11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Checklist:Securing Your <strong>Web</strong> ServerHow to Use This ChecklistThis checklist is a companion to Chapter 16, “Securing Your <strong>Web</strong> Server.” Use it tohelp implement a secure <strong>Web</strong> server, or as a quick evaluation snapshot of thecorresponding chapter.This checklist should evolve with steps that you discover to secure your <strong>Web</strong> server.Patches <strong>and</strong> UpdatesCheck DescriptionMBSA is run on a regular interval to check for latest operating system <strong>and</strong> componentsupdates. For more information, see http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/Tools/mbsahome.asp.The latest updates <strong>and</strong> patches are applied for Windows, IIS server, <strong>and</strong> the .NETFramework. (These are tested on development servers prior to deployment on the productionservers.)Subscribe to the Microsoft <strong>Security</strong> Notification Service at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/notify.asp.IISLockdownCheck DescriptionIISLockdown has been run on the server.URLScan is installed <strong>and</strong> configured.ServicesCheck DescriptionUnnecessary Windows services are disabled.Services are running with least-privileged accounts.FTP, SMTP, <strong>and</strong> NNTP services are disabled if they are not required.Telnet service is disabled.ASP .NET state service is disabled <strong>and</strong> is not used by your applications.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!