#FIG 3.2 Landscape Center Inches Letter 100.00 Single -2 1200 2 0 37 #e12d2f 0 38 #080808 0 39 #0a8d0a 2 1 0 1 37 37 100 0 -1 0.000 0 0 -1 0 0 4 7200 2700 7500 3000 7500 4200 7200 4500 2 1 0 1 37 37 100 0 -1 0.000 0 0 -1 0 0 4 7200 7500 7500 7800 7500 9000 7200 9300 4 0 0 100 0 2 24 0.0000 4 330 10395 1500 900 Components of a web-based service, vulnerabilities and defenses\001 4 0 0 100 0 2 16 0.0000 4 225 2385 600 3000 Application programs\001 4 0 0 100 0 2 16 0.0000 4 225 1965 600 4200 CGI programs and\001 4 0 0 100 0 2 16 0.0000 4 165 2130 675 4425 Web server modules\001 4 0 37 100 0 3 16 0.0000 4 210 2715 4200 3000 Buffer overflows and other\001 4 0 37 100 0 3 16 0.0000 4 210 2025 4200 3285 programming errors\001 4 0 37 100 0 3 16 0.0000 4 210 2385 4200 4200 Bugs, misconfiguration\001 4 0 37 100 0 3 16 0.0000 4 165 1650 4200 1800 Various attacks!\001 4 0 38 100 0 0 16 0.0000 4 225 2550 7800 1800 Keep system well patched\001 4 0 38 100 0 0 16 0.0000 4 225 3015 7800 2085 Monitor file integrity and logs\001 4 0 0 100 0 2 16 0.0000 4 165 915 600 6600 Network\001 4 0 0 100 0 2 16 0.0000 4 165 855 600 7800 Browser\001 4 0 37 100 0 3 16 0.0000 4 210 1935 4200 6600 Sniffing, hijacking\001 4 0 37 100 0 3 16 0.0000 4 210 2775 4200 9000 Malware, misconfiguration\001 4 0 37 100 0 3 16 0.0000 4 210 2385 4200 7800 Bugs, misconfiguration\001 4 0 38 100 0 0 16 0.0000 4 225 3090 7800 3900 Careful programming practices\001 4 0 38 100 0 0 16 0.0000 4 225 3000 7800 3600 Use cgiwrap to isolate damage\001 4 0 38 100 0 0 16 0.0000 4 225 3105 7800 5700 and is now fairly stable; section\001 4 0 38 100 0 0 16 0.0000 4 225 2895 7800 5985 that runs as root is very small\001 4 0 38 100 0 0 16 0.0000 4 225 2115 7800 6600 Use encryption (SSL)\001 4 0 38 100 0 0 16 0.0000 4 225 2520 7800 8400 Outside scope of my task\001 4 0 0 100 0 2 16 0.0000 4 165 1185 600 1800 Server host\001 4 0 0 100 0 2 16 0.0000 4 165 1155 600 9000 Client host\001 4 0 0 100 0 2 16 0.0000 4 165 2175 600 5400 Web server software\001 4 0 37 100 0 3 16 0.0000 4 210 2385 4200 5400 Bugs, misconfiguration\001 4 0 38 100 0 0 16 0.0000 4 225 3345 7800 5400 Apache runs mostly as "web user"\001