SlideShare a Scribd company logo
Server Tier
Security of the server, the frameworks and web content.
Types Of Concerns
Server Patching
Default Features
Extra Applications
Old Code And Backups
Server Patching
Front-end and back-end servers must be fully patched.
Default Features
Some web servers may come with default functionalities, which may
need to be removed or restricted to authorized personal only.
Tomcat - /manager, etc.
JBoss - /jmx-console, etc.
Apache - /server-status, etc.
Extra Applications
Default server installations may come with built-in applications.
PhpMyAdmin, Django Admin, etc.
Old Code And Backups
There could be old code and backups inside the application root folder.
File prefixes: ~, ., etc.
File suffixes: ~, .bck, .bac, .back, .tar.gz, tar.bz2, etc.
Lab
Let's see if we can find some of these problems.

More Related Content

Viewers also liked (13)

PPT
Chapter14 Windows Server 2003 Security Features
Raja Waseem Akhtar
 
PDF
Web Server Security Guidelines
webhostingguy
 
KEY
SQL Server: Security
LearnNowOnline
 
PPTX
Web Server Web Site Security
Steven Cahill
 
PPTX
Server Virtualization
Siddharth Bhatt
 
PDF
Server Virtualization
rjain51
 
PPTX
Client server security threats
rahul kundu
 
PPTX
Introduction to Computer Networking
Amit Saha
 
PPTX
Basic Server PPT (THDC)
Vineet Pokhriyal
 
PPTX
Virtualization 101: Everything You Need To Know To Get Started With VMware
Datapath Consulting
 
PPSX
Server Virtualization Concepts & Features
Ragesh R Nair
 
PPT
Basic concepts of computer Networking
Hj Habib
 
Chapter14 Windows Server 2003 Security Features
Raja Waseem Akhtar
 
Web Server Security Guidelines
webhostingguy
 
SQL Server: Security
LearnNowOnline
 
Web Server Web Site Security
Steven Cahill
 
Server Virtualization
Siddharth Bhatt
 
Server Virtualization
rjain51
 
Client server security threats
rahul kundu
 
Introduction to Computer Networking
Amit Saha
 
Basic Server PPT (THDC)
Vineet Pokhriyal
 
Virtualization 101: Everything You Need To Know To Get Started With VMware
Datapath Consulting
 
Server Virtualization Concepts & Features
Ragesh R Nair
 
Basic concepts of computer Networking
Hj Habib
 

Similar to Web Application Security 101 - 10 Server Tier (20)

PPTX
The Enemy Within: Organizational Insight Through the Eyes of a Webserver
Ramece Cave
 
PPT
web-servers3952 (1)qwjelkjqwlkjkqlwe.ppt
20521742
 
KEY
Apache Wizardry - Ohio Linux 2011
Rich Bowen
 
ODP
Application server
nava rathna
 
PPT
Web servers
webhostingguy
 
PDF
Webappcontrol for Information Technology
tiwariparivaar24
 
PPT
Web Hacking
Information Technology
 
PPTX
A Closer Look on C&C Panels
Tandhy Simanjuntak
 
PDF
Web Server Types - Understanding a Web Server
Cloudtechtiq
 
PDF
How to Use NDS eDirectory to Secure Apache Web Server for NetWare
webhostingguy
 
PDF
Oracle Fusion Middleware Infrastructure Best Practices
Revelation Technologies
 
PPTX
Hardening Enterprise Apache
guestd9aa5
 
PPTX
Apache error
Rishabh Bahukhandi
 
PDF
Puppet for Sys Admins
Puppet
 
PDF
Protecting TYPO3 With Suhosin And Modsecurity
Xavier Perseguers
 
PDF
Symfony quick tour_2.3
Frédéric Delorme
 
PDF
PowerPoint Presentation
webhostingguy
 
PPTX
Recommended Software and Modifications for Server Security
HTS Hosting
 
PPTX
Servlets
Rajkiran Mummadi
 
PPTX
Open Source Security
Sander Temme
 
The Enemy Within: Organizational Insight Through the Eyes of a Webserver
Ramece Cave
 
web-servers3952 (1)qwjelkjqwlkjkqlwe.ppt
20521742
 
Apache Wizardry - Ohio Linux 2011
Rich Bowen
 
Application server
nava rathna
 
Web servers
webhostingguy
 
Webappcontrol for Information Technology
tiwariparivaar24
 
A Closer Look on C&C Panels
Tandhy Simanjuntak
 
Web Server Types - Understanding a Web Server
Cloudtechtiq
 
How to Use NDS eDirectory to Secure Apache Web Server for NetWare
webhostingguy
 
Oracle Fusion Middleware Infrastructure Best Practices
Revelation Technologies
 
Hardening Enterprise Apache
guestd9aa5
 
Apache error
Rishabh Bahukhandi
 
Puppet for Sys Admins
Puppet
 
Protecting TYPO3 With Suhosin And Modsecurity
Xavier Perseguers
 
Symfony quick tour_2.3
Frédéric Delorme
 
PowerPoint Presentation
webhostingguy
 
Recommended Software and Modifications for Server Security
HTS Hosting
 
Open Source Security
Sander Temme
 
Ad

More from Websecurify (12)

PDF
Security Challenges in Node.js
Websecurify
 
PDF
Secure Coding - Web Application Security Vulnerabilities and Best Practices
Websecurify
 
