11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

470 Part IV: Securing Your Network, Host, <strong>and</strong> <strong>Application</strong>Stay Current With Service Packs <strong>and</strong> PatchesSet up a schedule to analyze your server software <strong>and</strong> subscribe to security alerts.Use MBSA to regularly scan your server for missing patches. The following linksprovide the latest updates:● Windows 2000 service packs. The latest service packs are listed athttp://www.microsoft.com/windows2000/downloads/servicepacks/default.asp.●●●.NET Framework Service Pack. For information about how to obtain the latest.NET Framework updates, see the MSDN article, “How to Get the Microsoft .NETFramework” at http://msdn.microsoft.com/netframework/downloads/howtoget.asp.Critical Updates. These updates help to resolve known issues <strong>and</strong> help protectyour computer from known security vulnerabilities. For the latest critical updates,see “Critical Updates” at http://www.microsoft.com/windows2000/downloads/critical/default.aspAdvanced <strong>Security</strong> Updates. For additional security updates, see “Advanced<strong>Security</strong> Updates” at http://www.microsoft.com/windows2000/downloads/security/default.asp.These also help protect your computer from known security vulnerabilities.Perform <strong>Security</strong> AssessmentsUse MBSA to regularly check for security vulnerabilities <strong>and</strong> to identify missingpatches <strong>and</strong> updates. Schedule MBSA to run daily <strong>and</strong> analyze the results to takeaction as needed. For more information about automating MBSA, see “How To:Use MBSA” in the “How To” section of this guide.Use <strong>Security</strong> Notification ServicesUse the Microsoft services listed in Table 16.5 to obtain security bulletins withnotifications of possible system vulnerabilities.Table 16.5 <strong>Security</strong> Notification ServicesServiceLocationTechNet <strong>Security</strong><strong>Web</strong> sitehttp://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/current.aspUse this <strong>Web</strong> page to view the security bulletins that are available for yoursystem.Microsoft <strong>Security</strong>Notification Servicehttp://register.microsoft.com/subscription/subscribeme.asp?ID=135Use this service to register for regular email bulletins that notify you of theavailability of new fixes <strong>and</strong> updates.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!