SlideShare a Scribd company logo
1 of 2
Disable HTTP PUT Method

       Go into IIS manager
       Right click on the website and select properties
       Go to the home directory tab
       un click write




Apply IP restrictions to allow only Office users to access edit pages

       Open IIS Manager and navigate to the level you want to manage. For information about opening
       IIS Manager, see Open IIS Manager (IIS 7). For information about navigating to locations in the
       UI, see Navigation in IIS Manager (IIS 7).
       In Features View, double-click IPv4 Address and Domain Restrictions.
       In the Actions pane, click Add Allow Entry.
       In the Add Allow Restriction Rule dialog box, select Specific IPv4 address, IPv4 address range, or
       Domain name, add the IPv4 address, range, mask, or domain name, and then click OK



Configure Anti Virus software to prevent the loading of malicious files

Set cache controls
http://support.microsoft.com/kb/247404

 How to disable SSL v2 protocol in Windows?                                                  2008.09.03
                                                                                               00:02:46
 Secure Socket Layer Protocol version 2 (SSL v2) has a serious vulnerability.
 Successful exploitation of this vulnerability would allow an attacker to execute
 arbitrary code in the context of the affected server. No authentication is required
 to reach the vulnerable code. No user interaction is required.

 Since this vulnerability is in the library code used by multiple applications, the
 details of how an attacker would exploit it varies. In all cases, an attacker would
 need to specify invalid parameters as part of the SSLv2 handshake. Common
 Vulnerabilities and Exposures (CVE) classified the vulnerability under CVE-2004-
 0120. Microsoft identified such vulnerabilities in its security bulletin MS04-011,
 however, until today the default configuration for Windows 2000 and Windows                       issam
 2003 has SSL v2.0 protocol enabled.
 To disable SSL V2 protocol:
  1.Click Start, click Run, type regedt32 or type regedit, and then click OK.
  2.In Registry Editor, locate the following registry key:
HKey_Local_MachineSystemCurrentControlSetControlSecurityProviders
    SCHANNELProtocolsSSL 2.0Server
  3.On the Edit menu, click Add Value.
  4.In the Data Type list, click DWORD.
  5.In the Value Name box, type Enabled, and then click OK.

    Note If this value is present, double-click the value to edit its current value.
  6.Type 00000000 in Binary Editor to set the value of the new key equal to "0".
  7.Click OK.


Disable SSL Version two
http://www.sslshopper.com/article-how-to-disable-ssl-2.0-in-iis-7.html

Suppress display of software versions in returned HTTP headers
This can be suppressed using I I S addin urlscan ( see above)

More Related Content

Viewers also liked

SharePoint 2013 Performance Enhancements
SharePoint 2013 Performance EnhancementsSharePoint 2013 Performance Enhancements
SharePoint 2013 Performance EnhancementsEric Shupps
 
SharePoint 2013 Performance Enhancements
SharePoint 2013 Performance EnhancementsSharePoint 2013 Performance Enhancements
SharePoint 2013 Performance EnhancementsEric Shupps
 
Laboratorio
LaboratorioLaboratorio
Laboratorioyone2011
 
SharePoint Performance Optimization In 10 Steps for the IT Professional
SharePoint Performance Optimization In 10 Steps for the IT ProfessionalSharePoint Performance Optimization In 10 Steps for the IT Professional
SharePoint Performance Optimization In 10 Steps for the IT ProfessionalJoel Oleson
 
Diapositivas oxalatos
Diapositivas oxalatosDiapositivas oxalatos
Diapositivas oxalatosanamcubillos
 
TOXICOLOGIA DE LOS ALIMENTOS
TOXICOLOGIA DE LOS ALIMENTOSTOXICOLOGIA DE LOS ALIMENTOS
TOXICOLOGIA DE LOS ALIMENTOSmonicalapo
 
Toxicología de los Alimentos: Frutas y Hortalizas
Toxicología de los Alimentos: Frutas y Hortalizas Toxicología de los Alimentos: Frutas y Hortalizas
Toxicología de los Alimentos: Frutas y Hortalizas Marco Vinicio Robles Aguilar
 
Litiasis urinaria
Litiasis urinariaLitiasis urinaria
Litiasis urinariaRubens
 
Litiasis renal
Litiasis renal Litiasis renal
Litiasis renal 23762376
 

Viewers also liked (17)

