11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

700 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresConfiguration File Settings (continued)Check DescriptionCustom error pages are returned to the client <strong>and</strong> detailed exception details are preventedfrom being returned by setting mode=“On”.A generic error page is specified by the defaultRedirect attribute.The authentication mode is appropriately configured to support application requirements. Toenforce the use of a specific authentication type, a element withallowOverride=“false” is used.The <strong>Web</strong> site is partitioned for public <strong>and</strong> restricted access.The Forms authentication configuration is secure:The authentication cookie is encrypted <strong>and</strong> integrity checked (protection).SSL is required for authentication cookie (requireSSL).Sliding expiration is set to false if SSL is not used (slidingExpiration).The session lifetime is restricted (timeout).Cookie names <strong>and</strong> paths are unique (name <strong>and</strong> path).The element is not used.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!