वापरू नका.
Part 3 recap
- Home मध्ये upload, मग public content /var/www/site मध्ये deploy. 755/644 सोबत योग्य ownership.
- Amazon Linux conf.d; Ubuntu sites-available + enable; active/default site तपासा.
- Root बदलताना Nginx root किंवा Apache DocumentRoot/Directory आणि SELinux mappings तपासा.
- Port बदलताना listener, source rules, host firewall आणि SELinux policy तपासा.
- Index क्रम आणि directory listing समजून configure करा.
- Versions कमी, headers आणि dot-files controls; प्रत्येक बदलानंतर test/reload/verify.
पुढे PHP, LAMP आणि LEMP मधून dynamic websites पाहू.