11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

728 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresOther Check PointsCheck DescriptionIISLockdown tool has been run on the server.HTTP requests are filtered. URLScan is installed <strong>and</strong> configured.Remote administration of the server is secured <strong>and</strong> configured for encryption, low sessiontime-outs, <strong>and</strong> account lockouts.Dos <strong>and</strong> Don’ts●●●●●●Do use a dedicated machine as a <strong>Web</strong> server.Do physically protect the <strong>Web</strong> server machine in a secure machine room.Do configure a separate anonymous user account for each application, if you hostmultiple <strong>Web</strong> applications,Do not install the IIS server on a domain controller.Do not connect an IIS Server to the Internet until it is fully hardened.Do not allow anyone to locally log on to the machine except for the administrator.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!