11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 22: Deployment Review 651RegistryReview the security of your registry configuration with the following questions:●Have you restricted remote registry administration?Use Regedt32.exe to review the ACL on the WinReg registry key, which controlswhether or not the registry can be remotely accessed.HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winregBy default in Windows 2000, remote registry access is restricted to members ofthe Administrators <strong>and</strong> Backup operators group. For maximum security, restrictall remote access to the registry by using an empty Discretionary Access ControlList (DACL).Note Some services require remote access to the registry. See Microsoft Knowledge Basearticle 153183, “How to Restrict Access to the Registry from a Remote Computer,” to see if yourscenario dem<strong>and</strong>s limited remote registry access.●Have you secured the SAM?This only applies to st<strong>and</strong>-alone servers. Check that you have restricted LMHashstorage in the <strong>Security</strong> Account Manager (SAM) database by creating the key(not value) NoLMHash in the registry as follows:HKLM\System\CurrentControlSet\Control\LSA\NoLMHashAuditing <strong>and</strong> LoggingReview your use of Windows auditing with the following questions.● Do you log all failed logon attempts?Use the Local <strong>Security</strong> Policy tool to check that you have enabled the auditing offailed logon attempts.● Do you log all failed actions across the file system?Use the Local <strong>Security</strong> Policy tool to check that you have enabled object accessauditing. Then check that auditing has been enabled across the file system.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!