11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

How To: Use IISLockdown.exe 797Running IISLockdownIISLockdown detects the Microsoft .NET Framework <strong>and</strong> takes steps to secure.NET Framework files. Install the .NET Framework on your <strong>Web</strong> server before yourun IISLockdown.IISLockd.exe is not an installation program. When you launch IISLockd.exe, it runsthe IIS Lockdown Wizard. To run IISLockdown1. Run IISlockd.exe on your IIS <strong>Web</strong> server, click Next, <strong>and</strong> then read <strong>and</strong> accept thelicense agreement.2. For <strong>Web</strong> servers that host ASP.NET <strong>Web</strong> applications, select Dynamic <strong>Web</strong> server(ASP enabled) from the Server templates list.3. Select View template settings <strong>and</strong> then click Next.This allows you to specify the changes that the IIS Lockdown tool should perform.4. Select <strong>Web</strong> service (HTTP) <strong>and</strong> make sure that no other services are selected.5. Select Remove unselected services, click Yes in response to the warning messagebox, <strong>and</strong> then click Next.6. On the Script Maps page, disable support for the following script maps, <strong>and</strong> thenclick Next.●●●●Index Server <strong>Web</strong> Interface (.idq, .htw, .ida)Server side includes (.shtml, .shtm, .stm)Internet Data Connector (.idc).HTR scripting (.htr)● Internet printing (.printer)7. On the Additional <strong>Security</strong> page, select all of the available options.This causes IISLockdown to remove all of the listed virtual directories, configureNTFS permissions for the anonymous Internet account, <strong>and</strong> disable <strong>Web</strong>DAV.8. Click Next.9. On the URLScan page, select Install URLScan filter on the server.10. Click Next twice.IISLockdown updates your server configuration using the selected options.11. Click Next <strong>and</strong> then Finish to exit the tool.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!