11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

788 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> CountermeasuresContents●●●●●●●●Before You BeginWhat You Must KnowScanning for <strong>Security</strong> Updates <strong>and</strong> PatchesScanning Multiple Systems for Updates <strong>and</strong> PatchesSQL Server <strong>and</strong> MSDE SpecificsScanning for Secure defaultsPitfallsAdditional ResourcesBefore You BeginInstall MBSA, using Mbsasetup.msi, to a tools directory. Copy the file Mssecure.cabto the MBSA installation directory.● Download MBSA. Download MBSA from the MBSA Home Page:http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/Tools/mbsahome.asp●Updates for MBSA. If the machine you use has Internet access, the latest securityXML file will be downloaded automatically, if needed. If your computer does nothave Internet access, you need to download the latest XML file using the signedCAB at the following location: http://download.microsoft.com/download/xml/security/1.0/NT5/EN-US/mssecure.cabThe CAB file is signed to ensure it has not been modified. You must uncompress it<strong>and</strong> store it in the same folder where MBSA is stored.Note To view the latest XML file without downloading it, use the following location:https://www.microsoft.com/technet/security/search/mssecure.xml●Default installation directory: \Program Files\Microsoft Baseline <strong>Security</strong>Analyzer\Note You need to run comm<strong>and</strong>s from this directory. MBSA does not create an environmentvariable for you.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!