11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Checklist: Securing Your <strong>Web</strong> Server 727ISAPI FiltersCheck DescriptionUnnecessary or unused ISAPI filters are removed from the server.IIS MetabaseCheck DescriptionAccess to the metabase is restricted by using NTFS permissions(%systemroot%\system32\inetsrv\metabase.bin).IIS banner information is restricted (IP address in content location disabled).Server CertificatesCheck DescriptionCertificate date ranges are valid.Certificates are used for their intended purpose (for example, the server certificate is notused for e-mail).The certificate’s public key is valid, all the way to a trusted root authority.The certificate has not been revoked.Machine.configCheck DescriptionProtected resources are mapped to HttpForbiddenH<strong>and</strong>ler.Unused HttpModules are removed.Tracing is disabled Debug compiles are turned off.Code Access <strong>Security</strong>Check DescriptionCode access security is enabled on the server.All permissions have been removed from the local intranet zone.All permissions have been removed from the Internet zone.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!