11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

796 <strong>Improving</strong> <strong>Web</strong> <strong>Application</strong> <strong>Security</strong>: <strong>Threats</strong> <strong>and</strong> Countermeasures●●It removes the following virtual directories:●●●●●IIS SamplesMSADCIISHelpScriptsIISAdminIt restricts anonymous access to system utilities as well as the ability to write to<strong>Web</strong> content directories. To do this, IISLockdown creates two new local groupscalled <strong>Web</strong> Anonymous Users <strong>and</strong> <strong>Web</strong> <strong>Application</strong>s <strong>and</strong> then it adds denyaccess control entries (ACEs) for these groups to the access control list (ACL) onkey utilities <strong>and</strong> directories.Next, IISLockdown adds the default anonymous Internet user account(IUSR_MACHINE) to <strong>Web</strong> Anonymous Users <strong>and</strong> the IWAM_MACHINEaccount to <strong>Web</strong> <strong>Application</strong>s.Note If you create custom, anonymous Internet user accounts, add them to the<strong>Web</strong> Anonymous Users group.●●It disables <strong>Web</strong> Distributed Authoring <strong>and</strong> Versioning (<strong>Web</strong>DAV).It installs the URLScan ISAPI filter.Installing IISLockdownTo install IISlockdown, download it from the Microsoft <strong>Web</strong> site athttp://download.microsoft.com/download/iis50/Utility/2.1/NT45XP/EN-US/iislockd.exe.You can save it locally or run it directly by clicking Open when you are prompted. Ifyou save IISLockd.exe, you can unpack helpful files by running the followingcomm<strong>and</strong>:iislockd.exe /q /cThis comm<strong>and</strong> unpacks the following files:● IISLockd.chm. This is the compiled help file for the IISLockdown tool.●●RunLockdUnattended.doc. This file includes instructions for unattendedIISLockdown execution.URLScan.exe <strong>and</strong> associated files. These files install URLScan without runningIISLockdown.exe.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!