You are here: hacking technology > network management > Content
Hot Articles
Recommend Articles
New Articles
Prevents the hacker to invade the WEB server three inchworms
  Add date: 07/10/2008   Publishing date: 07/10/2008   Hits: 145
The WEB server common situation occurrence, following gives three kind of most common situations the solutions

  Against ACCESS database downloading

  Increased MDB the expansion mapping to be possible. Method: The IIS attribute, the main table of contents, the disposition, the mapping, in the application program extension increases .mdb the application analysis, may from test as for choice analysis document everybody, so long as time visit database appeared is unable to find this page to be possible, here gave a choice is wam.dll

  Against upload

  Take the MSSQL database as the example. In the IIS WEB table of contents, can only the IIS user read and list the table of contents jurisdiction in the jurisdiction option, then enters the upload document preservation and the depositing database table of contents, adds on the jurisdiction which for the IIS user reads, then in these two table of contents's attribute, carried out the jurisdiction option to change the pure script does not have completes. Generally speaking is the table of contents which may upload for does not carry out the jurisdiction, has carries out the jurisdiction table of contents not to permit the upload.

  Against MSSQL pours into

  This is very important, in a reminder, connects the database not to be able to use the SA account number. Generally speaking may use the DB--OWNER jurisdiction to connect the database. However this existence differential backup obtains WEBSHELL the question. How did below say against differential backup.

  The differential backup has the backup jurisdiction, moreover must know the WEB table of contents. Now looks for the WEB table of contents the method is perhaps lists the main engine table of contents through the registry from to look, these two methods used XP_REGREAD and XP_DRITREE these two expansions actually save, so long as we deleted them to be possible. But also has a point is accidentally the procedure from blew out the table of contents. Must therefore let the account number the jurisdiction be lower, is unable to complete the backup. Operates as follows: In this account number's attribute, in the database visit option only needs to select corresponding the database and entrusts with its DB_OWNER jurisdiction, do not operate regarding other databases, then must arrive at this database, the attribute, the jurisdiction, removed this user's backup and the backup diary's jurisdiction may, such intruder could not gain WEBSEHLL through the differential backup.
Prev:Why can't hundreds of thousands of equipment block the hacker attack Next:Teaches you to close the network port protection network security

Comment:

Category: Home > network management