SharePoint 2013 Performance Enhancements
SharePoint 2013 Performance EnhancementsSharePoint 2013 Performance Enhancements
SharePoint 2013 Performance Enhancements
 
SharePoint 2013 Performance Enhancements
SharePoint 2013 Performance EnhancementsSharePoint 2013 Performance Enhancements
SharePoint 2013 Performance Enhancements
 
Laboratorio
LaboratorioLaboratorio
Laboratorio
 
Frutas y verduras
Frutas y verdurasFrutas y verduras
Frutas y verduras
 
SharePoint Performance Optimization In 10 Steps for the IT Professional
SharePoint Performance Optimization In 10 Steps for the IT ProfessionalSharePoint Performance Optimization In 10 Steps for the IT Professional
SharePoint Performance Optimization In 10 Steps for the IT Professional
 
Oxalatos
OxalatosOxalatos
Oxalatos
 
Diapositivas oxalatos
Diapositivas oxalatosDiapositivas oxalatos
Diapositivas oxalatos
 
TOXICOLOGIA DE LOS ALIMENTOS
TOXICOLOGIA DE LOS ALIMENTOSTOXICOLOGIA DE LOS ALIMENTOS
TOXICOLOGIA DE LOS ALIMENTOS
 
Pescados, mariscos y sus derivados.
Pescados, mariscos y sus derivados.Pescados, mariscos y sus derivados.
Pescados, mariscos y sus derivados.
 
Toxicología de los Alimentos: Frutas y Hortalizas
Toxicología de los Alimentos: Frutas y Hortalizas Toxicología de los Alimentos: Frutas y Hortalizas
Toxicología de los Alimentos: Frutas y Hortalizas
 
Pescados y mariscos.
Pescados y mariscos.Pescados y mariscos.
Pescados y mariscos.
 
Litiasis urinaria
Litiasis urinariaLitiasis urinaria
Litiasis urinaria
 
Litiasis Renal 2010
Litiasis Renal 2010Litiasis Renal 2010
Litiasis Renal 2010
 
Litiasis renal
Litiasis renal Litiasis renal
Litiasis renal
 
Litiasis urinaria
Litiasis urinariaLitiasis urinaria
Litiasis urinaria
 
Litiasis renal
Litiasis renal Litiasis renal
Litiasis renal
 
Principales cristales en orinas
Principales cristales en orinasPrincipales cristales en orinas
Principales cristales en orinas
 

Similar to Disable http put method

SVILUPPO WEB E SICUREZZA NEL 2014
SVILUPPO WEB E SICUREZZA NEL 2014SVILUPPO WEB E SICUREZZA NEL 2014
SVILUPPO WEB E SICUREZZA NEL 2014Massimo Chirivì
 
2024 Français Patch Tuesday - Février
2024 Français Patch Tuesday - Février2024 Français Patch Tuesday - Février
2024 Français Patch Tuesday - FévrierIvanti
 
Patch Tuesday Italia Febbraio
Patch Tuesday Italia FebbraioPatch Tuesday Italia Febbraio
Patch Tuesday Italia FebbraioIvanti
 
Web Application Scanning 101
Web Application Scanning 101Web Application Scanning 101
Web Application Scanning 101Sasha Nunke
 
2024 February Patch Tuesday
2024 February Patch Tuesday2024 February Patch Tuesday
2024 February Patch TuesdayIvanti
 
Patch Tuesday de Febrero
Patch Tuesday de FebreroPatch Tuesday de Febrero
Patch Tuesday de FebreroIvanti
 
Web Application Security: The Land that Information Security Forgot
Web Application Security: The Land that Information Security ForgotWeb Application Security: The Land that Information Security Forgot
Web Application Security: The Land that Information Security ForgotJeremiah Grossman
 
Web Application Penetration Tests - Vulnerability Identification and Details ...
Web Application Penetration Tests - Vulnerability Identification and Details ...Web Application Penetration Tests - Vulnerability Identification and Details ...
Web Application Penetration Tests - Vulnerability Identification and Details ...Netsparker
 
I can provide a sample vulnerability scanning report for you based o.pdf
I can provide a sample vulnerability scanning report for you based o.pdfI can provide a sample vulnerability scanning report for you based o.pdf
I can provide a sample vulnerability scanning report for you based o.pdfallystraders
 
