11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

652 Part V: Assessing Your <strong>Security</strong>IIS ConfigurationBy reviewing <strong>and</strong> improving the security of IIS configuration settings, you are ineffect reducing the attack surface of your <strong>Web</strong> server. For more information about thereview points covered in this section, see Chapter 16, “Securing Your <strong>Web</strong> Server.”The review questions in this section have been organized by the followingconfiguration categories.● IISLockdown● URLScan● Sites <strong>and</strong> virtual directories● ISAPI filters● IIS Metabase● Server certificatesIISLockdownThe IISLockdown tool identifies <strong>and</strong> turns off features to reduce the IIS attack surfacearea. To see if it has been run on your server, check for the following report generatedby IISLockdown:\WINNT\system32\inetsrv\oblt-rep.logFor more information about IISLockdown, see “How To: Use IISLockdown” in the“How To” section of this guide.URLScanURLScan is an ISAPI filter that is installed with IISLockdown. It helps preventpotentially harmful requests from reaching the server <strong>and</strong> causing damage. Checkthat it is installed <strong>and</strong> that it is configured appropriately. To see if URLScan is installed1. Start Internet Information Services.2. Right-click your server (not <strong>Web</strong> site) <strong>and</strong> then click Properties.3. Click the Edit button next to Master Properties.4. Click the ISAPI Filters tab <strong>and</strong> see if URLScan is listed.To check the URLScan configuration, use Notepad to edit the following URLScanconfiguration file.%WINDIR%\System32\Inetsrv\URLscan\Urlscan.ini

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!