11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

746 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> Countermeasures●●●●Acquire. If the vulnerability is not addressed by the security measures already inplace, download the patch for testing.Test. Install the patch on a test system to verify the ramifications of the updateagainst your production configuration.Deploy. Deploy the patch to production computers. Make sure your applicationsare not affected. Employ your rollback or backup restore plan if needed.Maintain. Subscribe to notifications that alert you to vulnerabilities as they arereported. Begin the patch management process again.The Role of MBSA in Patch ManagementThe Microsoft Baseline <strong>Security</strong> Analyzer (MBSA) is a tool that is designed for twopurposes: first, to scan a computer against vulnerable configurations; <strong>and</strong> second,to detect the availability of security updates that are released by Microsoft.In this How To, you use MBSA without scanning for vulnerable configurations. Whenusing the graphical user interface (GUI), specify this by unchecking the options inFigure 1 <strong>and</strong> only choosing Check for security updates.Figure 1MBSA scan optionsWhen using the comm<strong>and</strong> line interface (Mbsacli.exe), you can use the followingcomm<strong>and</strong> to scan only missing security updates.Mbsacli.exe /n OS+IIS+SQL+PASSWORDThe option /n specifies the checks to skip. The selection (OS+IIS+SQL+PASSWORD)skips the checks for vulnerabilities <strong>and</strong> weak passwords.For more details about using MBSA, including the security configuration scan,see “How To: Use MBSA” in the How To section of this guide.Backups <strong>and</strong> Patch ManagementYou should perform backups prior to deploying an update on production servers.Regularly test backups as well as your backup process. Discovering that your backupprocess is broken during restoration can be devastating.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!