Patch Tuesday for January 2020
Patch Tuesday for January 2020Patch Tuesday for January 2020
Patch Tuesday for January 2020Ivanti
 
February 2018 Patch Tuesday Analysis
February 2018 Patch Tuesday AnalysisFebruary 2018 Patch Tuesday Analysis
February 2018 Patch Tuesday AnalysisIvanti
 
August Patch Tuesday Analysis
August Patch Tuesday AnalysisAugust Patch Tuesday Analysis
August Patch Tuesday AnalysisIvanti
 
How to 2FA-enable Open Source Applications
How to 2FA-enable Open Source ApplicationsHow to 2FA-enable Open Source Applications
How to 2FA-enable Open Source ApplicationsAll Things Open
 
WEB APPLICATION VULNERABILITIES: DAWN, DETECTION, EXPLOITATION AND DEFENSE
WEB APPLICATION VULNERABILITIES: DAWN, DETECTION, EXPLOITATION AND DEFENSEWEB APPLICATION VULNERABILITIES: DAWN, DETECTION, EXPLOITATION AND DEFENSE
WEB APPLICATION VULNERABILITIES: DAWN, DETECTION, EXPLOITATION AND DEFENSEAjith Kp
 
Admin Tech Ed Presentation Hardening Sql Server
Admin Tech Ed Presentation   Hardening Sql ServerAdmin Tech Ed Presentation   Hardening Sql Server
Admin Tech Ed Presentation Hardening Sql Serverrsnarayanan
 
Novell GroupWise Multiple Untrusted Pointer Dereferences Exploitation
Novell GroupWise Multiple Untrusted Pointer Dereferences ExploitationNovell GroupWise Multiple Untrusted Pointer Dereferences Exploitation
Novell GroupWise Multiple Untrusted Pointer Dereferences ExploitationHigh-Tech Bridge SA (HTBridge)
 
Cloud Security or: How I Learned to Stop Worrying & Love the Cloud
Cloud Security or: How I Learned to Stop Worrying & Love the CloudCloud Security or: How I Learned to Stop Worrying & Love the Cloud
Cloud Security or: How I Learned to Stop Worrying & Love the CloudMarkAnnati
 

Similar to Disable http put method (20)

SVILUPPO WEB E SICUREZZA NEL 2014
SVILUPPO WEB E SICUREZZA NEL 2014SVILUPPO WEB E SICUREZZA NEL 2014
SVILUPPO WEB E SICUREZZA NEL 2014
 
50679.pdf
50679.pdf50679.pdf
50679.pdf
 
2024 Français Patch Tuesday - Février
2024 Français Patch Tuesday - Février2024 Français Patch Tuesday - Février
2024 Français Patch Tuesday - Février
 
Patch Tuesday Italia Febbraio
Patch Tuesday Italia FebbraioPatch Tuesday Italia Febbraio
Patch Tuesday Italia Febbraio
 
Web Application Scanning 101
Web Application Scanning 101Web Application Scanning 101
Web Application Scanning 101
 
2024 February Patch Tuesday
2024 February Patch Tuesday2024 February Patch Tuesday
2024 February Patch Tuesday
 
Patch Tuesday de Febrero
Patch Tuesday de FebreroPatch Tuesday de Febrero
Patch Tuesday de Febrero
 
Web Application Security: The Land that Information Security Forgot
Web Application Security: The Land that Information Security ForgotWeb Application Security: The Land that Information Security Forgot
Web Application Security: The Land that Information Security Forgot
 
Dns rebinding
Dns rebindingDns rebinding
Dns rebinding
 
Web Application Penetration Tests - Vulnerability Identification and Details ...
Web Application Penetration Tests - Vulnerability Identification and Details ...Web Application Penetration Tests - Vulnerability Identification and Details ...
Web Application Penetration Tests - Vulnerability Identification and Details ...
 
