11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

750 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresThe top portion of the MBSA screenshot shown in Figure 2 is self explanatory.Red crosses indicate that a critical issue has been found. To view the list of missingpatches, click the associated Result details link.The results of a security update scan might show two types of issues:●●Missing patchesPatch cannot be confirmedBoth types include links to the relevant Hotfix <strong>and</strong> security bulletin pages thatprovide details about the patch together with download instructions.Missing patches are indicated by a red cross. An example is shown in Figure 3.Figure 3Missing patch indicationWhen a patch cannot be confirmed, it is indicated by a blue asterisk. This occurswhen your system has a file that is newer than the file provided with a securitybulletin. This might occur if you install a new version of a product that updatesa common file.Figure 4Patch cannot be confirmed indicationFor updates that cannot be confirmed, review the information in the bulletin <strong>and</strong>follow the instructions. This may include installing a patch or making configurationchanges. For more information on patches that cannot be verified by MBSA, seeMicrosoft Knowledge Base article, 306460, “HFNetChk Returns Note Messages forInstalled Patches.”

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!