11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

538 Part IV: Securing Your Network, Host <strong>and</strong> <strong>Application</strong>Perform <strong>Security</strong> AssessmentsUse MBSA to regularly check for security vulnerabilities <strong>and</strong> to identify missingpatches <strong>and</strong> updates. Schedule MBSA to run daily <strong>and</strong> analyze the results to takeaction as needed. For more information about automating MBSA, see “How To: UseMBSA” in the “How To” section of this guide.Use <strong>Security</strong> Notification ServicesUse the Microsoft services listed in Table 18.6 to obtain security bulletins withnotifications of possible system vulnerabilities.Table 18.6 <strong>Security</strong> Notification ServicesServiceLocationTechNet security <strong>Web</strong> site http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/current.aspUse this <strong>Web</strong> page to view the security bulletins that are available foryour system.Microsoft <strong>Security</strong>Notification Servicehttp://register.microsoft.com/subscription/subscribeme.asp?ID=135Use this service to register for regular email bulletins that notify you ofthe availability of new fixes <strong>and</strong> updatesAdditionally, subscribe to the industry security alert services shown in Table 18.7.This allows you to assess the threat of a vulnerability where a patch is not yetavailable.Table 18.7 Industry <strong>Security</strong> Notification ServicesServiceLocationCERT Advisory Mailing List http://www.cert.org/contact_cert/certmaillist.htmlInformative advisories are sent when vulnerabilities are reported.Windows <strong>and</strong> .NETMagazine <strong>Security</strong> UPDATENTBugtraqhttp://email.winnetmag.com/winnetmag/winnetmag_prefctr.aspAnnounces the latest security breaches <strong>and</strong> identifies fixes.http://www.ntbugtraq.com/default.asp?pid=31&sid=1#020This is an open discussion of Windows security vulnerabilities <strong>and</strong>attacks. Vulnerabilities which currently have no patch are discussed.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!