PDF
Unicode - Hacking The International Character System
Websecurify
 
PDF
Next Generation of Web Application Security Tools
Websecurify
 
PDF
Web Application Security 101 - 14 Data Validation
Websecurify
 
PDF
Web Application Security 101 - 12 Logging
Websecurify
 
PDF
Web Application Security 101 - 07 Session Management
Websecurify
 
PDF
Web Application Security 101 - 06 Authentication
Websecurify
 
PDF
Web Application Security 101 - 05 Enumeration
Websecurify
 
PDF
Web Application Security 101 - 04 Testing Methodology
Websecurify
 
PDF
Web Application Security 101 - 03 Web Security Toolkit
Websecurify
 
PDF
Web Application Security 101 - 02 The Basics
Websecurify
 
Security Challenges in Node.js
Websecurify
 
Secure Coding - Web Application Security Vulnerabilities and Best Practices
Websecurify
 
Unicode - Hacking The International Character System
Websecurify
 
Next Generation of Web Application Security Tools
Websecurify
 
Web Application Security 101 - 14 Data Validation
Websecurify
 
Web Application Security 101 - 12 Logging
Websecurify
 
Web Application Security 101 - 07 Session Management
Websecurify
 
Web Application Security 101 - 06 Authentication
Websecurify
 
Web Application Security 101 - 05 Enumeration
Websecurify
 
Web Application Security 101 - 04 Testing Methodology
Websecurify
 
Web Application Security 101 - 03 Web Security Toolkit
Websecurify
 
Web Application Security 101 - 02 The Basics
Websecurify
 
Ad

Recently uploaded (20)

PDF
Linux Certificate of Completion - LabEx Certificate
VICTOR MAESTRE RAMIREZ
 
PPTX
Why Businesses Are Switching to Open Source Alternatives to Crystal Reports.pptx
Varsha Nayak
 
PPTX
MailsDaddy Outlook OST to PST converter.pptx
abhishekdutt366
 
PPTX
Agentic Automation Journey Session 1/5: Context Grounding and Autopilot for E...
klpathrudu
 
PDF
Why Businesses Are Switching to Open Source Alternatives to Crystal Reports.pdf
Varsha Nayak
 
PPTX
Human Resources Information System (HRIS)
Amity University, Patna
 
PDF
유니티에서 Burst Compiler+ThreadedJobs+SIMD 적용사례
Seongdae Kim
 
PDF
GetOnCRM Speeds Up Agentforce 3 Deployment for Enterprise AI Wins.pdf
GetOnCRM Solutions
 
PPTX
Comprehensive Guide: Shoviv Exchange to Office 365 Migration Tool 2025
Shoviv Software
 
PPTX
Feb 2021 Cohesity first pitch presentation.pptx
enginsayin1
 
PDF
Automate Cybersecurity Tasks with Python
VICTOR MAESTRE RAMIREZ
 
PDF
iTop VPN With Crack Lifetime Activation Key-CODE
utfefguu
 
PDF
Beyond Binaries: Understanding Diversity and Allyship in a Global Workplace -...
Imma Valls Bernaus
 
PDF
Mobile CMMS Solutions Empowering the Frontline Workforce
CryotosCMMSSoftware
 
PPTX
Engineering the Java Web Application (MVC)
abhishekoza1981
 
PDF
vMix Pro 28.0.0.42 Download vMix Registration key Bundle
kulindacore
 
PDF
Understanding the Need for Systemic Change in Open Source Through Intersectio...
Imma Valls Bernaus
 
PDF
Digger Solo: Semantic search and maps for your local files
seanpedersen96
 
PDF
Build It, Buy It, or Already Got It? Make Smarter Martech Decisions
bbedford2
 
PDF
Alexander Marshalov - How to use AI Assistants with your Monitoring system Q2...
VictoriaMetrics
 
Linux Certificate of Completion - LabEx Certificate
VICTOR MAESTRE RAMIREZ
 
Why Businesses Are Switching to Open Source Alternatives to Crystal Reports.pptx
Varsha Nayak
 
MailsDaddy Outlook OST to PST converter.pptx
abhishekdutt366
 
Agentic Automation Journey Session 1/5: Context Grounding and Autopilot for E...
klpathrudu
 
Why Businesses Are Switching to Open Source Alternatives to Crystal Reports.pdf
Varsha Nayak
 
Human Resources Information System (HRIS)
Amity University, Patna
 
유니티에서 Burst Compiler+ThreadedJobs+SIMD 적용사례
Seongdae Kim
 
GetOnCRM Speeds Up Agentforce 3 Deployment for Enterprise AI Wins.pdf
GetOnCRM Solutions
 
Comprehensive Guide: Shoviv Exchange to Office 365 Migration Tool 2025
Shoviv Software
 
Feb 2021 Cohesity first pitch presentation.pptx
enginsayin1
 
Automate Cybersecurity Tasks with Python
VICTOR MAESTRE RAMIREZ
 
iTop VPN With Crack Lifetime Activation Key-CODE
utfefguu
 
Beyond Binaries: Understanding Diversity and Allyship in a Global Workplace -...
Imma Valls Bernaus
 
Mobile CMMS Solutions Empowering the Frontline Workforce
CryotosCMMSSoftware
 
Engineering the Java Web Application (MVC)
abhishekoza1981
 
vMix Pro 28.0.0.42 Download vMix Registration key Bundle
kulindacore
 
Understanding the Need for Systemic Change in Open Source Through Intersectio...
Imma Valls Bernaus
 
Digger Solo: Semantic search and maps for your local files
seanpedersen96
 
Build It, Buy It, or Already Got It? Make Smarter Martech Decisions
bbedford2
 
Alexander Marshalov - How to use AI Assistants with your Monitoring system Q2...
VictoriaMetrics
 

Web Application Security 101 - 10 Server Tier