11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

768 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresMore InformationFor more information about developing with a non-administrative account, see thefollowing articles:● “Essential .NET <strong>Security</strong>,” at http://www.develop.com/kbrown/book/html/lifestyle.html●“Developing Software in Visual Studio .NET with Non-AdministrativePrivileges,” at http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dv_vstechart/html/tchDevelopingSoftwareInVisualStudioNETWithNon-AdministrativePrivileges.aspPatch <strong>and</strong> UpdateEnsure that your workstation has the latest service packs <strong>and</strong> patches. Check theoperating system, IIS, SQL Server, MSDE, Microsoft Data Access Components(MDAC), <strong>and</strong> the .NET Framework. Microsoft offers several tools <strong>and</strong> methods tohelp you scan <strong>and</strong> update your system. These include the Windows Update site,the Microsoft Baseline <strong>Security</strong> Analyzer (MBSA) tool, <strong>and</strong> the Automatic Updatesfeature.Using Windows UpdateYou can use Windows Update (available from the Start menu) to scan for updates<strong>and</strong> patches for Windows. Alternatively, you can directly scan for updates athttp://windowsupdate.microsoft.com.Note After you update your system using the Windows Update site, use MBSA to detect missingupdates for SQL Server, MSDE, <strong>and</strong> MDAC.Using MBSAYou can use MBSA to assess security <strong>and</strong> to verify patches. If you used automaticupdates or Windows Update to update your operating system <strong>and</strong> components,MBSA verifies those updates <strong>and</strong> additionally checks the status of updates for SQLServer <strong>and</strong> Microsoft Exchange Server. MBSA lets you create a script to checkmultiple computers. To detect <strong>and</strong> install patches <strong>and</strong> updates1. Download MBSA from the MBSA home page at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/Tools/mbsahome.asp.If you do not have Internet access when you run MBSA, MBSA cannot retrievethe XML file that contains the latest security settings from Microsoft. You canuse another computer to download the XML file, however. Then you cancopy it into the MBSA program directory. The XML file is available athttp://download.microsoft.com/download/xml/security/1.0/nt5/en-us/mssecure.cab.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!