11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

534 Part IV: Securing Your Network, Host <strong>and</strong> <strong>Application</strong>Table 18.5 Snapshot of a Secure Database Server (continued)Component CharacteristicsAccountsSQL Server service account is secured (least privileged).Unnecessary Windows accounts are deleted or disabled.The Windows guest account is disabled.A new administrator account is created.Strong password policy is enforced.Remote logons are restricted.Null sessions (anonymous logons) are disabled.Approval is required for account delegation.Shared accounts are not used.Membership of the local Administrators group is limited (ideally, no more thantwo members).The administrator account is limited to interactive logins (or a secure remoteadministration solution is provided).NTLMv2 authentication is enabled <strong>and</strong> enforced (LMCompatibilityLevel is setto 5).Files <strong>and</strong> DirectoriesVolumes are formatted with NTFS.Everyone group has no rights to system or tools directories.Samples directories, Help directories, <strong>and</strong> unused admin directories areremoved from the server.Permissions are hardened on SQL Server installation folder.Passwords removed from Service Pack 1 <strong>and</strong> Service Pack 2 setup log files.Tools, utilities <strong>and</strong> SDKs are removed.Unused applications are removed.Sensitive data files are encrypted using EFS. (This is optional for databasefiles (.mdf), but not for log files (.ldf)).SharesUnnecessary shares are removed from the server.Access is restricted to required shares.Shares are not accessible by Everyone, unless necessary.Administration shares (C$, Admin$) are removed if they are not required.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!