Question

Web servers are compromised for a number of reasons which may include any of the following:...

Web servers are compromised for a number of reasons which may include any of the following: Improper file or directory permissions, installing the server with default settings,

unnecessary services enabled, security conflicts, a lack of proper security policies, improper authorization with external systems, default accounts with default or no passwords,

unnecessary default, backup, or sample files, misconfigurations, bugs in server software, OS, or web applications, misconfigured SSL certificates and encryption settings, administrative or debugging functions that are enabled or accessible on web servers or the use of self-signed certificates and/or default certificates.

Select one of these compromises and explain how it could be avoided.

0 0
Add a comment Improve this question Transcribed image text
Answer #1

Answer:-

i have selected  security conflicts

how to avoid security confilicts in web server:-

Keep Web Server Secure

Web Server is one of the most important and critical components of a web infrastructure. Web server is responsible for hosting a Web site and its related code, services, and all required files.

Here is a list of tasks Web server administrators should perform to keep Web and Database servers secure.

  • Separate development, staging, and production environments
  • Keep Operating System on its own hard drive partition
  • Enable tight security on Web Server including permissions and access
  • Keep separate user logins and their permissions based on their roles
  • Remove unnecessary services and don’t install them during installations
  • Disable remote access. If you must provide remote access, it should be on a secure network
  • Keep web application, scripts, and all code on a separate partition of the hard drive
  • Install Firewall and necessary products
  • Websites should be secure using the latest version of SSL and other protocols
  • Close all default open ports
  • Make sure to change and separate Admin logins and passwords from Web application administrators
  • Configure and enable Web server and other logs
  • Provision web server for latest technologies such as containers
  • Make sure to allocate and separate proper resources for web applications and services
  • Avoid using shared servers among multiple clients
  • Do not enable write permissions on server’s file system

Secure Database Server

Here is a list of tasks database administrators must do to secure database servers.

  • Make sure database server is separate from a Web server
  • Secure and encrypt login credentials
  • Implement separate user logins for separate web applications
  • Don’t give database users write and delete permissions unless necessary
  • Use object permissions on database tables and objects
  • Use secure mechanism to provide data access
  • Store and monitor database logs

Security Patches and Updates

Keep your servers up to date with the current patches including OS patches, database upgrades, and other software upgrades.

Monitor Traffic

Implement proper mechanism to monitor server traffic and implement fraud protection mechanism for suspected traffic.

Monitor Application Logs and Exceptions

Web applications must implement recording of recommended logs and exceptions. Server administrators should work with application managers to monitor application logs and exceptions frequently.

Audit Server Logs

Monitor server logs frequently.

Educate Users

Server administrators must educate Web administrators, developers, and even management about the importance of security and discourage them to download and make frequent changes. All changes on the servers must be logged, reviewed, and approved.

Add a comment
Know the answer?
Add Answer to:
Web servers are compromised for a number of reasons which may include any of the following:...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • TASK Read the Regional gardens case study document before attempting this assignment. Background: You have been...

    TASK Read the Regional gardens case study document before attempting this assignment. Background: You have been employed by Regional Gardens as their first Chief Information Officer (CIO). You have been tasked by the Board to conduct a review of the company’s risks and start to deploy security policies to protect their data and resources. You are concerned that the company has no existing contingency plans in case of a disaster. The Board indicated that some of their basic requirements for...

  • IT's About Business 4.1 The Heartbleed Bug What Is Heartbleed? OpenSSL, an open-source software package, is...

    IT's About Business 4.1 The Heartbleed Bug What Is Heartbleed? OpenSSL, an open-source software package, is a popular type of transport layer security (TLS) software (discussed later in this chapter) that secures numerous websites around the world. Web servers use OpenSSL to encrypt sites. Such sites show up in browsers with a “lock” icon and the “https” prefix in the address bar. The encryption protects Internet sites offering banking, shopping, email, and other private communications. Roughly two out of three...

  • TRUE/FALSE QUESTIONS:  Foundations of Information Security and Assurance 1. There is a problem anticipating and testing for...

    TRUE/FALSE QUESTIONS:  Foundations of Information Security and Assurance 1. There is a problem anticipating and testing for all potential types of non-standard inputs that might be exploited by an attacker to subvert a program. 2. Without suitable synchronization of accesses it is possible that values may be corrupted, or changes lost, due to over-lapping access, use, and replacement of shared values. 3. The biggest change of the nature in Windows XP SP2 was to change all anonymous remote procedure call (RPC)...

  • Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around...

    Risk management in Information Security today Everyday information security professionals are bombarded with marketing messages around risk and threat management, fostering an environment in which objectives seem clear: manage risk, manage threat, stop attacks, identify attackers. These objectives aren't wrong, but they are fundamentally misleading.In this session we'll examine the state of the information security industry in order to understand how the current climate fails to address the true needs of the business. We'll use those lessons as a foundation...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT