11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

454 Part IV: Securing Your Network, Host, <strong>and</strong> <strong>Application</strong> To disable parent paths1. Start IIS.2. Right-click the root of your <strong>Web</strong> site, <strong>and</strong> click Properties.3. Click the Home Directory tab.4. Click Configuration.5. Click the App Options tab.6. Clear Enable parent paths.Note If you use the <strong>Application</strong> Center 2002 Administration Site, see Microsoft Knowledge Basearticle 288309, “PRB: Disabling Parent Paths Breaks User Interface.”Remove Potentially Dangerous Virtual DirectoriesSample applications are not installed by default <strong>and</strong> should not be installed onproduction <strong>Web</strong> servers. Remove all sample applications, including the ones that canbe accessed only from the local computer with http://localhost, or http://127.0.0.1.Remove the following virtual directories from production servers: IISSamples,IISAdmin, IISHelp, <strong>and</strong> Scripts.Note IISLockdown provides an option to remove the Scripts, IISSamples, IISAdmin, <strong>and</strong> IISHelpvirtual directories.Remove or Secure RDSRemote Data Services (RDS) is a component that enables controlled Internet accessto remote data resources through IIS. The RDS interface is provided by Msadcs.dll,which is located in the following directory: program files\common files\system\Msadc.Removing RDSIf your applications do not use RDS, remove it. To remove RDS support1. Remove the /MSADC virtual directory mapping from IIS.2. Remove the RDS files <strong>and</strong> subdirectories at the following location:\Program Files\Common Files\System\Msadc3. Remove the following registry key:HKLM\System\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunchNote IISLockdown provides an option to remove the MSADC virtual directory. Note thatIISLockdown only removes the virtual directory, not the files or registry key.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!