11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

492 Part IV: Securing Your Network, Host, <strong>and</strong> <strong>Application</strong> To configure a static endpoint for DCOM1. Obtain the application ID for your Enterprise Services application from the COM+catalog. To do this:a. Start the Component Services tool.b. Display the Properties dialog box of the application, <strong>and</strong> retrieve theapplication ID from the General page.2. Start the registry editor (Regedt32.exe).3. Select the following registry key:HKEY_CLASSES_ROOT\AppID4. From the Edit menu, click Add Value, <strong>and</strong> then add the following registry value,where {your AppID} is the <strong>Application</strong> ID of the COM+ application that youobtained in step 1:Key name: {Your AppID}Value name: EndpointsData type: REG_MULTI_SZValue data: ncacn_ip_tcp,0,The port number that you specify in the Value data text box must be greater than1024 <strong>and</strong> must not conflict with well-known ports that other applications on thecomputer use. You cannot modify the ncacn_ip_tcp,0 portion of this key.5. Close the registry editor.COM+ CatalogEnterprise Services application configuration settings are maintained in the COM+catalog. The majority of configuration items are contained in the registration database(RegDB), which consists of files located in the following directory:%windir%\registrationBy default, the Everyone group has permission to read the database. Modify theaccess control list (ACL) for this directory to restrict read/write access toadministrators <strong>and</strong> the local system account. Also grant read access to the accountsused to run Enterprise Services applications. Here is the required ACL:Administrators: Read, WriteSystem: Read, WriteEnterprise Services Run-As Account(s): Read

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!