11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 17: Securing Your <strong>Application</strong> Server 499SummaryWhen sufficient perimeter network defenses are in place, many of the threats thataffect middle-tier application servers come from inside of an organization. A secureinfrastructure that consists of IPSec policies that restrict access to the applicationserver from selected <strong>Web</strong> servers only, <strong>and</strong> also provide secure communicationchannels, is an effective risk mitigation strategy.This chapter has shown you additional security measures. These measures differdepending on the technology used on the application server.Internal firewalls on either side of the application server present other issues. Theports that must be open depend on application implementation choices, such astransport protocols <strong>and</strong> the use of distributed transactions.For a checklist that summarizes the steps in this chapter, see “Checklist: SecuringYour <strong>Application</strong> Server” in the “Checklists” section of this guide.Additional ResourcesFor more information about the issues addressed in this chapter, see the followingarticles in the Microsoft Knowledge Base at http://support.microsoft.com:●●●●●●Article 233256, “How to: Enable IPSec Traffic Through a Firewall”Article 312960, “Cannot Set Fixed Endpoint for a COM+ <strong>Application</strong>”Article 259011, “SAMPLE: A Simple DCOM Client Server Test <strong>Application</strong>”Article 248809, “PRB: DCOM Does Not Work over NAT-Based Firewall”Article 250367, “INFO: Configuring Microsoft Distributed Transaction Coordinator(DTC) to Work Through a Firewall”Article 154596, “How To: Configure RPC Dynamic Port Allocation to Work with aFirewall”

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!