[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fdq-1z5oygUUdyByuB-c9edHkwTBZUuQ6EAUFWi4CXPk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},635,"How can you use mod_rewrite to redirect traffic based on User-Agent?","Use `RewriteCond` to check the `HTTP_USER_AGENT` header and `RewriteRule` to specify the redirection target. For example, `RewriteCond \"%{HTTP_USER_AGENT}\" \"Macintosh; Intel Mac OS X 10_9_3\" [NC]` followed by `RewriteRule 1.html 2.html` will redirect requests from that Safari browser to `2.html`. This technique is demonstrated in the article for filtering traffic by client type.","\u003Cp>Use `RewriteCond` to check the `HTTP_USER_AGENT` header and `RewriteRule` to specify the redirection target. For example, `RewriteCond &quot;%{HTTP_USER_AGENT}&quot; &quot;Macintosh; Intel Mac OS X 10_9_3&quot; [NC]` followed by `RewriteRule 1.html 2.html` will redirect requests from that Safari browser to `2.html`. This technique is demonstrated in the article for filtering traffic by client type.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fcia-hive-beacon-infrastructure-replication-1-using-apache-mod-rewrite-for-http-traffic-distribution\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-you-use-mod_rewrite-to-redirect-traffic-based-on-user-agent-1777482560236","RewriteCond, HTTP_USER_AGENT, redirect by User-Agent, Safari, traffic filtering",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},156,"CIA Hive Beacon Infrastructure Replication 1 - Using Apache mod_rewrite for HTTP Traffic Distribution","cia-hive-beacon-infrastructure-replication-1-using-apache-mod-rewrite-for-http-traffic-distribution","Learn to replicate CIA Hive's HTTP traffic distribution using Apache mod_rewrite. Step-by-step guide for Windows and Ubuntu setups with .htaccess rules.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>On November 9, 2017, WikiLeaks released a document codenamed Vault8, containing the source code and development documentation for the server remote control tool Hive. The framework diagram in the development documentation shows that Hive supports traffic distribution functionality: if the traffic is valid, it is forwarded to the Honeycomb server; if there are issues with the traffic, it is forwarded to the Cover Server.\u003C\u002Fp>\u003Cp>This article, solely from a technical research perspective, attempts to use Apache's mod_rewrite module to achieve HTTP traffic distribution and accomplish the same objective.\u003C\u002Fp>\u003Cp>The marked framework diagram is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017280801_0_e120939b27.jpeg\">\u003C\u002Fp>\u003Cp>Previous analysis article:\u003C\u002Fp>\u003Cp>\"CIA Hive Testing Guide - Source Code Acquisition and Brief Analysis\"\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Installing and configuring Apache mod_rewrite on Windows systems\u003C\u002Fli>\u003Cli>Installing and configuring Apache mod_rewrite on Ubuntu systems\u003C\u002Fli>\u003Cli>Rule configuration techniques and examples\u003C\u002Fli>\u003Cli>Implement HTTP traffic distribution based on judgment conditions\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Install and configure Apache mod_rewrite on Windows system\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Download Apache\u003C\u002Fh3>\u003Cp>Address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fhttpd.apache.org\u002Fdownload.cgi\u003C\u002Fp>\u003Cp>Select the required version, test version Apache 2.4.33, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.apachehaus.com\u002Fcgi-bin\u002Fdownload.plx?dli=wUWZ1allWW00kej9iUG5UeJVlUGRVYRdnWzQmW\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Cp>After extraction, install via command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd \\Apace24\\bin\u003Cbr>httpd -k install\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enable mod_rewrite module\u003C\u002Fh3>\u003Cp>Edit file: \\Apace24\\conf\\httpd.conf\u003C\u002Fp>\u003Cp>Find #LoadModule rewrite_module modules\u002Fmod_rewrite.so and remove the #\u003C\u002Fp>\u003Ch3>4. Enable support for .htaccess files\u003C\u002Fh3>\u003Cp>Edit the file: \\Apace24\\conf\\httpd.conf\u003C\u002Fp>\u003Cp>Locate the following section:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DocumentRoot \"${SRVROOT}\u002Fhtdocs\"\u003Cbr>\u003Cdirectory \"${srvroot}=\"\" htdocs\"=\"\">\u003Cbr>    #\u003Cbr>    # Possible values for the Options directive are \"None\", \"All\",\u003Cbr>    # or any combination of:\u003Cbr>    #   Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI MultiViews\u003Cbr>    #\u003Cbr>    # Note that \"MultiViews\" must be named *explicitly* --- \"Options All\"\u003Cbr>    # doesn't give it to you.