je repost mon lighttpd conf :
------------------------------
server.modules = (
"mod_access",
"mod_alias",
"mod_compress",
"mod_redirect",
# "mod_rewrite",
)
server.document-root = "/var/www"
server.upload-dirs = ( "/var/cache/lighttpd/uploads" )
server.errorlog = "/var/log/lighttpd/error.log"
server.pid-file = "/var/run/lighttpd.pid"
server.username = "www-data"
server.groupname = "www-data"
index-file.names = ( "index.php", "index.html",
"index.htm", "default.htm",
" index.lighttpd.html" )
url.access-deny = ( "~", ".inc" )
static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" )
include_shell "/usr/share/lighttpd/use-ipv6.pl"
dir-listing.encoding = "utf-8"
server.dir-listing = "enable"
compress.cache-dir = "/var/cache/lighttpd/compress/"
compress.filetype = ( "application/x-javascript", "text/css", "text/html", "text/plain" )
include_shell "/usr/share/lighttpd/create-mime.assign.pl"
include_shell "/usr/share/lighttpd/include-conf-enabled.pl"
fastcgi.server = ( ".php" => ((
"bin-path" => "/usr/bin/php5-cgi",
"socket" => "/tmp/php.socket"
)))
$SERVER["socket"] == ":443" {
ssl.engine = "enable"
ssl.pemfile = "/etc/lighttpd/certs/lighttpd.pem"
}
server.modules += ( "mod_auth" )
auth.backend = "htdigest"
auth.backend.htdigest.userfile = "/etc/lighttpd/.auth"
auth.debug = 2
auth.require = ( "/rutorrent/" =>
(
"method" => "digest",
"realm" => "ruTorrent Seedbox",
"require" => "valid-user"
),
"/FRA0" => (
"method" => "digest",
"realm" => "ruTorrent Seedbox",
"require" => "user=franck",
),
)
server.modules += ( "mod_scgi" )
scgi.server = (
"/FRA0" =>
( "127.0.0.1" =>
(
"socket" => "/home/franck/.session/fra.socket",
"check-local" => "disable",
"disable-time" => 0, # don't disable scgi if connection fails
)
)
)
alias.url += (
"/awstatsclasses" => "/usr/share/awstats/lib/",
"/awstatscss" => "/usr/share/doc/awstats/examples/css",
"/awstatsicons" => "/usr/share/awstats/icon/",
"/awstats" => "/usr/lib/cgi-bin/",
"/icon/" => "/usr/share/awstats/icon/"
)
server.modules += ( "mod_cgi" )
$HTTP["url"] =~ "/awstats/" {
cgi.assign = (
".pl" => "/usr/bin/perl",
".cgi" => "/usr/bin/perl"
)
auth.backend = "htdigest"
auth.backend.htdigest.userfile = "/etc/lighttpd/.aw"
auth.require = ( "/awstats/" =>
(
"method" => "digest",
"realm" => "Awstats",
"require" => "valid-user"
)
}
---------------------------------------
j'ai suivi ce tuto (
http://mondedie.fr/discussion/5253/tuto-securisation-logs#Item_20 ) aussi pour sécurisé mon serveur et depuis je n'ai plus accès à ce dernier sauf avec webmin. plus d'accès ssh, ftp et rutorrent...