4.Xss
4.Xss4.Xss
4.Xss
 
I can provide a sample vulnerability scanning report for you based o.pdf
I can provide a sample vulnerability scanning report for you based o.pdfI can provide a sample vulnerability scanning report for you based o.pdf
I can provide a sample vulnerability scanning report for you based o.pdf
 
Patch Tuesday for January 2020
Patch Tuesday for January 2020Patch Tuesday for January 2020
Patch Tuesday for January 2020
 
February 2018 Patch Tuesday Analysis
February 2018 Patch Tuesday AnalysisFebruary 2018 Patch Tuesday Analysis
February 2018 Patch Tuesday Analysis
 
August Patch Tuesday Analysis
August Patch Tuesday AnalysisAugust Patch Tuesday Analysis
August Patch Tuesday Analysis
 
How to 2FA-enable Open Source Applications
How to 2FA-enable Open Source ApplicationsHow to 2FA-enable Open Source Applications
How to 2FA-enable Open Source Applications
 
WEB APPLICATION VULNERABILITIES: DAWN, DETECTION, EXPLOITATION AND DEFENSE
WEB APPLICATION VULNERABILITIES: DAWN, DETECTION, EXPLOITATION AND DEFENSEWEB APPLICATION VULNERABILITIES: DAWN, DETECTION, EXPLOITATION AND DEFENSE
WEB APPLICATION VULNERABILITIES: DAWN, DETECTION, EXPLOITATION AND DEFENSE
 
Admin Tech Ed Presentation Hardening Sql Server
Admin Tech Ed Presentation   Hardening Sql ServerAdmin Tech Ed Presentation   Hardening Sql Server
Admin Tech Ed Presentation Hardening Sql Server
 
Novell GroupWise Multiple Untrusted Pointer Dereferences Exploitation
Novell GroupWise Multiple Untrusted Pointer Dereferences ExploitationNovell GroupWise Multiple Untrusted Pointer Dereferences Exploitation
Novell GroupWise Multiple Untrusted Pointer Dereferences Exploitation
 
Cloud Security or: How I Learned to Stop Worrying & Love the Cloud
Cloud Security or: How I Learned to Stop Worrying & Love the CloudCloud Security or: How I Learned to Stop Worrying & Love the Cloud
Cloud Security or: How I Learned to Stop Worrying & Love the Cloud
 

Disable http put method

  • 1. Disable HTTP PUT Method Go into IIS manager Right click on the website and select properties Go to the home directory tab un click write Apply IP restrictions to allow only Office users to access edit pages Open IIS Manager and navigate to the level you want to manage. For information about opening IIS Manager, see Open IIS Manager (IIS 7). For information about navigating to locations in the UI, see Navigation in IIS Manager (IIS 7). In Features View, double-click IPv4 Address and Domain Restrictions. In the Actions pane, click Add Allow Entry. In the Add Allow Restriction Rule dialog box, select Specific IPv4 address, IPv4 address range, or Domain name, add the IPv4 address, range, mask, or domain name, and then click OK Configure Anti Virus software to prevent the loading of malicious files Set cache controls http://support.microsoft.com/kb/247404 How to disable SSL v2 protocol in Windows? 2008.09.03 00:02:46 Secure Socket Layer Protocol version 2 (SSL v2) has a serious vulnerability. Successful exploitation of this vulnerability would allow an attacker to execute arbitrary code in the context of the affected server. No authentication is required to reach the vulnerable code. No user interaction is required. Since this vulnerability is in the library code used by multiple applications, the details of how an attacker would exploit it varies. In all cases, an attacker would need to specify invalid parameters as part of the SSLv2 handshake. Common Vulnerabilities and Exposures (CVE) classified the vulnerability under CVE-2004- 0120. Microsoft identified such vulnerabilities in its security bulletin MS04-011, however, until today the default configuration for Windows 2000 and Windows issam 2003 has SSL v2.0 protocol enabled. To disable SSL V2 protocol: 1.Click Start, click Run, type regedt32 or type regedit, and then click OK. 2.In Registry Editor, locate the following registry key:
  • 2. HKey_Local_MachineSystemCurrentControlSetControlSecurityProviders SCHANNELProtocolsSSL 2.0Server 3.On the Edit menu, click Add Value. 4.In the Data Type list, click DWORD. 5.In the Value Name box, type Enabled, and then click OK. Note If this value is present, double-click the value to edit its current value. 6.Type 00000000 in Binary Editor to set the value of the new key equal to "0". 7.Click OK. Disable SSL Version two http://www.sslshopper.com/article-how-to-disable-ssl-2.0-in-iis-7.html Suppress display of software versions in returned HTTP headers This can be suppressed using I I S addin urlscan ( see above)