<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>SharePoint Sharpener &#187; security</title>
	<atom:link href="http://sharepointsharpener.wordpress.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://sharepointsharpener.wordpress.com</link>
	<description>Obsessively Sharpening SharePoint</description>
	<lastBuildDate>Mon, 19 Oct 2009 21:48:56 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='sharepointsharpener.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/a13c576c6a4d38c391bc0a6d1d7261ba?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>SharePoint Sharpener &#187; security</title>
		<link>http://sharepointsharpener.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://sharepointsharpener.wordpress.com/osd.xml" title="SharePoint Sharpener" />
		<item>
		<title>Hardening Your MOSS 2007 WCM Application</title>
		<link>http://sharepointsharpener.wordpress.com/2009/02/18/hardening-your-moss-2007-wcm-application/</link>
		<comments>http://sharepointsharpener.wordpress.com/2009/02/18/hardening-your-moss-2007-wcm-application/#comments</comments>
		<pubDate>Wed, 18 Feb 2009 09:54:47 +0000</pubDate>
		<dc:creator>Thomas Sondergaard</dc:creator>
				<category><![CDATA[Configuration]]></category>
		<category><![CDATA[Optimisation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hardening]]></category>
		<category><![CDATA[installation]]></category>
		<category><![CDATA[lockdown]]></category>
		<category><![CDATA[wcm]]></category>

		<guid isPermaLink="false">http://sharepointsharpener.wordpress.com/2009/02/18/hardening-your-moss-2007-wcm-application/</guid>
		<description><![CDATA[This is a re-post of a still relevant post from my old blog at SharePointBlogs.com:
&#8212;
Today Last year at the SharePoint Conference in Berlin, Ben Robb of cScape Ltd gave a talk about configuring internet-facing web sites running MOSS 2007/WCM.
He brought up some interesting points about securing the application against unauthorised content editing and attacks from [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=88&subd=sharepointsharpener&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This is a re-post of a still relevant post from my old blog at SharePointBlogs.com:
<p>&#8212;
<p><strike>Today</strike> Last year at the SharePoint Conference in Berlin, Ben Robb of cScape Ltd gave a talk about configuring internet-facing web sites running MOSS 2007/WCM.
<p>He brought up some interesting points about securing the application against unauthorised content editing and attacks from hackers.
<p>Make sure your installation check list contains a least the following items:
<p><strong>1. Enable firewalls and standard network security</strong><br />Fairly standard stuff, but necessary all the same.
<p><strong>2. Disable SMTP and incoming mail</strong><br />In essence, you shouldn&#8217;t be running services on the server that aren&#8217;t necessary for MOSS. Also, close any ports that MOSS doesn&#8217;t need.
<p><strong>3. Secure the Central Administration site</strong><br />Surprisingly, it is very common to leave this entry point wide open. The admin site should be accessible only via an SSL connection .
<p><strong>4. Use lockdown mode<br /></strong>Use this stsadm command to activate lockdown mode:<br />stsadm –o activatefeature –url &lt;url&gt; -filename ViewFormPagesLockdown\feature.xml<br /><a href="http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/">Read more</a> about ViewFormPagesLockdown.
<p><strong>5. Restricted reader role</strong><br />The anonymous user should have a restricted reader role which only enables viewing of pages, documents and images.
<p><strong>6. Policies<br /></strong>Constrain the maximum access per web application and deny all write access via <a href="http://sitename:80">http://sitename:80</a>.
<p><strong>7. Content deployment</strong><br />Use different servers for authoring and the actual internet-facing web application. Content generated on the authoring server (typically within the intranet) should be pushed out to the public site using scheduled content deployment jobs.
<p>&#8230;
<p>To many administrators the above bullets merely point out the obvious and do feel free to leave comments if you have any additions to the list.
<p>Thanks to Ben Robb for providing 99% of the info for this post.</p>
  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointsharpener.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointsharpener.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointsharpener.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointsharpener.wordpress.com/88/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointsharpener.wordpress.com/88/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointsharpener.wordpress.com/88/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=88&subd=sharepointsharpener&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointsharpener.wordpress.com/2009/02/18/hardening-your-moss-2007-wcm-application/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0dfb315d39c37443371df076767fa665?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thomassondergaard</media:title>
		</media:content>
	</item>
		<item>
		<title>Enabling Anonymous Access on an Internet-Facing MOSS Portal</title>
		<link>http://sharepointsharpener.wordpress.com/2008/08/28/enabling-anonymous-access-on-an-internet-facing-moss-portal/</link>
		<comments>http://sharepointsharpener.wordpress.com/2008/08/28/enabling-anonymous-access-on-an-internet-facing-moss-portal/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 11:39:16 +0000</pubDate>
		<dc:creator>Thomas Sondergaard</dc:creator>
				<category><![CDATA[Configuration]]></category>
		<category><![CDATA[anonymous access]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[central administration]]></category>
		<category><![CDATA[permissions]]></category>
		<category><![CDATA[publishing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wcm]]></category>

		<guid isPermaLink="false">http://sharepointsharpener.wordpress.com/2008/08/28/enabling-anonymous-access-on-an-internet-facing-moss-portal/</guid>
		<description><![CDATA[If you are using the publishing features of SharePoint on an internet-facing portal, you probably need to enable anonymous access.
It&#8217;s a quick two-step process:
&#160;
A. Edit Authentication Providers

Go to Central Administration and then Application Management.
Under SharePoint Web Application Management click Web application list.
Select the web application on which you want to enable anonymous access.
Under Application Security [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=54&subd=sharepointsharpener&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>If you are using the publishing features of SharePoint on an internet-facing portal, you probably need to enable anonymous access.</p>
<p>It&#8217;s a quick two-step process:</p>
<p><strong></strong>&nbsp;</p>
<p><strong>A. Edit Authentication Providers</strong></p>
<ol>
<li>Go to <em>Central Administration</em> and then <em>Application Management</em>.
<li>Under <em>SharePoint Web Application Management</em> click <em>Web application list</em>.
<li>Select the web application on which you want to enable anonymous access.
<li>Under <em>Application Security</em> select <em>Authentication providers</em>.
<li>Click the zone you want edit (probably <em>Default</em>).
<li>Check the box <em>Enable anonymous access</em> and click <em>Save</em>:</p>
<p><img style="border-width:0;" height="111" alt="image" src="http://sharepointsharpener.files.wordpress.com/2008/08/image7.png?w=548&#038;h=111" width="548" border="0"></li>
</ol>
<p>&nbsp;</p>
<p><strong>B. Enable Anonymous Access at Site Collection Level</strong></p>
<ol>
<li>Go back to your site and go to <em>Site</em> Settings &#8211; at site collection level.
<li>Under <em>Users and Permissions</em> click <em>Advanced permissions</em>.
<li>In the <em>Settings</em> drop-down menu select <em>Anonymous Access</em>.
<li>Click <em>Entire Web site</em> (or whatever applies to your setup) and click <em>OK</em>:</p>
<p><img style="border-width:0;" height="109" alt="image" src="http://sharepointsharpener.files.wordpress.com/2008/08/image8.png?w=586&#038;h=109" width="586" border="0"> </li>
</ol>
<p>&nbsp;</p>
<p>Remember, <a href="http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/">hardening your internet-facing MOSS installation</a> is essential to shield your portal against intruders.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointsharpener.wordpress.com/54/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointsharpener.wordpress.com/54/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointsharpener.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointsharpener.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointsharpener.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointsharpener.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointsharpener.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointsharpener.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointsharpener.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointsharpener.wordpress.com/54/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointsharpener.wordpress.com/54/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointsharpener.wordpress.com/54/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=54&subd=sharepointsharpener&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointsharpener.wordpress.com/2008/08/28/enabling-anonymous-access-on-an-internet-facing-moss-portal/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0dfb315d39c37443371df076767fa665?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thomassondergaard</media:title>
		</media:content>