\u003Cbr>    #\u003Cbr>    # The Options directive is both complicated and important.  Please see\u003Cbr>    # http:\u002F\u002Fhttpd.apache.org\u002Fdocs\u002F2.4\u002Fmod\u002Fcore.html#options\u003Cbr>    # for more information.\u003Cbr>    #\u003Cbr>    Options Indexes FollowSymLinks\u003Cbr>\u003Cbr>    #\u003Cbr>    # AllowOverride controls what directives may be placed in .htaccess files.\u003Cbr>    # It can be \"All\", \"None\", or any combination of the keywords:\u003Cbr>    #   Options FileInfo AuthConfig Limit\u003Cbr>    #\u003Cbr>    AllowOverride All\u003Cbr>\u003Cbr>    #\u003Cbr>    # Controls who can get stuff from this server.\u003Cbr>    #\u003Cbr>    Require all granted\u003Cbr>\u003C\u002Fdirectory>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change AllowOverride None to AllowOverride All\u003C\u002Fp>\u003Ch3>5. Write .htaccess file and configure rules\u003C\u002Fh3>\u003Cp>Save path: \\Apace24\\htdocs\\\u003C\u002Fp>\u003Cp>Test rule: redirect 1.html to 2.html, specific content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteRule 1.html 2.html\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Open with Notepad, save as a file with filename \".htaccess\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Filename includes quotes \", as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017308894_1_83915ea807.jpeg\">\u003C\u002Fp>\u003Cp>2.html is saved in \\Apace24\\htdocs\\, content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>True page\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Start Apache service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>httpd.exe -k start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Test\u003C\u002Fh3>\u003Cp>Access http:\u002F\u002F127.0.0.1\u002F1.html\u003C\u002Fp>\u003Cp>Return content True page, indicating the webpage has been redirected to 2.html\u003C\u002Fp>\u003Ch3>8. Supplement\u003C\u002Fh3>\u003Cp>Apache log path is \\Apache24\\logs\u003C\u002Fp>\u003Cp>mod_rewrite logs are saved in error.log\u003C\u002Fp>\u003Cp>File \\Apache24\\conf\\httpd.conf can specify log recording level\u003C\u002Fp>\u003Ch2>0x03 Install and configure Apache mod_rewrite on Ubuntu system\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Download and install\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sudo apt-get install apache2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Enable the mod_rewrite module\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sudo a2enmod rewrite\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enable support for .htaccess files\u003C\u002Fh3>\u003Cp>Edit the file: \u002Fetc\u002Fapache2\u002Fapache2.conf\u003C\u002Fp>\u003Cp>Locate the following section:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cdirectory var=\"\" www=\"\">\u003Cbr>        Options Indexes FollowSymLinks\u003Cbr>        AllowOverride None\u003Cbr>        Require all granted\u003Cbr>\u003C\u002Fdirectory>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change AllowOverride None to AllowOverride All\u003C\u002Fp>\u003Ch3>4. Write the .htaccess file and configure the rules\u003C\u002Fh3>\u003Cp>Save the path as \\var\\www\\html\\\u003C\u002Fp>\u003Cp>The test rule is to redirect 1.html to 2.html, with the specific content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteRule 1.html 2.html\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2.html is saved in \\var\\www\\html\\, with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>True page\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Start the Apache service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sudo \u002Fetc\u002Finit.d\u002Fapache2 