11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

488 Part IV: Securing Your Network, Host, <strong>and</strong> <strong>Application</strong>What Does the Operating System Install?The following table shows the core Component Services elements that are installedwith a st<strong>and</strong>ard operating system installation.Table 17.1 Enterprise Services ComponentsItemAdministrationDetailsComponent Services ExplorerThis provides configurable administration of COM+ applications, <strong>and</strong> islocated at \WINNT\system32\Com\comexp.msc.COM+ CatalogThe COM+ Catalog maintains configuration information for each COM+application.System <strong>Application</strong>(a COM+ serverapplication)ServicesSystem <strong>Application</strong>This application manages the configuration <strong>and</strong> tracking of COM+components. It can be viewed from the Component Services MicrosoftManagement Console (MMC). It has two associated roles: Administrator<strong>and</strong> Reader. By default, the administrators are part of the Administratorrole, which can modify the COM+ Catalog, while Everyone is part of theReader role, which can read only COM+ Catalog values.COM+ Event SystemThis service is required to support the COM+ loosely coupled event (LCE)system. The LCE system is used by operating system services such as theSystem Event Notification Services (SENS) service <strong>and</strong> optionally by yourapplications.Distributed Transaction Coordinator (DTC)This service is required if your Enterprise Services solution uses COM+automatic transactions.AccountsLog FilesEnterprise Services do not create any accounts. Library applications run asthe identity of the process they run in. Server applications can beconfigured to run as the interactive user or a specific user. (You canconfigure the user account on the Identity tab of the COM+ application’sProperties dialog box in Component Services).DTC log file: %windir%\system32\DTCLogCRM log file: %windir%\registrationRegistry KeysHKEY_CLASSES_ROOT\CLSIDHKEY_CLASSES_ROOT\AppID

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!