Sinergija09 :: Akcija!!! Besplatno testiranje bezbednosti web sajta za sve firme-učesnike Sinergije09 ! Kompanija Microsoft Software je u saradnji sa partnerskom.

Slides:



Advertisements
Similar presentations
Windows Vista Security Tidbits
Advertisements

Internet Information Server 6.0. IIS 6.0 Enhancements  Fundamental changes, aimed at: Reliability & Availability Reliability & Availability Performance.
©2006 Microsoft Corporation. All rights reserved. Windows Vista Security Tidbits Steve Riley Senior Security Strategist Microsoft Corporation
Chapter 10 Securing Windows Server 2008 MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration.
Chapter 9 Deploying IIS and Active Directory Certificate Services
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 13: Planning Server and Network Security.
Module 3 Windows Server 2008 Branch Office Scenario.
Configuring Windows Vista Security Chapter 3. IE7 Pop-up Blocker Pop-up Blocker prevents annoying and sometimes unsafe pop-ups from web sites Can block.
Chapter 7 HARDENING SERVERS.
Chapter 11: Active Directory Certificate Services
Security and Policy Enforcement Mark Gibson Dave Northey
Using Internet Information Server And Microsoft ® Internet Explorer To Implement Security On The Intranet HTTP.
Chapter 6: Configuring Security. Group Policy and LGPO Setting Options Software Installation not available with LGPOs Remote Installation Services Scripts.
Microsoft Baseline Security Analyzer INLS 187 Security Software Presentation by Hinár György Polczer
Windows 2000 Security Architecture Peter Brundrett Program Manager Windows 2000 Security Microsoft Corporation.
Chapter 6 Configuring, Monitoring & Troubleshooting IPsec
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Avanade: 10 tips for å sikring av dine SQL Server databaser Bernt Lervik Infrastructure Architect Avanade.
Internet Information Server 6.0. Overview  What’s New in IIS 6.0?  Built-in Accounts and IIS 6.0  IIS Pass-Through Authentication  Securing Web Traffic.
Principles of Computer Security: CompTIA Security + ® and Beyond, Second Edition © 2010 Baselines Chapter 14.
Gavin Carius Architect Microsoft Services SVR311.
Edwin Sarmiento Microsoft MVP – Windows Server System Senior Systems Engineer/Database Administrator Fujitsu Asia Pte Ltd
Introduction to Active Directory December 10th, pm Daniels 407.
Clinic Security and Policy Enforcement in Windows Server 2008.
Module 9 Configuring Server Security Compliance. Module Overview Securing a Windows Infrastructure Overview of EFS Configuring an Audit Policy Overview.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
Configuring a Web Server. Overview Overview of IIS Preparing for an IIS Installation Installing IIS Configuring a Web Site Administering IIS Troubleshooting.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
Week #7 Objectives: Secure Windows 7 Desktop
Troubleshooting Windows Vista Security Chapter 4.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Module 14: Configuring Server Security Compliance
Module 9: Configuring IPsec. Module Overview Overview of IPsec Configuring Connection Security Rules Configuring IPsec NAP Enforcement.
1 Web services and security ---discuss different ways to enforce security Presenter: Han, Xue.
Windows XP Professional Features ©Richard L. Goldman February 5, 2003.
Module 9: Fundamentals of Securing Network Communication.
1 Introduction to Microsoft Windows 2000 Windows 2000 Overview Windows 2000 Architecture Overview Windows 2000 Directory Services Overview Logging On to.
Maintaining Network Health. Active Directory Certificate Services Public Key Infrastructure (PKI) Provides assurance that you are communicating with the.
1 Objectives Windows Firewalls with Advanced Security Bit-Lock Update and maintain your clients using Windows Server Update Service Microsoft Baseline.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
Planning a Microsoft Windows 2000 Administrative Structure Designing default administrative group membership Designing custom administrative groups local.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Welcome Windows Server 2008 安全功能 -NAP. Network Access Protection in Windows Server 2008.
Guide to MCSE , Second Edition, Enhanced1 The Windows XP Security Model User must logon with: Valid user ID Password User receives access token Access.
Module 14: Securing Windows Server Overview Introduction to Securing Servers Implementing Core Server Security Hardening Servers Microsoft Baseline.
Principles of Computer Security: CompTIA Security + ® and Beyond, Third Edition © 2012 Principles of Computer Security: CompTIA Security+ ® and Beyond,
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Module 7: Implementing Security Using Group Policy.
1 Chapter Overview Creating Web Sites and FTP Sites Creating Virtual Directories Managing Site Security Troubleshooting IIS.
Security E-Learning Chapter 08. Security Control access to your web site –3 Techinques for Identifying users Giving users access to your site Securing.
May 30 th – 31 st, 2007 Chateau Laurier Ottawa. Getting it Done: Understanding the Security Features of Windows Vista Kai Axford, CISSP, MCSE-Security.
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
Module 8 Implementing Security Using Group Policy.
4.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 12: Implementing Security.
Internet Information Server 6.0 & new management features.
IS 4506 Windows NTFS and IIS Security Features.  Overview Windows NTFS Server security Internet Information Server security features Securing communication.
Securing Tomorrow’s World Microsoft Security Roadmap Ed Gibson & Steve Lamb Microsoft Ltd.
ArcGIS for Server Security: Advanced
Basharat Institute of Higher Education
Module 8: Securing Network Traffic by Using IPSec and Certificates
IIS.
Server-to-Client Remote Access and DirectAccess
الخطوات المطلوب القيام بها قبل انشاء الموقع
{ Security Technologies}
Implementing Client Security on Windows 2000 and Windows XP Level 150
Module 8: Securing Network Traffic by Using IPSec and Certificates
Designing IIS Security (IIS – Internet Information Service)
Presentation transcript:

