<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>SharePoint Sharpener &#187; lockdown</title>
	<atom:link href="http://sharepointsharpener.wordpress.com/tag/lockdown/feed/" rel="self" type="application/rss+xml" />
	<link>http://sharepointsharpener.wordpress.com</link>
	<description>Obsessively Sharpening SharePoint</description>
	<lastBuildDate>Mon, 19 Oct 2009 21:48:56 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='sharepointsharpener.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/a13c576c6a4d38c391bc0a6d1d7261ba?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>SharePoint Sharpener &#187; lockdown</title>
		<link>http://sharepointsharpener.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://sharepointsharpener.wordpress.com/osd.xml" title="SharePoint Sharpener" />
		<item>
		<title>Hardening Your MOSS 2007 WCM Application</title>
		<link>http://sharepointsharpener.wordpress.com/2009/02/18/hardening-your-moss-2007-wcm-application/</link>
		<comments>http://sharepointsharpener.wordpress.com/2009/02/18/hardening-your-moss-2007-wcm-application/#comments</comments>
		<pubDate>Wed, 18 Feb 2009 09:54:47 +0000</pubDate>
		<dc:creator>Thomas Sondergaard</dc:creator>
				<category><![CDATA[Configuration]]></category>
		<category><![CDATA[Optimisation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hardening]]></category>
		<category><![CDATA[installation]]></category>
		<category><![CDATA[lockdown]]></category>
		<category><![CDATA[wcm]]></category>

		<guid isPermaLink="false">http://sharepointsharpener.wordpress.com/2009/02/18/hardening-your-moss-2007-wcm-application/</guid>
		<description><![CDATA[This is a re-post of a still relevant post from my old blog at SharePointBlogs.com:
&#8212;
Today Last year at the SharePoint Conference in Berlin, Ben Robb of cScape Ltd gave a talk about configuring internet-facing web sites running MOSS 2007/WCM.
He brought up some interesting points about securing the application against unauthorised content editing and attacks from [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=88&subd=sharepointsharpener&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This is a re-post of a still relevant post from my old blog at SharePointBlogs.com:
<p>&#8212;
<p><strike>Today</strike> Last year at the SharePoint Conference in Berlin, Ben Robb of cScape Ltd gave a talk about configuring internet-facing web sites running MOSS 2007/WCM.
<p>He brought up some interesting points about securing the application against unauthorised content editing and attacks from hackers.
<p>Make sure your installation check list contains a least the following items:
<p><strong>1. Enable firewalls and standard network security</strong><br />Fairly standard stuff, but necessary all the same.
<p><strong>2. Disable SMTP and incoming mail</strong><br />In essence, you shouldn&#8217;t be running services on the server that aren&#8217;t necessary for MOSS. Also, close any ports that MOSS doesn&#8217;t need.
<p><strong>3. Secure the Central Administration site</strong><br />Surprisingly, it is very common to leave this entry point wide open. The admin site should be accessible only via an SSL connection .
<p><strong>4. Use lockdown mode<br /></strong>Use this stsadm command to activate lockdown mode:<br />stsadm –o activatefeature –url &lt;url&gt; -filename ViewFormPagesLockdown\feature.xml<br /><a href="http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/">Read more</a> about ViewFormPagesLockdown.
<p><strong>5. Restricted reader role</strong><br />The anonymous user should have a restricted reader role which only enables viewing of pages, documents and images.
<p><strong>6. Policies<br /></strong>Constrain the maximum access per web application and deny all write access via <a href="http://sitename:80">http://sitename:80</a>.
<p><strong>7. Content deployment</strong><br />Use different servers for authoring and the actual internet-facing web application. Content generated on the authoring server (typically within the intranet) should be pushed out to the public site using scheduled content deployment jobs.
<p>&#8230;
<p>To many administrators the above bullets merely point out the obvious and do feel free to leave comments if you have any additions to the list.
<p>Thanks to Ben Robb for providing 99% of the info for this post.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointsharpener.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointsharpener.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointsharpener.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointsharpener.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointsharpener.wordpress.com/88/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=88&subd=sharepointsharpener&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointsharpener.wordpress.com/2009/02/18/hardening-your-moss-2007-wcm-application/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0dfb315d39c37443371df076767fa665?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thomassondergaard</media:title>
		</media:content>
	</item>
		<item>
		<title>ViewFormPagesLockDown Does not Kick In</title>
		<link>http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/</link>
		<comments>http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 09:59:14 +0000</pubDate>
		<dc:creator>Thomas Sondergaard</dc:creator>
				<category><![CDATA[Configuration]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[feature]]></category>
		<category><![CDATA[lockdown]]></category>
		<category><![CDATA[publishing]]></category>
		<category><![CDATA[stsadm]]></category>
		<category><![CDATA[wcm]]></category>

		<guid isPermaLink="false">http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/</guid>
		<description><![CDATA[Hardening your internet-facing MOSS installation is essential to avoid attacks. Check out Microsoft&#8217;s excellent guide which takes you through most of the steps required to shield your portal against intruders.
However, if your portal wasn&#8217;t born as a publishing portal, all anonymous users will have access to AllItems.aspx, DispForm.aspx and other pages that you probably don&#8217;t [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=56&subd=sharepointsharpener&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Hardening your internet-facing MOSS installation is essential to avoid attacks. Check out Microsoft&#8217;s <a href="http://technet.microsoft.com/en-us/library/cc263468.aspx" target="_blank">excellent guide</a> which takes you through most of the steps required to shield your portal against intruders.</p>
<p>However, if your portal wasn&#8217;t born as a publishing portal, all anonymous users will have access to AllItems.aspx, DispForm.aspx and other pages that you probably don&#8217;t want outside users to see. For instance, you may have created a newsletter signup web part which posts data to a list (using <a href="http://sharepointsharpener.wordpress.com/2008/08/27/elevation-run-code-as-an-administrator/">elevation</a>). In time, the list fills up with more or less sensitive information about your newsletter subscribers and you probably don&#8217;t want this information to end up in the wrong hands.</p>
<p>Unfortunately, it is quite easy for someone with just a litte SharePoint experience to guess the path to e.g. the AllItems.aspx page of a SharePoint list:</p>
<p>&nbsp;<img style="border-width:0;" height="62" alt="image" src="http://sharepointsharpener.files.wordpress.com/2008/08/image9.png?w=460&#038;h=62" width="460" border="0">&nbsp; </p>
<p>And if your portal is not locked down, all list items will be there for the taking.</p>
<p>&nbsp;</p>
<p><strong>ViewFormPagesLockDown</strong></p>
<p>Stsadm comes to the rescue yet again. To activate the lockdown, simply run this stsadm command:</p>
<p><em>stsadm -o activatefeature -url &lt;site collection url&gt; -filename ViewFormPagesLockDown\feature.xml</em></p>
<p>If you get the &#8220;Operation completed successfully&#8221;-message, you&#8217;re in business.</p>
<p>Well, almost&#8230;</p>
<p>&nbsp;</p>
<p><strong>The final step</strong></p>
<p>You&#8217;ll probably find that the new feature still hasn&#8217;t kicked in. Fear not, you simply need to deactivate and <a href="http://sharepointsharpener.wordpress.com/2008/08/28/enabling-anonymous-access-on-an-internet-facing-moss-portal/">reactivate anonymous access</a> on the portal.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointsharpener.wordpress.com/56/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointsharpener.wordpress.com/56/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointsharpener.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointsharpener.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointsharpener.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointsharpener.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointsharpener.wordpress.com/56/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=56&subd=sharepointsharpener&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0dfb315d39c37443371df076767fa665?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thomassondergaard</media:title>
		</media:content>

		<media:content url="http://sharepointsharpener.files.wordpress.com/2008/08/image9.png" medium="image">
			<media:title type="html">image</media:title>
		</media:content>
	</item>
	</channel>
</rss>