Server Security Settings (2)

Source: Internet
Author: User

NOTE: For the WWW Service, you can reject addresses suspected of website attacks. Especially for the FTP service, if you only upload files from your own company, you can only allow the company's IP address to access and change the FTP service, which greatly improves the security.

18. Prohibit anonymous access to the FTP service
NOTE: If anonymous access to the FTP service is allowed, the anonymous account may be used to obtain more information, causing harm to the system.

19. We recommend that you use W3C to expand the log file format and record the customer's IP address, user name, server port, method, URI root, HTTP status, and user proxy every day. (It is recommended that you do not use the default directory. We recommend that you change the log recording path and set the Log Access permission to only allow the Administrator and system to be Full Control)
Note: As an important measure, we can detect signs of attacks, take preventive measures, and use it as evidence of attacks.

20. Exercise caution when setting the access permission for the WEB site directory. Generally, do not grant the directory write or allow the directory browsing permission. Only grant the. ASP file directory the script permission instead of the execution permission.
Note: Directory Access Permissions must be carefully set; otherwise, they will be exploited by hackers.

21. ASP programming security:

Security is not only a matter of network management, but also a programmer must pay attention to some security details to form a good security habit. Otherwise, hackers will be able to take advantage of it. Currently, ASP programs on most websites have such security vulnerabilities. However, if you pay attention to the vulnerabilities when writing programs, you can avoid them.

It is best to encapsulate programs involving user names and passwords on the server side and appear as few as possible in ASP files. The minimum permission should be granted to the user names and passwords in connection with the database.
Note: usernames and passwords are often the most interesting things for hackers. If the source code is seen in some way, the consequences are serious. Therefore, we should minimize the number of times they appear in ASP files. The user name and password can be written in a concealed include file in one location. If you need to connect to a database, you can only grant it the permission to execute the stored procedure. do not grant the user the permission to modify, insert, or delete records directly.

For an ASP page that requires verification, you can trace the file name of the previous page. Only sessions that are transferred from the previous page can read this page.
Note: currently, most ASP programs that need to be verified Add a judgment statement in the header of the page, but this is not enough. hackers may bypass the verification and directly access the site, therefore, it is necessary to track the previous page. For specific vulnerabilities, see the vulnerability documentation.

Prevent ASP homepage. inc file Leakage
When the asp homepage is being created and the final debugging is not completed, some search engines can append it as a search object. If someone uses the search engine to search for these webpages, the file is located, and the detailed location and structure of the database can be viewed in the browser to reveal the complete source code.

Solution: programmers should thoroughly debug the webpage before publishing it. Security experts need to fix asp files so that external users cannot view them. First, encrypt the. inc file content, and then use the. asp file instead of the. inc file so that users cannot directly view the source code of the file from the browser .. The name of the inc file does not need to use the system default or has a special meaning that is easily guessed by the user, try to use English letters without rules.

Note that some ASP editors will automatically back up asp files and will be downloaded.
In some tools used to edit asp programs, when an asp file is created or modified, the editor automatically creates a backup file. For example, UltraEdit backs up one file .. bak file. If you have created or modified some files. asp, the editor automatically generates a file called some. asp. bak file. If you haven't deleted this bak file, you can directly download some. asp. bak file, so some. the source program of asp will be downloaded.

In ASP programs that process input boxes such as message boards and BBS, it is best to block HTML, javascript, and VBScript statements. If there are no special requirements, only letters and numbers are allowed, special characters are blocked. The length of the input characters is also limited. In addition, you must not only check the validity of input on the client, but also perform similar checks in the server program.
Note: The input box is a target used by hackers. They can damage the user client by entering the script language. If the input box involves data query, they will use the special query input to get more database data, or even the whole table. Therefore, the input box must be filtered. However, if you only check the validity of input on the client to improve the efficiency, it may still be bypassed. Therefore, you must perform another check on the server.

This vulnerability prevents ACCESS mdb databases from being downloaded.
When using ACCESS as the background database, if someone knows or guessed the path and name of the server's ACCESS database through various methods, then he can download the ACCESS database file, this is very dangerous.
Solution:
(1) create a complex and unconventional name for your database file name and put it under several directories. For example, if a database stores information about books, do not set up a book. mdb, such as d34ksfslf. mdb, and then put it in. in the/kdslf/i44/studi/directory, it is difficult for hackers to obtain your ACCESS database files by means of guesses.
(2) do not write the database name in the program. Some people like to write DSN in a program, such:
DBPath = Server. MapPath ("analytic dB. mdb ")
Conn. Open "driver = {Microsoft Access Driver (*. mdb)}; dbq =" & DBPath
If you get the source program, your ACCESS database name will be displayed at a glance. Therefore, we recommend that you set the data source in ODBC and write it in the program as follows:


