11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Checklist: Securing Enterprise Services 711ImpersonationCheck DescriptionThe impersonation level is configured correctly. For ASP.NET clients, the impersonation levelis configured in Machine.config on the element.For Enterprise Services client applications, the level is configured in the COM+ catalog.Serviced component assemblies define the required impersonation level by using the<strong>Application</strong>AccessControl attribute as shown below:[assembly: <strong>Application</strong>AccessControl(ImpersonationLevel=ImpersonationLevelOption.Identify)]Administrator ChecklistCheck DescriptionLatest COM+ updates <strong>and</strong> patches are installed.Object constructor strings do not contain plain text secrets.COM+ administration components are restricted.Impersonation level that is set for the application is correct.Server applications are configured to run with a least-privileged account.Server applications do not run using the identity of the interactively logged on user.DTC service is disabled if it is not required.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!