11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

762 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresDo Not Forward Packets Destined for Multiple HostsMulticast packets may be responded to by multiple hosts, resulting in responses thatcan flood a network.Value: EnableMulticastForwardingRecommended value data: 0Valid range: 0 (false), 1 (true)Description: The routing service uses this parameter to control whether or not IPmulticasts are forwarded. This parameter is created by the Routing <strong>and</strong> RemoteAccess Service.Only Firewalls Forward Packets Between NetworksA multi-homed server must not forward packets between the networks it isconnected to. The obvious exception is the firewall.Value: IPEnableRouterRecommended value data: 0Valid range: 0 (false), 1 (true)Description: Setting this parameter to 1 (true) causes the system to route IP packetsbetween the networks to which it is connected.Mask Network Topology DetailsThe subnet mask of a host can be requested using ICMP packets. This disclosure ofinformation by itself is harmless; however, the responses of multiple hosts can beused to build knowledge of the internal network.Value: EnableAddrMaskReplyRecommended value data: 0Valid range: 0 (false), 1 (true)Description: This parameter controls whether the computer responds to an ICMPaddress mask request.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!