11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

474 Part IV: Securing Your Network, Host, <strong>and</strong> <strong>Application</strong>SummaryA secure <strong>Web</strong> server provides a protected foundation for hosting your <strong>Web</strong>applications. This chapter has shown you the main threats that have the potentialto impact your ASP.NET <strong>Web</strong> server <strong>and</strong> has provided the security steps requiredfor risk mitigation. By performing the hardening steps presented in this chapter,you can create a secure platform <strong>and</strong> host infrastructure to support ASP.NET <strong>Web</strong>applications <strong>and</strong> <strong>Web</strong> services.The methodology used in this chapter allows you to build a secure <strong>Web</strong> server fromscratch <strong>and</strong> also allows you to harden the security configuration of an existing <strong>Web</strong>server. The next step is to ensure that any deployed applications are correctlyconfigured.Additional ResourcesFor additional related reading, see the following resources:● For information about securing your developer workstation, see “How To: SecureYour Developer Workstation” in the “How To” section of this guide.● For more information about how to secure ASP.NET <strong>Web</strong> applications <strong>and</strong> <strong>Web</strong>services, see Chapter 19, “Securing Your ASP.NET <strong>Application</strong>.”● For information on how the Open Hack application was configured, see theMSDN article, “Building <strong>and</strong> Configuring More Secure <strong>Web</strong> Sites,” athttp://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnnetsec/html/openhack.asp.●●For security-related resources on TechNet, see the TechNet <strong>Security</strong> page,http://www.microsoft.com/technet/security/default.asp.For a printable checklist, see “Checklist: Securing Your <strong>Web</strong> Server” in the“Checklists” section of this guide.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!