11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

How To: Use the Microsoft Baseline <strong>Security</strong> Analyzer 789What You Must KnowBefore using this How To, you should be aware of the following:● You can use MBSA by using the graphical user interface (GUI) or from thecomm<strong>and</strong> line. The GUI executable is Mbsa.exe <strong>and</strong> the comm<strong>and</strong> line executableis Mbsacli.exe.● MBSA uses ports 138 <strong>and</strong> 139 to perform its scans.● MBSA requires administrator privileges on the computer that you scan. Theoptions /u (username) <strong>and</strong> /p (password) can be used to specify the username torun the scan. Do not store user names <strong>and</strong> passwords in text files such ascomm<strong>and</strong> files or scripts.● MBSA requires the following software:● Windows NT 4.0 SP4 <strong>and</strong> above, Windows 2000, or Windows XP (local scansonly on Windows XP computers that use simple file sharing).● IIS 4.0, 5.0 (required for IIS vulnerability checks).● SQL 7.0, 2000 (required for SQL vulnerability checks).● Microsoft Office 2000, XP (required for Office vulnerability checks).● The following services must be installed/enabled: Server service, RemoteRegistry service, File & Print Sharing.● The section Additional Information later in this How To includes tips onworking with MBSA.Scanning for <strong>Security</strong> Updates <strong>and</strong> PatchesYou can run Mbsa.exe <strong>and</strong> Mbsacli.exe with options to verify the presence of securitypatches.Using the Graphical InterfaceUse the MBSA GUI tool as described next. To use the MBSA GUI to scan for updates <strong>and</strong> patches1. Click Microsoft Baseline <strong>Security</strong> Analyzer from the Programs menu.2. Click Scan a computer.3. Make sure that the following options are not selected, <strong>and</strong> then click Start scan.●●●●Check for Windows vulnerabilitiesCheck for weak passwordsCheck for IIS vulnerabilitiesCheck for SQL vulnerabilities

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!