11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

490 Part IV: Securing Your Network, Host, <strong>and</strong> <strong>Application</strong>Updates to the COM+ runtime are sometimes released as QFE releases. Use thefollowing resources to help manage patches <strong>and</strong> updates:● Windows updates <strong>and</strong> patchesUse the Microsoft Baseline <strong>Security</strong> Analyzer (MBSA) to detect missing securityupdates on application servers. For more information about how to use the MBSAon a single computer <strong>and</strong> to keep a group of servers up-to-date, see “How to: UseMBSA” in the “How To” section of this guide.For information about environments that require many servers to be updated froma centralized administration point, see “How To: Patch Management” in the “HowTo” section of this guide.● .NET Framework updates <strong>and</strong> patchesAt the time of this writing (May 2003), MBSA does not have the ability to detect the.NET Framework. Therefore, you must update the .NET Framework manually. To manually update the .NET Framework1. Determine which .NET Framework service pack is installed on your <strong>Web</strong> server.To do this, see Microsoft Knowledge Base article 318785, “INFO: DeterminingWhether Service Packs Are Installed on .NET Framework.”2. Compare the installed version of the .NET Framework to the current service pack.To do this, use the .NET Framework versions listed in Microsoft Knowledge Basearticle 318836, “INFO: How to Obtain the Latest .NET Framework Service Pack.”● COM+ updates <strong>and</strong> patchesThe latest Windows service packs include the current fixes to COM+. However,updates to the COM+ runtime are sometimes released in the form of QFE releases.An automatic notification service for COM+ updates does not currently exist, somonitor the Microsoft Knowledge Base at http://support.microsoft.com. Use“kbQFE” as a search keyword to refine your search results.ServicesTo reduce the attack surface profile, disable any services that are not required.Required services include the Microsoft DTC <strong>and</strong> the COM+ Event System service,which is required to support the LCE COM+ feature.To secure the services on your application server, disable the MS DTC if it is notrequired.Disable the Microsoft DTC If It Is Not RequiredThe DTC service is tightly integrated with COM+. It coordinates transactions that aredistributed across two or more databases, message queues, file systems, or otherresource managers. If your applications do not use the COM+ automated transactionservices, then the DTC should be disabled by using the Services MMC snap-in.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!