Special OPS: Host and Network Security for Microsoft, UNIX, and Oracle

Chapter 11: Hacking Custom Web Applications
Chapter 12: Attacking and Defending Microsoft SQL Server
Chapter 13: Attacking and Defending Oracle
An intranet Web site is a private portal providing a means of publishing and accessing company information. But because it is connected to a wealth of corporate information, it is also a key target for insider hackers. The threats facing an internal Internet Information Services (IIS) server are unique and sometimes greater than those threats coming from outside attacks. This chapter demonstrates how to build an intranet IIS server that can address the unique threats exposed by those hackers coming from behind the firewall.
An internal IIS server has many unique vulnerabilities and exposures that an outside Web server may not have. The greatest weakness is that the attackers are coming from the same network and therefore have access to many additional attacks. Further, the insiders have access to information that outsiders simply do not have. The insider may already know about the network structure, what security measures are in place, and may even pass the IIS server on the way to the water cooler every day. Insiders already have some trusted access to the network and do not need to be concerned with penetrating the firewall. Insider hackers may be able to sniff traffic on the internal network and perhaps have the great advantage of gaining physical access to the server itself. As an employee or contractor, the insider may also be able...