Conn. open "shujiyuan"
(3) Use ACCESS to encode and encrypt database files. First, choose tools> Security> encryption/Decryption database, and select the database (for example, employer. mdb), and then click OK. Then, the window "Save the database encrypted and saved as: employer1.mdb" appears. Then employer. mdb will be encoded and stored as employer1.mdb ..
Note that the above actions are not to set a password for the database, but to encode the database files to prevent others from using other tools to view the contents of the database files.
Next, we encrypt the database. First, we open the encoded employer1.mdb, and select the "exclusive" mode when opening it. Choose tools> Security> set database password from the menu, and enter the password. In this way, even if someone else gets the employee 1.mdb file, he cannot see the employee 1.mdb without a password.

23. SQL SERVER Security

SQL SERVER is the most widely used database system on the NT platform, but its security problems must also be paid attention. Databases often have the most valuable information. Once data is stolen, the consequences are unimaginable.

Update patches in a timely manner.
Note: Like NT, many SQL SERVER Vulnerabilities are compensated by patches. We recommend that you perform a test on the testing machine before installing the patch, and back up data on the target server in advance.

Give SA a complex password.
Note: SA has all permissions for SQL SERVER database operations. Unfortunately, some network administrators are not familiar with the database, and the database creation work is done by the programmers. However, these programmers only pay attention to writing SQL statements, I am not familiar with SQL SERVER database management, which may result in a blank SA password. This poses a serious threat to database security. At present, there are not a few websites with such risks.

Strictly control the permissions of database users. do not grant users the permission to directly query, modify, insert, or delete tables. You can grant users the permission to access views, and only have the permission to execute the stored procedure.
Note: If a user has direct operation permissions on a table, the data may be damaged.

Formulate complete database backup and recovery policies.

24. PCANYWHERE security:

Currently, PCANYWHERE is the most popular remote control tool based on NT and 2000. You also need to pay attention to security issues.

We recommend that you use a separate user name and password. It is best to use encryption. Do not use the same username and password as the NT administrator, or use the password integrated with NT. At the same time, when setting the server side, you must use the strong encryption method in security options to reject low-level encrypted connections. At the same time, password encryption and user name and password encryption during transmission are used, to prevent sniffing and limit the number of connections, it is also important to set a strong password in protect item, at the same time, you must restrict the access to any settings on your host. You must enter a password to view the settings on the host!

Note: The PCANYWHERE password is the first entry in remote control. If it is the same as that of NT, it will lose the security barrier. After being attacked, there will be no security. If you use a separate password, even if you break through PCANYWHERE, NT also has a password barrier.
Install newer versions in time.

2. Intermediate: IIS security and performance Adjustment

In fact, there are many conflicts between security and applications. Therefore, you need to find a balance between them. After all, the server is used for users rather than open hack, if the security principle hinders system application, this is not a good principle. Network security is a system project. It not only has a spatial span, but also has a time span. Many of my friends (including some system administrators) think that the host with security configuration is secure. In fact, there is a misunderstanding: we can only say that a host is secure for a certain period of time with changes in the network structure, detection of new vulnerabilities, and operations by administrators/users, the security status of hosts changes anytime and anywhere. Only security awareness and security systems can be implemented throughout the entire process.

Eight Ways to Improve the efficiency of IIS 5.0 website servers
The following are eight ways to improve the efficiency of the IIS 5.0 website Server:
1. Enabling the continuous effect of HTTP can be improved by 15 ~ 20% execution efficiency.
2. Record disabled can be improved by 5 ~ 8% execution efficiency.
3. Using a [independent] processing program will result in a 20% reduction in execution efficiency.
4. Increase the number of files stored in the cache to improve the efficiency of Active Server Pages.
5. Do not use CGI programs.
6. Increase the number of CPUs of IIS 5.0 computers.
7. Do not enable ASP debugging.
8. Static web pages adopt HTTP compression, which can reduce the transmission volume by about 20%.

The following is a brief introduction.
1. Enable the continuous effect of HTTP
When the HTTP continuous function (Keep-Alive) is enabled, the connection between IIS and the browser will not be broken, which can improve the execution efficiency until the browser is closed. Because the "Keep-Alive" status is maintained, a new connection is not required for each client request, so the efficiency of the server is improved. This function is a preset function of HTTP1.1. HTTP 1.0 with the Keep-Alive header can also provide the HTTP continuous function.
 

2. Enabling the continuous effect of HTTP can be improved by 15 ~ 20% of executions

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.