11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 17: Securing Your <strong>Application</strong> Server 477<strong>Threats</strong> <strong>and</strong> CountermeasuresMany threats to an application server come from within an organization becauseapplication servers should be isolated from Internet access. The main threats to anapplication server are:● Network eavesdropping● Unauthorized access● Viruses, Trojan horses, <strong>and</strong> wormsFigure 17.2 shows the main threats to an application server.PerimeterFirewallViruses,Trojanhorses,<strong>and</strong> Worms<strong>Web</strong> ServerNetworkEavesdropping<strong>Application</strong>ServerNetworkEavesdroppingSQLServerUnauthorizedAccessUnauthorizedAccessFigure 17.2Top application server related threats <strong>and</strong> vulnerabilitiesNetwork EavesdroppingAttackers with network monitoring software can intercept data flowing from the <strong>Web</strong>server to the application server <strong>and</strong> from the application server to downstreamsystems <strong>and</strong> database servers. The attacker can view <strong>and</strong> potentially modify thisdata.VulnerabilitiesVulnerabilities that can make your application server vulnerable to networkeavesdropping include:● Sensitive data transmitted in clear text by the application● Use of Microsoft SQL Server authentication to the database, resulting in clear textcredentials

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!