restart\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Test\u003C\u002Fh3>\u003Cp>Visit http:\u002FIP\u002F1.html\u003C\u002Fp>\u003Cp>The returned content 'True page' indicates that the webpage has been redirected to 2.html\u003C\u002Fp>\u003Ch3>7. Supplement\u003C\u002Fh3>\u003Cp>The log path for Apache is \u002Fvar\u002Flog\u002Fapache2\u002F\u003C\u002Fp>\u003Cp>mod_rewrite logs are saved in error.log\u003C\u002Fp>\u003Cp>The file \u002Fetc\u002Fapache2\u002Fapache2.conf can specify the log level\u003C\u002Fp>\u003Ch2>0x04 Rule Configuration Tips and Examples\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Redirect all web pages to https:\u002F\u002Fwww.baidu.com\u003C\u002Fh3>\u003Cp>The content of the .htaccess file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteRule . https:\u002F\u002Fwww.baidu.com\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Filter Request Header\u003C\u002Fh3>\u003Ch4>(1) User Agent\u003C\u002Fh4>\u003Cp>Redirect only requests with specific User Agents\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Access 1.html using Safari on Mac and redirect it to 2.html\u003C\u002Fp>\u003Cp>The content of the .htaccess file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteCond \"%{HTTP_USER_AGENT}\" \"Macintosh; Intel Mac OS X 10_9_3\" [NC]\u003Cbr>RewriteRule 1.html 2.html\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>RewriteCond \"%{HTTP_USER_AGENT}\" \"Macintosh; Intel Mac OS X 10_9_3\" [NC] represents the condition, checking whether HTTP_USER_AGENT contains the string \"Macintosh; Intel Mac OS X 10_9_3\" (case-insensitive)\u003C\u002Fp>\u003Cp>NC: Character comparison, case-insensitive\u003C\u002Fp>\u003Cp>For detailed parameter descriptions, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fhttpd.apache.org\u002Fdocs\u002Fcurrent\u002Fmod\u002Fmod_rewrite.html#rewritecond\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Testing with curl\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simulating Chrome browser:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>curl -A \"Mozilla\u002F5.0 (Windows NT 10.0; WOW64) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F65.0.3325.181 Safari\u002F537.36\" http:\u002F\u002F192.168.62.137\u002F1.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>No redirection occurred, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017331540_2_5421957909.jpeg\">\u003C\u002Fp>\u003Cp>Simulating Mac Safari browser:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>curl -A \"Mozilla\u002F5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\u002F537.75.14 (KHTML, like Gecko) Version\u002F7.0.3 Safari\u002F7046A194A\" http:\u002F\u002F192.168.62.137\u002F1.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Web page redirection, obtaining the content of 2.html, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017382369_3_d5edc245d1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Method for modifying User Agent in Chrome browser\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Access the page, F12 -&gt; More tools -&gt; Network conditions, select User agent as Safari — Mac\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017405146_4_d864dd4e0b.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Referer\u003C\u002Fh4>\u003Cp>Redirect only requests from specific sources\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the source is test.com, redirect to 2.html when accessing 1.html\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteCond \"%{HTTP_REFERER}\" \"test.com\" [NC]\u003Cbr>RewriteRule 1.html 2.html\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Testing with curl:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>curl -e \"test.com\" http:\u002F\u002F192.168.62.137\u002F1.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Other available filtering conditions\u003C\u002Fh4>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017453164_5_a188d27b9d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image source: https:\u002F\u002Fhttpd.apache.org\u002Fdocs\u002Fcurrent\u002Fmod\u002Fmod_rewrite.html#rewritecond\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Jeff Dimmock shared insights on configuring rules with mod_rewrite on his blog, which is worth learning. