11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

512 Part IV: Securing Your Network, Host <strong>and</strong> <strong>Application</strong>2. Run MBSA by double-clicking the desktop icon or selecting it from the Programsmenu.3. Click Scan a computer. MBSA defaults to the local computer.4. Clear all check boxes apart from Check for security updates. This option detectswhich patches <strong>and</strong> updates are missing.5. Click Start scan. Your server is now analyzed. When the scan is complete, MBSAdisplays a security report, which it also writes to the %userprofile%\<strong>Security</strong>Scansdirectory.6. Download <strong>and</strong> install the missing updates.Click the Result details link next to each failed check to view the list of securityupdates that are missing. The resulting dialog box displays the Microsoft securitybulletin reference number. Click the reference to find out more about the bulletin<strong>and</strong> to download the update.For more information about using MBSA, see “How To: Use the Microsoft Baseline<strong>Security</strong> Analyzer” in the “How To” section of this guide.For more information about applying service packs, hot fixes, <strong>and</strong> security patches,see http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bestprac/bpsp.asp.Patching MSDEThe Microsoft Desktop Edition (MSDE) of SQL Server must be patched differentlythan the full version of SQL Server. For details about patching MSDE, see “How To:Secure Your Developer Workstation” in the “How To” section of this guide.Step 2. ServicesTo reduce the attack surface area <strong>and</strong> to make sure you are not affected byundiscovered service vulnerabilities, disable any service that is not required. Runthose services that remain using least privileged accounts.In this step, you:● Disable unused SQL Server services.●Disable the Microsoft DTC (if not required).Note To disable a service, set its startup type to Disabled using the Services MMC snap-in in theComputer Management tool.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!