11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

How To:Use the Microsoft Baseline<strong>Security</strong> AnalyzerApplies ToThis information applies to computers that run the following:● Servers running Microsoft ® Windows 2000 Server or Windows 2003 Server● Developer workstations running Windows 2000 (all flavors), Windows XPProfessional or Windows 2003 Server● SQL Server 2000, including the Desktop Edition (MSDE)SummaryMicrosoft Baseline <strong>Security</strong> Analyzer (MBSA) checks for operating system <strong>and</strong> SQLServer updates. MBSA also scans a computer for insecure configuration. Whenchecking for Windows service packs <strong>and</strong> patches, it includes Windows componentssuch as Internet Information Service (IIS) <strong>and</strong> COM+. MBSA uses an XML file as themanifest of existing updates. This XML file, contained in the archive Mssecure.cab, iseither downloaded by MBSA when a scan is run, or the file can be downloaded onthe local computer, or made available from a network server.In this chapter, you will learn how to use MBSA to perform two processes:● A security updates scan● A check for default settings that are not secureThis How To reviews each mode separately, although both modes can be performedin the same pass.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!