11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 16: Securing Your <strong>Web</strong> Server 435For more information on using MBSA, see “How To: Use Microsoft Baseline <strong>Security</strong>Analyzer” in the “How To” section of this guide.Update the .NET FrameworkAt the time of this writing (May 2003), MBSA cannot detect .NET Framework updates<strong>and</strong> patches. Therefore, you must manually detect .NET Framework updates. To manually update .NET Framework version 1.01. Determine which .NET Framework service pack is installed on your <strong>Web</strong> server.To do this, see Microsoft Knowledge Base article 318785, “INFO: DeterminingWhether Service Packs Are Installed on .NET Framework.”2. Compare the installed version of the .NET Framework to the current service pack.To do this, use the .NET Framework versions listed in Microsoft Knowledge Basearticle 318836, “INFO: How to Obtain the Latest .NET Framework Service Pack.”Step 2. IISLockdownThe IISLockdown tool helps you to automate certain security steps. IISLockdowngreatly reduces the vulnerability of a Windows 2000 <strong>Web</strong> server. It allows you to picka specific type of server role, <strong>and</strong> then use custom templates to improve security forthat particular server. The templates either disable or secure various features. Inaddition, IISLockdown installs the URLScan ISAPI filter. URLScan allows <strong>Web</strong> siteadministrators to restrict the kind of HTTP requests that the server can process, basedon a set of rules that the administrator controls. By blocking specific HTTP requests,the URLScan filter prevents potentially harmful requests from reaching the server<strong>and</strong> causing damage.During this step, you:● Install <strong>and</strong> run IISLockdown.●.Install <strong>and</strong> configure URLScan.Install <strong>and</strong> Run IISLockdownIISLockdown is available as an Internet download from the Microsoft <strong>Web</strong> site athttp://download.microsoft.com/download/iis50/Utility/2.1/NT45XP/EN-US/iislockd.exe.Save IISlockd.exe in a local folder. IISlockd.exe is the IISLockdown wizard <strong>and</strong> not aninstallation program. You can reverse any changes made by IISLockdown by runningIISlockd.exe a second time.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!