Special OPS: Host and Network Security for Microsoft, UNIX, and Oracle

Chapter 10: Securing IIS
Chapter 12: Attacking and Defending Microsoft SQL Server
Chapter 13: Attacking and Defending Oracle
Despite the comments of doomsayers worldwide, the last few years have seen an overall increase in information security awareness. The recent surge in worldwide security awareness has provided many IT departments with more resources. This surge has increased the overall state of computer security by allowing IT departments to sharpen their focus and gain a deeper understanding of the daily tasks required to effectively combat this constantly evolving adversary. Traditional avenues of attack have been battened down and most administrators are maintaining patch levels and subscribing to vendor alerts. Organizations have long since realized the need for firewalls and Intrusion Detection Systems (IDSs), default installations are more secure, and even the "greenest" of systems administrators realize the danger of running production servers with unneeded services or without vendor-issued patches. So what is the next frontier for attackers? The answer is custom written Web applications.
As the technical aptitude of the staff increases in your organization, so will the demand for greater application flexibility. This demand can be solved in two ways build or buy. Some shrink-wrapped solutions are functionally rigid; others are so complex in functionality they cease to be useful. The solution for many organizations is homegrown applications. Creating intranet Web applications that are "just right" can solve many headaches for administrators and staff alike. Intranet servers are littered with applications and applets used by internal staff. This...