11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 16: Securing Your <strong>Web</strong> Server 433Including Service Packs with a Base InstallationIf you need to build multiple servers, you can incorporate service packs directly intoyour Windows installations. Service packs include a program called Update.exe tocombine a service pack with your Windows installation files. To combine a service pack with a Windows installation1. Download the latest service pack.2. Extract Update.exe from the service pack by launching the service pack setup withthe -x option, as follows:w3ksp3.exe -x3. Integrate the service pack with your Windows installation source, by runningupdate.exe with the -s option, passing the folder path of your Windowsinstallation as follows:update.exe -s c:\YourWindowsInstallationSourceFor more information, see the MSDN article, “Customizing Unattended Win2KInstallations” at http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnw2kmag01/html/custominstall.asp.Steps for Securing Your <strong>Web</strong> ServerThe next sections guide you through the process of securing your <strong>Web</strong> server. Thesesections use the configuration categories introduced in the “Methodology forSecuring Your <strong>Web</strong> Server” section of this chapter. Each high-level step contains oneor more actions to secure a particular area or feature.Step 1Patches <strong>and</strong> UpdatesStep 10Auditing <strong>and</strong> LoggingStep 2IISLockdownStep 11Sites <strong>and</strong> Virtual DirectoriesStep 3ServicesStep 12Script MappingsStep 4ProtocolsStep 13ISAPI FiltersStep 5AccountsStep 14IIS MetabaseStep 6Files <strong>and</strong> DirectoriesStep 15Server CertificatesStep 7SharesStep 16Machine.configStep 8PortsStep 17Code Access <strong>Security</strong>Step 9Registry

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!