Tag: apache
Enhanced Nagios; CGI Security and Authentication
by Mark on Nov.03, 2008, under Nagios, sysadmin
Over the past few days we have been tackling a nasty Cross Site Request Forgery (CSRF) bug in Nagios 3.0.4. With our bug fix I updated the Nagios documentation to include some information on Enhanced CGI Security and Authentication. This is a much needed addition that answers some of the communities questions regarding different ways to secure Nagios. This post will rehash much of what I wrote about in the documentation. There are many ways to enhance the security of your monitoring server and Nagios environment. This should not be taken as the end all approach to security. Instead, think of it as an introduction to some of the techniques you can use to tighten the security of your system. As always, you should do your research and use the best techniques available. Treat your monitoring server as it were the most important server in your network and you shall be rewarded.