11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

How To: Secure Your Developer Workstation 773Apply Patches for Each Instance of SQL Server <strong>and</strong> MSDEMSDE shares common technology with SQL Server, <strong>and</strong> it enables developers,partners, <strong>and</strong> IT professionals to build database applications without requiring thefull SQL Server product. MSDE can be packaged with applications that requiredatabase support. To apply patches to MSDE, you must know which applicationinstalled it on your system. This is important because you must obtain the patch forMSDE from the product vendor.For more information on applications that include MSDE, refer to the followingresources:● “Microsoft Products That Include MSDE,” at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/MSDEapps.asp●“SQL Server/MSDE-Based <strong>Application</strong>s,” at http://www.sqlsecurity.com/forum/applicationslistgridall.aspxIf your third-party vendor does not supply a patch for MSDE, <strong>and</strong> if it becomescritical to have the latest patches, you can only do the following:● Uninstall the instance of SQL Server using Add/Remove Programs. If you do notsee an uninstall option for your instance, you might need to uninstall yourapplication.● Stop the instance of SQL Server using the Services MMC snap-in in ComputerManagement. You can also stop the instance from the comm<strong>and</strong> line by runningthe following comm<strong>and</strong>:●net stop mssqlserver (default instance), mssql$instancename (for instances)Use IPSec to limit which hosts can connect to the ab<strong>and</strong>oned (unpatched)instances of SQL Server. Restrict access to localhost clients.Analyze SQL Server <strong>and</strong> MSDE <strong>Security</strong> ConfigurationUse MBSA to analyze your Microsoft SQL Server or MSDE configuration on yourworkstation. To analyze SQL Server <strong>and</strong> MSDE security configuration1. Run MBSA by double-clicking the desktop icon or selecting it from thePrograms menu.2. Click Scan a computer. MBSA defaults to the local computer.3. Clear all check boxes except for Check for SQL vulnerabilities.This option scans for security vulnerabilities in the configurations of SQL Server7.0, SQL Server 2000, <strong>and</strong> MSDE. For example, it checks the authentication mode,the sa account password, <strong>and</strong> the SQL Server service account, among other checks.A number of the checks require that your instance of SQL Server is running. If it isnot running, start it.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!