11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

748 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresDetectingUse MBSA to detect missing security patches for Windows NT 4.0, Windows 2000,<strong>and</strong> Windows XP. You can use MBSA in two modes; GUI <strong>and</strong> comm<strong>and</strong> line. Bothmodes are used to scan single or multiple computers. The comm<strong>and</strong> line can bescripted to run on a schedule.Note The login used to run MBSA must be a member of the Administrators group on the targetcomputer(s). To verify adequate access <strong>and</strong> privilege, use the comm<strong>and</strong> net use\\computername\c$ where computername is the network name of a machine which you are goingto scan for missing patches. Resolve any issues accessing the administrative share before usingMBSA to scan the remote computer. To manually detect missing updates using the MBSA graphical interface1. Run MBSA by double-clicking the desktop icon or by selecting it from thePrograms menu.2. Click Scan a computer. MBSA defaults to the local computer. To scan multiplecomputers, select Scan more than one computer <strong>and</strong> select either a range ofcomputers to scan or an IP address range.3. Clear all check boxes except Check for security updates. This option detectsuninstalled patches <strong>and</strong> updates.4. Click Start scan. Your server is now analyzed. When the scan is complete,MBSA displays a security report <strong>and</strong> also writes the report to the%userprofile%\<strong>Security</strong>Scans directory.5. Download <strong>and</strong> install the missing updates.Click the Result details link next to each failed check to view the list of uninstalledsecurity updates. A dialog box displays the Microsoft security bulletin referencenumber. Click the reference to find out more about the bulletin <strong>and</strong> to downloadthe update. To detect missing updates using the MBSA comm<strong>and</strong> line interface●From a comm<strong>and</strong> window, change directory to the MBSA installation directory,<strong>and</strong> type the following comm<strong>and</strong>:mbsacli /i 127.0.0.1 /n OS+IIS+SQL+PASSWORDYou can also specify a computer name. For example:mbsacli /c domain\machinename /n OS+IIS+SQL+PASSWORD

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!