11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 18: Securing Your Database Server 537Perform Regular BackupsYou must be able to restore data in the event of a compromise. If you have a recoverysystem in place, test it before you actually need it. The first time you need to recoverdata should not be the first time you test your backup <strong>and</strong> restore process. For moreinformation on backing up <strong>and</strong> restoring SQL Server, see the following resources:● SQL Server 2000 documentation, “Backing Up <strong>and</strong> Restoring Databases”● “Backup <strong>and</strong> Restore Strategies with SQL Server 2000,” by Rudy Lee Martinez,http://www.dell.com/us/en/biz/topics/power_ps4q00-martin.htmAudit Group MembershipKeep track of user group membership, particularly for privileged groups such asAdministrators. The following comm<strong>and</strong> lists the members of the Administratorsgroup:net localgroup administratorsMonitor Audit LogsMonitor audit logs regularly <strong>and</strong> analyze the log files by manually viewing them oruse the technique described in Microsoft Knowledge Base article 296085, “How To:Use SQL Server to Analyze <strong>Web</strong> Logs.”Stay Current with Service Packs <strong>and</strong> PatchesSet up a schedule to analyze your server’s software <strong>and</strong> subscribe to security alerts.Use MBSA to regularly scan your server for missing patches. The following linksprovide the latest updates:● Windows 2000 service packs. The latest service packs are listed athttp://www.microsoft.com/windows2000/downloads/servicepacks/default.asp.●●Critical updates. These updates help to resolve known issues <strong>and</strong> help protectyour computer from known security vulnerabilities. For the latest critical updates,see http://www.microsoft.com/windows2000/downloads/critical/default.asp.Advanced security updates. Also monitor the advanced security updates athttp://www.microsoft.com/windows2000/downloads/security/default.asp.These also help protect your computer from known security vulnerabilities.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!