11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 16: Securing Your <strong>Web</strong> Server 455Securing RDSIf your applications require RDS, secure it. To secure RDS1. Delete the samples at the following location:\Progam Files\Common Files\System\Msadc\Samples2. Remove the following registry key:HKLM\System\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\VbBusObj.VbBusObjCls3. Disable Anonymous access for the MSADC virtual directory in IIS.4. Create a H<strong>and</strong>lerRequired registry key in the following location:HKLM\Software\Microsoft\DataFactory\H<strong>and</strong>lerInfo\5. Create a new DWORD value, <strong>and</strong> set it to 1 (1 indicates safe mode, while 0indicates unsafe mode.Note You can use the registry script file H<strong>and</strong>safe.reg to change the registry key. The script file islocated in the msadc directory: \Program Files\Common Files\System\msadcFor more information about securing RDS, see the following:●●MS99-025 Microsoft <strong>Security</strong> Program: Unauthorized Access to IIS Servers throughODBC Data Access with RDS at http://www.microsoft.com/technet/security/bulletin/ms99-025.asp.MS98-004 Microsoft <strong>Security</strong> Program: Microsoft <strong>Security</strong> Bulletin: UnauthorizedODBC Data Access with RDS <strong>and</strong> IIS at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS98-004.asp.● Microsoft Knowledge Base article 184375, “PRB: <strong>Security</strong> Implications of RDS 1.5,IIS 3.0 or 4.0, <strong>and</strong> ODBC.”Set <strong>Web</strong> Permissions<strong>Web</strong> permissions are configured through the IIS snap-in <strong>and</strong> are maintained in the IISmetabase. They are not NTFS permissions.Use the following <strong>Web</strong> permissions:● Read Permissions. Restrict Read permissions on include directories.● Write <strong>and</strong> Execute Permissions. Restrict Write <strong>and</strong> Execute permissions on virtualdirectories that allow anonymous access.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!