11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 19: Securing Your ASP.NET <strong>Application</strong> <strong>and</strong> <strong>Web</strong> Services 587Table 19.4 Snapshot of a Secure ASP.NET <strong>Application</strong> Configuration (continued)Component CharacteristicsRemotingRemoting is disabled on Internet-facing <strong>Web</strong> servers:. . .<strong>Web</strong> services<strong>Web</strong> services are disabled if they are not required:. . .Unnecessary protocols are disabled:. . .The documentation protocol is disabled to prevent the automatic generation ofWSDL:. . .Bin directoryThe bin directory is secured.(Read, Write, <strong>and</strong> Directory browsing permissions removed from bin. Executepermissions are set to None.)Authentication settings are removed from bin directory

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!