Sinergija09 :: Akcija!!! Besplatno testiranje bezbednosti web sajta za sve firme-učesnike Sinergije09 ! Kompanija Microsoft Software je u saradnji sa partnerskom firmom Network Security Solutions rešila da pokloni svim zainteresovanim firmama učesnicama Sinergije09, bez obzira na broj prijavljenih posetilaca konferencije, po jednu besplatnu osnovnu procenu bezbednosti web sajta. Prijave do 30. Novembra

Protecting Windows and Web applications Dejan Levaja, MVP [Enterprise Security] Network Security Solutions

Agenda Server 2008 Security mehnizmi - podsetnik IIS 7 security Patching Auditing Scanning and Assessment Hardening Security Testing

Security and protection Security improvements to the kernel – Kernel patch protection for 64-bit editions – Security improvements to the heap manager – Security improvements to the registry – Code integrity – Data Execution Prevention – Address Space Layout Randomization – Windows Resource Protection Security improvements to Windows services – Windows service hardening – Session 0 isolation – Named pipe hardening Windows Integrity Mechanism Windows Internet Explorer 7/8 – Protected mode – Extended Validation SSL certificates Extensible logon architecture Cryptography Next Generation Authentication protocol improvements – Windows implementation of the Kerberos protocol – TLS/SSL cryptographic enhancements

Threats and vulnerabilities mitigation Server role security configuration Server Core installation option User Account Control Web Server (IIS) role Backup and recovery Windows Firewall with Advanced Security Network Policy and Access Services role – Network Policy Server – Network Access Protection – Routing and Remote Access

Secure configuration assessment and management Security auditing Server security policy management Security Configuration Wizard Authorization Manager Group Policy Active Directory Domain Services – Fine-grained password policies – Auditing

Identity and access control Smart cards 802.1X authenticated wired and wireless access Backup and restore of stored user names and passwords Credential Security Service Provider and single sign-on for Terminal Services logon Previous logon information Access control user interface TrustedInstaller SID Restricted SIDs checks File system namespace modifications Default permissions changes Changes to tokens Integrity levels Icacls command-line tool OwnerRights SID BitLocker Drive Encryption Encrypting File System Active Directory Certificate Services – Cryptography Next Generation – Online Certificate Status Protocol – Network Device Enrollment Service – Web enrollment – Policy settings – Restricted enrollment agent – Enterprise PKI snap-in Active Directory Domain Services Active Directory Rights Management Service

IIS 7 Security Ranjivosti – IIS 7 (2006. – Sinergija09)=> 2 – Apache 2.2 (2006. – Sinergija09)=> 17 – IIS 6 (2003. – Sinergija09)=> 8 – Apache 2.0 (2003. – Sinergija09)=> 41 Authentication IP and Domain Restriction URL Authorization Request Filtering Certificates

