11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 16: Securing Your <strong>Web</strong> Server 465Remove All Permissions for the Local Intranet ZoneThe local intranet zone applies permissions to code running from UNC shares orinternal <strong>Web</strong> sites. Reconfigure this zone to grant no permissions by associating itwith the Nothing permission set. To remove all permissions for the local intranet zone1. Start the Microsoft .NET Framework version 1.1 Configuration tool from theAdministrative Tools program group.2. Exp<strong>and</strong> Runtime <strong>Security</strong> Policy, exp<strong>and</strong> Machine, <strong>and</strong> then exp<strong>and</strong> CodeGroups.3. Exp<strong>and</strong> All_Code <strong>and</strong> then select LocalIntranet_Zone.4. Click Edit Code Group Properties.5. Click the Permission Set tab.6. Select Nothing from the drop-down Permission list.7. Click OK.The dialog box shown in Figure 16.6 is displayed.Figure 16.6Setting LocalIntranet_Zone code permissions to NothingRemove All Permissions for the Internet ZoneThe Internet zone applies code access permissions to code downloaded over theInternet. On <strong>Web</strong> servers, this zone should be reconfigured to grant no permissionsby associating it with the Nothing permission set.Repeat the steps shown in the preceding section, “Remove All Permissions for theLocal Intranet Zone,” except set the Internet_Zone to the Nothing permission set.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!