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbluescreenofjeff.com\u002Ftags\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the methods for installing and configuring Apache mod_rewrite on Windows and Ubuntu systems, shares configuration tips and examples, and achieves HTTP traffic distribution based on request conditions from a technical research perspective.\u003C\u002Fp>\u003Cp>The next article will cover the implementation of HTTPS traffic distribution.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>On November 9, 2017, WikiLeaks released a document codenamed Vault8, containing the source code and development documentation for the server remote control tool Hive. The framework diagram in the development documentation shows that Hive supports traffic distribution functionality: if the traffic is valid, it is forwarded to the Honeycomb server; if there are issues with the traffic, it is forwarded to the Cover Server.\u003C\u002Fp>\u003Cp>This article, solely from a technical research perspective, attempts to use Apache's mod_rewrite module to achieve HTTP traffic distribution and accomplish the same objective.\u003C\u002Fp>\u003Cp>The marked framework diagram is as follows:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017280801_0_e120939b27-1.jpeg\">\u003C\u002Fp>\u003Cp>Previous analysis article:\u003C\u002Fp>\u003Cp>\"CIA Hive Testing Guide - Source Code Acquisition and Brief Analysis\"\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Installing and configuring Apache mod_rewrite on Windows systems\u003C\u002Fli>\u003Cli>Installing and configuring Apache mod_rewrite on Ubuntu systems\u003C\u002Fli>\u003Cli>Rule configuration techniques and examples\u003C\u002Fli>\u003Cli>Implement HTTP traffic distribution based on judgment conditions\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Install and configure Apache mod_rewrite on Windows system\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Download Apache\u003C\u002Fh3>\u003Cp>Address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fhttpd.apache.org\u002Fdownload.cgi\u003C\u002Fp>\u003Cp>Select the required version, test version Apache 2.4.33, download address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.apachehaus.com\u002Fcgi-bin\u002Fdownload.plx?dli=wUWZ1allWW00kej9iUG5UeJVlUGRVYRdnWzQmW\u003C\u002Fp>\u003Ch3>2. Installation\u003C\u002Fh3>\u003Cp>After extraction, install via command line:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd \\Apace24\\bin\u003Cbr>httpd -k install\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enable mod_rewrite module\u003C\u002Fh3>\u003Cp>Edit file: \\Apace24\\conf\\httpd.conf\u003C\u002Fp>\u003Cp>Find #LoadModule rewrite_module modules\u002Fmod_rewrite.so and remove the #\u003C\u002Fp>\u003Ch3>4. Enable support for .htaccess files\u003C\u002Fh3>\u003Cp>Edit the file: \\Apace24\\conf\\httpd.conf\u003C\u002Fp>\u003Cp>Locate the following section:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>DocumentRoot \"${SRVROOT}\u002Fhtdocs\"\u003Cbr>\u003Cdirectory \"${srvroot}=\"\" htdocs\"=\"\">\u003Cbr>    #\u003Cbr>    # Possible values for the Options directive are \"None\", \"All\",\u003Cbr>    # or any combination of:\u003Cbr>    #   Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI MultiViews\u003Cbr>    #\u003Cbr>    # Note that \"MultiViews\" must be named *explicitly* --- \"Options All\"\u003Cbr>    # doesn't give it to you.\u003Cbr>    #\u003Cbr>    # The Options directive is both complicated and important.  Please see\u003Cbr>    # http:\u002F\u002Fhttpd.apache.org\u002Fdocs\u002F2.4\u002Fmod\u002Fcore.html#options\u003Cbr>    # for more information.\u003Cbr>    #\u003Cbr>    Options Indexes FollowSymLinks\u003Cbr>\u003Cbr>    #\u003Cbr>    # AllowOverride controls what directives may be placed in .htaccess files.\u003Cbr>    # It can be \"All\", \"None\", or any combination of the keywords:\u003Cbr>    #   Options FileInfo AuthConfig Limit\u003Cbr>    #\u003Cbr>    AllowOverride All\u003Cbr>\u003Cbr>    #\u003Cbr>    # Controls who can get stuff from this server.