IIS 7 Security - Authentication Izmene – IUSR_machine_name => IUSR – IUSR_machine_name postoji samo ako postoji i FTP – IUSR radi u bezbednosnom kontekstu worker procesa (network service) – IUSR nema lozinku – IUSR_WPG => IIS_IUSR – Najvažnije: IUSR i IIS_IUSR su Built-In nalozi –> svuda isti SID -> moguć XCOPY /O Authentication – Anonymous – Basic – Windows – Forms – Certificates* – Digest – ASP.NET Impersonation

IIS 7 Security - IP and Domain Restriction Ograničenje pristupa po IP adresi Ograničenje pristupa po imenu domena (zahteva reversni DNS lookup!) – Demo Dynamic IP Restrictions Extension (beta) –

IIS 7 Security - URL Authorization NTFS vs URL autorizacija – xcopy /o Demo – Scenario Isključimo Anon Auth, uključimo Basic kreiramo grupu kreiramo korisnike i dodamo ih u grupu obrišemo defaultni URL Authorization Rule i kreiramo novi – Sve ovo može i iz CMD-a (appcmd.exe)!

Request Filtering – simple WAF URLScan => Request Filtering – Filter Double-Encoded Requests ‘\’ => %5c – ‘% ‘=> %25 » %255c scripts/..%255c..%255c..%255cwinnt/system32/cmd.exe?/c+dir+c:\ (IIS 5.0) – Filter High Bit Characters – Filter Based on File Extensions – Filter Based on Request Limits – Filter by Verbs – Filter Based on URL Sequences /../, – Filter Out Hidden Segments

Certificates SSL – one to many mapping – one to one mapping – AD mapping – CLR, delta CRL – Next, next, finish Demo

Patching Windows Update – <= Vista – OS + IE Microsoft Update – Windows Update + MS Office + Exchange + SQL +... – Automatic Update Patch Tuesday ( and Exploit Wednesday ) Microsoft Catalog –

Patching WSUS 3.0 – Sastavni deo Servera 2008 (KB ) – SUS == OS; WSUS == OS + ostalo – WSUS = IIS 7+ SQL (WID) + Microsoft Update – GPO ili Registry GPO => Computer Configuration\Administrative Templates\Windows Components\Windows Upddate\Specify Intranet Microsoft Update Service Location Registry => KLM\Software\Policies\Microsoft\Windows\WindowsUpdate\ – reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate » /v WUServer /t REG_SZ /d » /v WUStatusServer /t REG_SZ /d

Auditing Auditing in Server 2008 – 4GB vs >petabyte – n*1000 evt/sec vs n*10000 evt/sec – granular audit policy (GAP) – GPO (R2), AuditPol.exe EventViewer – XML eventquery.vbs wevtutil.exe Demo: Failed logons – wevtutil qe Security /q:"*[System[(EventID=4624)]]" /f:text > logon.txt wevtutil qe Security /q:"*[System[(EventID=4624)]]" /f:text > logon.txt

Scanning MBSA – Security Updates, Administrative Vulnerabilities, IIS, SQL, Desktop apps – WSUS i MBSA – GUI, cmd (mbsacli.exe) – Online, Offline – wsusscn2.cab - – Visio Connector (2003,2007) – %userprofile%\SecurityScans – Demo: mbsacli.exe /target /u administrator /p mbsacli.exe /n SQL+IIS /catalog c:\wsusscan2.cab /nd

Assessment MSAT – MSAT is designed to help you identify and address security risks in your IT environment. – Preko 200 pitanja baziranih na ISO Infrastructure, Applications, Operations, People Demo

Hardening Windows Firewall with Advanced Security IPSec => Server and Domain Isolation – R2 or not R2 ? – Demo Security Configuration Wizard – Demo

Security Testing Vulnerability Assessment – popisuje ranjivosti – MBSA,... Penetration Testing – dokazuje da je moguće iskoristiti prona đ ene ranjivosti – browser + proxy, metasploit,... Besplatno testiranje bezbednosti web sajta za sve firme-učesnike Sinergije09 ! Prijave do 30. Novembra

Molimo vas da popunite ankete! Please fill out the evaluations! Vaše mišljenje čini osnovu sledeće Sinergije i omogućava nam da oblikujemo sadržaj u skladu sa Vašim željama. Svi posetioci koji popune ankete ulaze u nagradnu igru Your opinion forms the next Sinergija conference, and it provides us with the means to shape its content to best suit you. All attendees that fill out the evaluations are taking part in drawing of special prizes

Hvala! Microsoft Community Serbia