11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

688 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresSecuring ChecklistsEach checklist in the securing series covers aspects of securing the servers based onroles. The checklists cover the following: patches <strong>and</strong> updates, services, protocols,accounts, files <strong>and</strong> directories, shares, ports, registry, <strong>and</strong> auditing <strong>and</strong> logging. Thesechecklists are:● Checklist: Securing <strong>Web</strong> Server. In addition to the common checklist informationcited previously, this checklist covers the following points that are specific to a<strong>Web</strong> server: sites <strong>and</strong> virtual directories, script mappings, ISAPI filters, metabase,Machine.config, <strong>and</strong> code access security.● Checklist: Securing Database Server. In addition to the common checklistinformation cited previously, this checklist covers following points that are specificto a database server: SQL Server security; <strong>and</strong> SQL Server logins, users, <strong>and</strong> roles.Assessing ChecklistChecklist: <strong>Security</strong> Review for Managed Code helps you to uncover securityvulnerabilities in your managed code. This checklist covers the following:assembly-level checks, class-level checks, cryptography, secrets, exceptionmanagement, delegates, serialization, threading, reflection, unmanaged codeaccess, file I/O, event log, registry, environment variables <strong>and</strong> code access securityconsiderations.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!