Sign inSign up

detoxd/httpd

By detoxd

•Updated 6 months ago

Image
0

2.3K

detoxd/httpd repository overview

⁠Apache HTTP Server (httpd) - Detoxd Hardened Image

⁠Overview

Apache HTTP Server (commonly called "httpd" or "Apache") is the world's most widely used web server software. Developed and maintained by the Apache Software Foundation since 1995, Apache has powered the majority of websites on the internet and remains a cornerstone of web infrastructure.

⁠Common Use Cases

  • Static Content Serving - HTML, CSS, JS, images
  • Reverse Proxy - mod_proxy for backend services
  • Virtual Hosting - Multiple websites on one server
  • PHP Hosting - Traditional LAMP stack
  • Authentication Gateway - mod_auth for access control
  • SSL/TLS Termination - HTTPS handling

⁠Security Concerns

Apache, being internet-facing, is a common attack target:

  • Information Disclosure - Server version, directory listings
  • Configuration Vulnerabilities - Permissive .htaccess
  • Module Vulnerabilities - Numerous modules with varying security
  • DoS Attacks - Slowloris, resource exhaustion
  • CVE History - Long history means many disclosed vulnerabilities

⁠What Detoxd Does

⁠Server Signature Hiding
ServerSignature Off
ServerTokens Prod
  • ServerSignature Off - Removes version from error pages
  • ServerTokens Prod - Returns only "Apache" without version
⁠System Hardening
  • Updates all Alpine packages to latest versions
  • Removes setuid/setgid bits from binaries
  • Removes unnecessary tools and packages
  • Cleans package caches
⁠Minimal Attack Surface
  • Removes wget, curl, busybox-extras
  • Removes unnecessary system users
  • Secures file permissions
⁠httpd.conf Security Settings
# Disable directory browsing
<Directory />
    Options -Indexes -FollowSymLinks
    AllowOverride None
    Require all denied
</Directory>

# Secure document root
<Directory /var/www/html>
    Options -Indexes -ExecCGI
    AllowOverride None
    Require all granted
</Directory>

# Disable unnecessary modules
# LoadModule autoindex_module modules/mod_autoindex.so
# LoadModule status_module modules/mod_status.so
# LoadModule info_module modules/mod_info.so

# Security headers
Header always set X-Content-Type-Options "nosniff"
Header always set X-Frame-Options "DENY"
Header always set X-XSS-Protection "1; mode=block"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set Content-Security-Policy "default-src 'self'"

# Disable TRACE method
TraceEnable off

# Limit request size
LimitRequestBody 10485760
LimitRequestFields 50
LimitRequestFieldSize 8190
LimitRequestLine 8190

# Timeout settings
Timeout 60
KeepAliveTimeout 5

# Disable server-side includes
<Directory />
    Options -Includes
</Directory>
⁠SSL/TLS Configuration
<VirtualHost *:443>
    SSLEngine on
    SSLCertificateFile /etc/ssl/certs/server.crt
    SSLCertificateKeyFile /etc/ssl/private/server.key
    
    # Strong SSL configuration
    SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
    SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256
    SSLHonorCipherOrder on
    
    # HSTS
    Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"
</VirtualHost>
⁠Block Common Attacks
# Block SQL injection attempts
<IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteCond %{QUERY_STRING} (\<|%3C).*script.*(\>|%3E) [NC,OR]
    RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
    RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2}) [OR]
    RewriteCond %{QUERY_STRING} ^.*(\[|\]|\(|\)|<|>).* [NC]
    RewriteRule ^(.*)$ - [F,L]
</IfModule>

# Disable access to sensitive files
<FilesMatch "^\.ht">
    Require all denied
</FilesMatch>

<FilesMatch "\.(bak|config|sql|fla|psd|ini|log|sh|inc|swp|dist)$">
    Require all denied
</FilesMatch>
⁠Dockerfile Best Practices
FROM detoxd/httpd:2.4-alpine-detox.1

# Copy custom configuration
COPY httpd.conf /usr/local/apache2/conf/httpd.conf
COPY httpd-ssl.conf /usr/local/apache2/conf/extra/httpd-ssl.conf

# Copy static content
COPY --chown=www-data:www-data html/ /usr/local/apache2/htdocs/

# Ensure correct permissions
RUN chmod -R 755 /usr/local/apache2/htdocs/

EXPOSE 80 443

⁠Comparison with Standard httpd

FeatureStandard httpdDetoxd httpd
ServerSignatureOnOff
ServerTokensFullProd
Security patchesManualApplied
Setuid binariesPresentRemoved
Development toolsMay existRemoved
Package cachePresentCleaned

⁠References

Tag summary

Content type

Image

Digest

sha256:bcf705464…

Size

20 MB

Last updated

6 months ago

docker pull detoxd/httpd:2.4.66-alpine3.23-detox.1