11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

How To: Implement Patch Management 751AssessingWith the list of missing patches identified by MBSA, you must determine if thevulnerabilities pose a significant risk. Microsoft <strong>Security</strong> Bulletins provide technicaldetails to help you determine the level of threat the vulnerability poses to yoursystems.The details from security bulletins that help you assess the risk of attack are:●●●Technical details of requirements an attacker needs to exploit the vulnerabilityaddressed by the bulletin. For example, an attack may require physical access orthe user must open a malicious email attachment.Mitigating factors that you need to compare against your security policy todetermine your level of exposure to the vulnerability. It may be that yoursecurity policy mitigates the need to apply a patch. For example, if you do nothave the Indexing Service running on your server, you do not need to installpatches to address vulnerabilities in the service.Severity rating that assists in determining priority. The severity rating is basedon multiple factors including the role of the machines that may be vulnerable, <strong>and</strong>the level of exposure to the vulnerability.For more information about the severity rating system used by the securitybulletins, see the TechNet article, “Microsoft <strong>Security</strong> Response Center <strong>Security</strong>Bulletin Severity Rating System” at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/policy/rating.aspNote If you use an affected product, you should almost always apply patches that addressvulnerabilities rated critical or important. Patches rated critical should be applied as soon aspossible.AcquiringThere are several ways you can obtain patches, including:● Using MBSA report details. MBSA links to the security bulletin that contains thepatch, or instructions about obtaining the patch. You can use the link to downloadthe patch <strong>and</strong> save it on your local network. You can then apply the patch tomultiple computers.● Windows Update. With a list of the updates you want to install, useInternet Explorer on the server that requires the patch, <strong>and</strong> accesshttp://windowsupdate.microsoft.com/. Then select the required updates forinstallation. The updates are installed from the site <strong>and</strong> cannot be downloadedfor installation on another computer. Windows Update requires that an ActiveXcontrol is installed on the server (you will be prompted when you visit the site ifthe control is not found.) This method works well for st<strong>and</strong>alone workstations orwhere a small number of servers are involved.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!