\u003Cbr>    #\u003Cbr>    Require all granted\u003Cbr>\u003C\u002Fdirectory>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change AllowOverride None to AllowOverride All\u003C\u002Fp>\u003Ch3>5. Write .htaccess file and configure rules\u003C\u002Fh3>\u003Cp>Save path: \\Apace24\\htdocs\\\u003C\u002Fp>\u003Cp>Test rule: redirect 1.html to 2.html, specific content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteRule 1.html 2.html\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Open with Notepad, save as a file with filename \".htaccess\"\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Filename includes quotes \", as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017308894_1_83915ea807-1.jpeg\">\u003C\u002Fp>\u003Cp>2.html is saved in \\Apace24\\htdocs\\, content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>True page\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Start Apache service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>httpd.exe -k start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>7. Test\u003C\u002Fh3>\u003Cp>Access http:\u002F\u002F127.0.0.1\u002F1.html\u003C\u002Fp>\u003Cp>Return content True page, indicating the webpage has been redirected to 2.html\u003C\u002Fp>\u003Ch3>8. Supplement\u003C\u002Fh3>\u003Cp>Apache log path is \\Apache24\\logs\u003C\u002Fp>\u003Cp>mod_rewrite logs are saved in error.log\u003C\u002Fp>\u003Cp>File \\Apache24\\conf\\httpd.conf can specify log recording level\u003C\u002Fp>\u003Ch2>0x03 Install and configure Apache mod_rewrite on Ubuntu system\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Download and install\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sudo apt-get install apache2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Enable the mod_rewrite module\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sudo a2enmod rewrite\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Enable support for .htaccess files\u003C\u002Fh3>\u003Cp>Edit the file: \u002Fetc\u002Fapache2\u002Fapache2.conf\u003C\u002Fp>\u003Cp>Locate the following section:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cdirectory var=\"\" www=\"\">\u003Cbr>        Options Indexes FollowSymLinks\u003Cbr>        AllowOverride None\u003Cbr>        Require all granted\u003Cbr>\u003C\u002Fdirectory>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Change AllowOverride None to AllowOverride All\u003C\u002Fp>\u003Ch3>4. Write the .htaccess file and configure the rules\u003C\u002Fh3>\u003Cp>Save the path as \\var\\www\\html\\\u003C\u002Fp>\u003Cp>The test rule is to redirect 1.html to 2.html, with the specific content as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteRule 1.html 2.html\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2.html is saved in \\var\\www\\html\\, with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cbr>\u003Cbr>True page\u003Cbr>\u003Cbr>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Start the Apache service\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>sudo \u002Fetc\u002Finit.d\u002Fapache2 restart\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>6. Test\u003C\u002Fh3>\u003Cp>Visit http:\u002FIP\u002F1.html\u003C\u002Fp>\u003Cp>The returned content 'True page' indicates that the webpage has been redirected to 2.html\u003C\u002Fp>\u003Ch3>7. Supplement\u003C\u002Fh3>\u003Cp>The log path for Apache is \u002Fvar\u002Flog\u002Fapache2\u002F\u003C\u002Fp>\u003Cp>mod_rewrite logs are saved in error.log\u003C\u002Fp>\u003Cp>The file \u002Fetc\u002Fapache2\u002Fapache2.conf can specify the log level\u003C\u002Fp>\u003Ch2>0x04 Rule Configuration Tips and Examples\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Redirect all web pages to https:\u002F\u002Fwww.baidu.com\u003C\u002Fh3>\u003Cp>The content of the .htaccess file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteRule . https:\u002F\u002Fwww.baidu.com\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Filter Request Header\u003C\u002Fh3>\u003Ch4>(1) User Agent\u003C\u002Fh4>\u003Cp>Redirect only requests with specific User Agents\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Access 1.html using Safari on Mac and redirect it to 2.html\u003C\u002Fp>\u003Cp>The content of the .htaccess file is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteCond \"%{HTTP_USER_AGENT}\" \"Macintosh; Intel Mac OS X 10_9_3\" [NC]\u003Cbr>RewriteRule 1.html 2.html\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cp>RewriteCond \"%{HTTP_USER_AGENT}\" \"Macintosh; Intel Mac OS X 10_9_3\" [NC] represents the condition, checking whether HTTP_USER_AGENT contains the string \"Macintosh; Intel Mac OS X 10_9_3\" (case-insensitive)\u003C\u002Fp>\u003Cp>NC: Character comparison, case-insensitive\u003C\u002Fp>\u003Cp>For detailed parameter descriptions, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fhttpd.apache.org\u002Fdocs\u002Fcurrent\u002Fmod\u002Fmod_rewrite.html#rewritecond\u003C\u002Fp>\u003Cp>\u003Cstrong>1. Testing with curl\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Simulating Chrome browser:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>curl -A \"Mozilla\u002F5.0 (Windows NT 10.0; WOW64) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F65.0.3325.181 Safari\u002F537.36\" http:\u002F\u002F192.168.62.137\u002F1.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>No redirection occurred, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017331540_2_5421957909-1.jpeg\">\u003C\u002Fp>\u003Cp>Simulating Mac Safari browser:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>curl -A \"Mozilla\u002F5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit\u002F537.75.14 (KHTML, like Gecko) Version\u002F7.0.3 Safari\u002F7046A194A\" http:\u002F\u002F192.168.62.137\u002F1.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Web page redirection, obtaining the content of 2.html, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017382369_3_d5edc245d1-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>2. Method for modifying User Agent in Chrome browser\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Access the page, F12 -&gt; More tools -&gt; Network conditions, select User agent as Safari — Mac\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017405146_4_d864dd4e0b-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Referer\u003C\u002Fh4>\u003Cp>Redirect only requests from specific sources\u003C\u002Fp>\u003Cp>\u003Cstrong>Example:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If the source is test.com, redirect to 2.html when accessing 1.html\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003Cifmodule mod_rewrite.c=\"\">\u003Cbr>RewriteEngine on\u003Cbr>RewriteCond \"%{HTTP_REFERER}\" \"test.com\" [NC]\u003Cbr>RewriteRule 1.html 2.html\u003Cbr>\u003C\u002Fifmodule>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Testing with curl:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>curl -e \"test.com\" http:\u002F\u002F192.168.62.137\u002F1.html\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Other available filtering conditions\u003C\u002Fh4>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017453164_5_a188d27b9d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Image source: https:\u002F\u002Fhttpd.apache.org\u002Fdocs\u002Fcurrent\u002Fmod\u002Fmod_rewrite.html#rewritecond\u003C\u002Fp>\u003Cp>\u003Cstrong>Additional note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Jeff Dimmock shared insights on configuring rules with mod_rewrite on his blog, which is worth learning. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fbluescreenofjeff.com\u002Ftags\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the methods for installing and configuring Apache mod_rewrite on Windows and Ubuntu systems, shares configuration tips and examples, and achieves HTTP traffic distribution based on request conditions from a technical research perspective.\u003C\u002Fp>\u003Cp>The next article will cover the implementation of HTTPS traffic distribution.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",878,"Onedaysec",5,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Apache mod_rewrite for HTTP Traffic Distribution - CIA Hive Replication","Apache mod_rewrite, HTTP traffic distribution, CIA Hive replication, .htaccess configuration, traffic redirection, cybersecurity, server setup",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],636,634,633,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.232Z","2026-07-23T16:01:52.510Z","draft","2026-07-23T16:13:54.717Z"]