11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

770 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresAutomatic Updates scans <strong>and</strong> installs updates for the following operating systems(including the .NET Framework <strong>and</strong> IIS where applicable):● Microsoft Windows 2000 Professional● Microsoft Windows 2000 Server● Microsoft Windows XP ProfessionalIn addition to using Automatic Updates, use MBSA to detect missing updates forSQL Server, MSDE <strong>and</strong> MDAC.Secure IISYou often need to run IIS locally for <strong>Web</strong> development. If you run IIS, secure it.IISLockdown <strong>and</strong> URLScan significantly reduce your <strong>Web</strong> server’s attack profile.IISLockdown points unused or forbidden script mappings to 404.dll <strong>and</strong> helps secureaccess to system directories <strong>and</strong> system tools. URLScan blocks known dangerousrequests.Although IISLockdown improves IIS security, if you choose the wrong installationoptions or do not modify the URLScan configuration file, URLScan.ini, you couldencounter the following issues:● You cannot create new ASP.NET <strong>Web</strong> applications. NTFS file system permissionsare configured to strengthen default access to <strong>Web</strong> locations. This may prevent thelogged on user from creating new ASP.NET <strong>Web</strong> applications.● Cannot debug existing ASP.NET <strong>Web</strong> applications. URLScan blocks the DEBUGverb, which is used when you debug ASP.NET <strong>Web</strong> applications.The following steps show you how to improve IIS security on your developmentworkstation <strong>and</strong> avoid the issues listed above:● Install <strong>and</strong> run IISLockdown● Configure URLScan● Restrict access to the local <strong>Web</strong> serverInstall <strong>and</strong> Run IISLockdown To install <strong>and</strong> run IISLockdown1. Run the IISLockdown installation program (Iislockd.exe) fromhttp://download.microsoft.com/download/iis50/Utility/2.1/NT45XP/EN-US/iislockd.exe.Note If you run Iislockd.exe a second time, it removes all changes based on the log file\WINNT\System32\Inetsrv\oblt-log.log.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!