module 6: patches and security updates 1. overview installing patches and security updates recent...

18
Module 6: Patches and Security Updates 1

Upload: corey-welch

Post on 23-Dec-2015

238 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Module 6: Patches and Security Updates

1

Page 2: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Overview

• Installing Patches and Security Updates

• Recent patches and security updates for IIS

• Recent patches and security updates for Apache

• Recent patches and security updates for some other web server (TBD)

2

Page 3: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

3

Installing Patches and Security Upates

Page 4: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Installing Patches and Security Updates

Page 5: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Installing Patches and Security Updates

• MS10-019

• MS10-020

• MS10-025

• MS10-026

• MS10-027

• MS10-021

Page 6: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Installing Patches and Security Updates

IIS 5.0 is the version installed by default on W2K computers. If you have SP4 for W2K (and you should), these are the patches that you need to apply to your computer:

• 327696 MS02-062

• 321599 MS02-028

• 319733 MS02-018

6

Page 7: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Other IIS Patching Tools

You should also look at the IIS Lockdown Tool and URLScan which are valuable tools for "anti-IIS" activity protection:

• URLScan Security Tool (v2.5)

• IIS Lockdown Tool (v2.1)

Page 8: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

IIS 5.1 Required Patches

• IIS 5.1 is the version available on Windows XP computers. Although it is not installed by default on XP Pro computers, it's still a big security concern.

• This patch is a cumulative patch that includes the functionality of all security patches released for IIS 5.1 since Windows XP Service Pack 1:

• 327696 MS02-062:

• 321599 MS02-028:

• 319733 MS02-018:

Page 9: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Improved Patch Management

• No service interruption while installing patches.

• Auto Update.

• Windows Update Corporate Edition.

• Resource Free DLLs.

Page 10: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

 Options to Obtain Security Updates

Option

Microsoft Security Notification Service Newsletter

Windows Update

SUS

Page 11: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Security update Deployment

OPTION DEPLOYMENT

Microsoft Security Notification Service

Newsletter

Manually download the updates and then deploy them manually or automatically by using a software distribution program, such as Microsoft System Management Server.

Windows Update Configure Windows Update to do one of the following

SUS Configure the SUS to provide updates to the Web server through

an updated version of Windows Update called Automatic Updates.

Page 12: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Vulnerability Rating

RATING DESCRIPTION

CriticalA vulnerability that, if exploited, might allow the propagation of an Internet worm without user action.

ImportantA vulnerability that, if exploited, might result in a compromise of the confidentiality, integrity, or availability of user data, or of the integrity or availability of processing resources.

ModerateA vulnerability risk that can be mitigated by factors such as default configuration, auditing, or difficulty to exploit.

Low A vulnerability that is extremely difficult to exploit, or that has minimal impact.

Page 13: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

13

Recent patches and security updates for IIS

Page 14: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Security updates

• Deny resource access by default and only allow resource functionality as desired.

• Log all web requests as they help identify suspicious activity.

• Subscribe to the Apache Server Announcement mailing list which can send updates, patches and security fixes.

Page 15: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

15

Recent patches and security updates for Apache

Page 16: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

Security updates

• Disable default services such as FTP and SMTP unless you need them.

• Disable the directory browsing function unless it is required as it allows visitors to see which files are running on your system.

• Disable any FrontPage Server Extensions that are not being used.

Page 17: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

17

Recent patches and security updates for OWS

Page 18: Module 6: Patches and Security Updates 1. Overview Installing Patches and Security Updates Recent patches and security updates for IIS Recent patches

18