11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

730 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresServicesCheck DescriptionUnnecessary Microsoft Windows ® services are disabled on the database server.All optional services, including Microsoft Search Service, MSSQLServerADHelper, <strong>and</strong>SQLServerAgent, are disabled if not used by any applications.The Microsoft Distributed Transaction Coordinator (MS DTC) is disabled if it is not beingused by any applications.A least-privileged local/domain account is used to run the various SQL Server services,for example, back up <strong>and</strong> replication.ProtocolsCheck DescriptionAll protocols except TCP/IP are disabled within SQL Server. Check this using the ServerNetwork Utility.The TCP/IP stack is hardened on the database server.AccountsCheck DescriptionSQL Server is running using a least-privileged local account (or optionally, a least-privilegeddomain account if network services are required).Unused accounts are removed from Windows <strong>and</strong> SQL Server.The Windows guest account is disabled.The administrator account is renamed <strong>and</strong> has a strong password.Strong password policy is enforced.Remote logons are restricted.Null sessions (anonymous logons) are restricted.Approval is required for account delegation.Shared accounts are not used.Membership of the local administrators group is restricted (ideally, no more than twoadministration accounts).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!