11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 18: Securing Your Database Server 511Steps for Securing Your Database ServerThis section guides you through the process of securing your database server usingthe configuration categories introduced earlier. The steps cover Windows 2000 <strong>and</strong>SQL Server 2000. Each step may contain one or more actions to secure a particulararea or feature.Step 1Patches <strong>and</strong> UpdatesStep 7PortsStep 2ServicesStep 8RegistryStep 3ProtocolsStep 9Auditing <strong>and</strong> LoggingStep 4AccountsStep 10SQL Server <strong>Security</strong>Step 5Files <strong>and</strong> DirectoriesStep 11SQL Server Logins, Users, <strong>and</strong> RolesStep 6SharesStep 12SQL Server Database ObjectsStep 1. Patches <strong>and</strong> UpdatesFailure to apply the latest patches <strong>and</strong> updates in a timely manner means that you areproviding opportunities for attackers to exploit known vulnerabilities. You shouldverify that your database server is updated with the latest Windows 2000 <strong>and</strong> SQLServer service packs <strong>and</strong> updates.Important Make sure to test patches <strong>and</strong> updates on test systems that mirror your productionservers as closely as possible before applying them on production servers.Detect Missing Service Packs <strong>and</strong> UpdatesUse the Microsoft Baseline <strong>Security</strong> Analyzer (MBSA) to detect the necessaryWindows <strong>and</strong> SQL Server updates that may be missing. MBSA uses an XML file asthe reference of existing updates. This XML file is either downloaded by MBSA whena scan runs, or the file can be downloaded on the local server or from a networkserver. To detect <strong>and</strong> install patches <strong>and</strong> updates1. Download <strong>and</strong> install MBSA.You can do this from the MBSA home page at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/Tools/mbsahome.asp.If you do not have Internet access when you run MBSA, it will not be able toretrieve the XML file containing the latest security settings from Microsoft. In thisevent, download the XML file manually <strong>and</strong> put it in the MBSA program directory.The XML file is available from http://download.microsoft.com/download/xml/security/1.0/nt5/en-us/mssecure.cab.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!