11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 22: Deployment Review 655Parent Path SettingCheck that you have disabled the parent path setting to prevent the use of “..”in script <strong>and</strong> application calls to functions such as MapPath. This helps preventdirectory traversal attacks. To review the parent paths setting1. Start Internet Services Manager.2. Right-click your <strong>Web</strong> site, <strong>and</strong> click Properties.3. Click the Home Directory tab.4. Click Configuration.5. Click the App Options tab.6. Check that the Enable parent paths check box is clear.FrontPage Server Extensions (FPSE)FrontPage Server Extensions are used for accessing, authoring, <strong>and</strong> administeringthe FrontPage-based <strong>Web</strong> site. Use the latest versions of these extensions to avoidsecurity vulnerabilities. If you do not use FPSE, disable them to reduce the attacksurface.For more information, see “Step 11. Sites <strong>and</strong> Virtual Directories” in Chapter 16,“Securing Your <strong>Web</strong> Server.”ISAPI FiltersMake sure that no unused ISAPI filters are installed to prevent any potentialvulnerabilities in these filters from being exploited. To review ISAPI filters1. Start Internet Information Manager.2. Right click your server (not <strong>Web</strong> site) <strong>and</strong> then click Properties.3. Click the Edit button next to Master Properties.4. Click the ISAPI Filters tab to view the installed filters.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!