Jump to content

Apache 2.2 -- HTTPD.exe service


farnoise

Recommended Posts

Hi,

I have a quick question I hope you guys can help me, I'm writing a report on Tomcat and Apache server but there is something that I really don't know about.

I wonder if anyone can help me the Security disadvantages of HTTPD.exe service on a local network(The network that is connected to the Internet  through a Gateway imagine a big company's network),

 

first of all can any one access my HTTPD.exe to send spam emails to the global address book and secondly what are the real critical risks of having this service unable on our network?

 

Thank you all for you helps

Link to comment
Share on other sites

Httpd is a web service, not an SMTP service.  If you want to keep spam down, look into shutting down sendmail

Without a web service such as HTTPd or IIS, how would a company have an intranet?  Who doesn't have one?

 

Httpd is not a security concern.  Poorly written software on a webserver IS the security concern.

 

Source: Andrew Gauger

Link to comment
Share on other sites

I understand that is not a security concern but the problem is our company's IT HQ is asking us to shut down our Apache server, cuz they think this module is a security concern, plus the main reason that I started this server in my Division was I needed a mail() function to deploy couple emails everyday to some people. So now I have to come up with a report to prove that it's not a BIG DEAL really just a  simple module

 

Regards

Link to comment
Share on other sites

Sorry but if I'm not misunderstood, You mean why I'm not using PHP's send mail function? Well this is the main reason that I have this server up and running because we don't want to use outside sources and we don't want to open any port to outside word so I have this server up and running then we can have all transitions inside our network, And it's clearly visible that there is absolutely no security concern with this method but it's just the IT security Div, are overreacting.

 

btw I guess I got my answer from your first post, I just need to clarify that this is not a SMTP service

 

I really appreciate your helps Andrew and thanks again

 

Arad

 

Link to comment
Share on other sites

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.