Dropped here by your search engine? Use the same keyword in the google box below to search this site.
Google
 
Web This Site


Step by Step Guide: Securing Web servers

Doing business in today's world seems to create an ongoing need to set up a new Web server. For everything from development to marketing to training to ecommerce, the desire to load up static pages or networked applications is endless. But how can you be sure that the path you go down will lead you to a secure Web server that's less likely to be compromised by malicious outsiders or rogue insiders?

There are certain must have baseline configuration settings every Windows based Web server needs regardless of whether it's IIS, Apache or some no name software built into your niche email server product. Your goal for configuration settings should be to have a server ready to be placed "in the wild" that's resilient to common Web server OS and application attacks and vulnerabilities:

* Null sessions
* Weak share and NTFS permissions
* Weak passwords and authentication systems
* Exploitable vulnerabilities due to missing patches and other OS misconfigurations
* Fingerprinting
* Parameter manipulation
* Default scripts
* Buffer overflows
* Cross-site scripting
* SQL injection
* Denial of Service due to missing critical layered defenses

This is certainly not an exhaustive list of attack methods, but it covers the main areas at both the OS and Web server application levels. Step by Step Guide: Securing Web servers



More News



You are browsing the old version of "The Network Security. Org", Please
click here to visit the
new version.


Categories


RSS feed



server uptime monitor service




Warning: main(ad_network_213.php) [function.main]: failed to open stream: No such file or directory in /home/thenetw/public_html/news/View.php on line 282

Warning: main(ad_network_213.php) [function.main]: failed to open stream: No such file or directory in /home/thenetw/public_html/news/View.php on line 282

Warning: main(ad_network_213.php) [function.main]: failed to open stream: No such file or directory in /home/thenetw/public_html/news/View.php on line 282

Warning: main() [function.include]: Failed opening 'ad_network_213.php' for inclusion (include_path='.:/usr/lib/php:/usr/local/lib/php:../:../../:../../../:../../../../') in /home/thenetw/public_html/news/View.php on line 282