{"id":82,"date":"2011-09-25T15:30:18","date_gmt":"2011-09-25T05:30:18","guid":{"rendered":"http:\/\/sijnstra.name\/blog\/?p=82"},"modified":"2011-09-25T15:30:18","modified_gmt":"2011-09-25T05:30:18","slug":"stats-and-security","status":"publish","type":"post","link":"http:\/\/sijnstra.name\/blog\/2011\/09\/25\/stats-and-security\/","title":{"rendered":"Stats and security"},"content":{"rendered":"<p>While developing this blog, I&#8217;ve been working on the background on security and other curiosities. I wanted to use a log processor to look at where some of the hits on this site were coming from, so of course I turned to <a href=\"http:\/\/awstats.sourceforge.net\/\" target=\"_blank\">AWstats<\/a>. I also wanted to make this viewable by myself, and didn&#8217;t want another password to either type in or store. There were great instructions available for <a href=\"https:\/\/help.ubuntu.com\/community\/AWStats\" target=\"_blank\">basic installation<\/a>, but I had to look a little harder for secuirity. I only really want to view the stats from home, and luckily I have a fixed IP address. This is certainly a lazy way to do security, and I haven&#8217;t yet pushed it to be SSL-only, but to bolt down the AWstats pages by IP address all that was required in the Apache2 conf file was:<\/p>\n<p>[sourcecode language=&#8221;xml&#8221;]<br \/>\n  Alias \/awstatsclasses &quot;\/usr\/share\/awstats\/lib\/&quot;<br \/>\n  Alias \/awstats-icon\/ &quot;\/usr\/share\/awstats\/icon\/&quot;<br \/>\n  Alias \/awstatscss &quot;\/usr\/share\/doc\/awstats\/examples\/css&quot;<br \/>\n  ScriptAlias \/awstats\/ \/usr\/lib\/cgi-bin\/<br \/>\n&lt;Location \/awstats&gt;<br \/>\n  Options ExecCGI -MultiViews +SymLinksIfOwnerMatch<br \/>\n  Order Deny,Allow<br \/>\n  Deny from all<br \/>\n  Allow from 1.2.3.4<br \/>\n  Allow from 127<br \/>\n&lt;\/Location&gt;<br \/>\n[\/sourcecode]<\/p>\n<p>Where of course the 1.2.3.4 is replaced with your desired access address &#8211; IP address or DNS address<\/p>\n<p>In other security related news, somebody else ran a script against this site but at least it was a better attempt. They looked for 151 vulnerabilities in a single sitting rather than the 6 the last guys did. There&#8217;s been some other feeble one or two since then, but it&#8217;s nice to be tested thoroughly.<\/p>\n<p>Newsflash: I&#8217;ve now had my first spam comment submitted. Hooray!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>While developing this blog, I&#8217;ve been working on the background on security and other curiosities. I wanted to use a log processor to look at where some of the hits on this site were coming from, so of course I turned to AWstats. I also wanted to make this viewable by myself, and didn&#8217;t want &hellip; <\/p>\n<p class=\"link-more\"><a href=\"http:\/\/sijnstra.name\/blog\/2011\/09\/25\/stats-and-security\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Stats and security&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[5],"tags":[8,10],"_links":{"self":[{"href":"http:\/\/sijnstra.name\/blog\/wp-json\/wp\/v2\/posts\/82"}],"collection":[{"href":"http:\/\/sijnstra.name\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/sijnstra.name\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/sijnstra.name\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/sijnstra.name\/blog\/wp-json\/wp\/v2\/comments?post=82"}],"version-history":[{"count":0,"href":"http:\/\/sijnstra.name\/blog\/wp-json\/wp\/v2\/posts\/82\/revisions"}],"wp:attachment":[{"href":"http:\/\/sijnstra.name\/blog\/wp-json\/wp\/v2\/media?parent=82"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/sijnstra.name\/blog\/wp-json\/wp\/v2\/categories?post=82"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/sijnstra.name\/blog\/wp-json\/wp\/v2\/tags?post=82"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}