		<media:content url="http://sharepointsharpener.files.wordpress.com/2008/08/image7.png" medium="image">
			<media:title type="html">image</media:title>
		</media:content>

		<media:content url="http://sharepointsharpener.files.wordpress.com/2008/08/image8.png" medium="image">
			<media:title type="html">image</media:title>
		</media:content>
	</item>
		<item>
		<title>ViewFormPagesLockDown Does not Kick In</title>
		<link>http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/</link>
		<comments>http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/#comments</comments>
		<pubDate>Thu, 28 Aug 2008 09:59:14 +0000</pubDate>
		<dc:creator>Thomas Sondergaard</dc:creator>
				<category><![CDATA[Configuration]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[feature]]></category>
		<category><![CDATA[lockdown]]></category>
		<category><![CDATA[publishing]]></category>
		<category><![CDATA[stsadm]]></category>
		<category><![CDATA[wcm]]></category>

		<guid isPermaLink="false">http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/</guid>
		<description><![CDATA[Hardening your internet-facing MOSS installation is essential to avoid attacks. Check out Microsoft&#8217;s excellent guide which takes you through most of the steps required to shield your portal against intruders.
However, if your portal wasn&#8217;t born as a publishing portal, all anonymous users will have access to AllItems.aspx, DispForm.aspx and other pages that you probably don&#8217;t [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=56&subd=sharepointsharpener&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Hardening your internet-facing MOSS installation is essential to avoid attacks. Check out Microsoft&#8217;s <a href="http://technet.microsoft.com/en-us/library/cc263468.aspx" target="_blank">excellent guide</a> which takes you through most of the steps required to shield your portal against intruders.</p>
<p>However, if your portal wasn&#8217;t born as a publishing portal, all anonymous users will have access to AllItems.aspx, DispForm.aspx and other pages that you probably don&#8217;t want outside users to see. For instance, you may have created a newsletter signup web part which posts data to a list (using <a href="http://sharepointsharpener.wordpress.com/2008/08/27/elevation-run-code-as-an-administrator/">elevation</a>). In time, the list fills up with more or less sensitive information about your newsletter subscribers and you probably don&#8217;t want this information to end up in the wrong hands.</p>
<p>Unfortunately, it is quite easy for someone with just a litte SharePoint experience to guess the path to e.g. the AllItems.aspx page of a SharePoint list:</p>
<p>&nbsp;<img style="border-width:0;" height="62" alt="image" src="http://sharepointsharpener.files.wordpress.com/2008/08/image9.png?w=460&#038;h=62" width="460" border="0">&nbsp; </p>
<p>And if your portal is not locked down, all list items will be there for the taking.</p>
<p>&nbsp;</p>
<p><strong>ViewFormPagesLockDown</strong></p>
<p>Stsadm comes to the rescue yet again. To activate the lockdown, simply run this stsadm command:</p>
<p><em>stsadm -o activatefeature -url &lt;site collection url&gt; -filename ViewFormPagesLockDown\feature.xml</em></p>
<p>If you get the &#8220;Operation completed successfully&#8221;-message, you&#8217;re in business.</p>
<p>Well, almost&#8230;</p>
<p>&nbsp;</p>
<p><strong>The final step</strong></p>
<p>You&#8217;ll probably find that the new feature still hasn&#8217;t kicked in. Fear not, you simply need to deactivate and <a href="http://sharepointsharpener.wordpress.com/2008/08/28/enabling-anonymous-access-on-an-internet-facing-moss-portal/">reactivate anonymous access</a> on the portal.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/sharepointsharpener.wordpress.com/56/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/sharepointsharpener.wordpress.com/56/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/sharepointsharpener.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/sharepointsharpener.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/sharepointsharpener.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/sharepointsharpener.wordpress.com/56/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/sharepointsharpener.wordpress.com/56/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/sharepointsharpener.wordpress.com/56/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=sharepointsharpener.wordpress.com&blog=4068218&post=56&subd=sharepointsharpener&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://sharepointsharpener.wordpress.com/2008/08/28/viewformpageslockdown-does-not-kick-in/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0dfb315d39c37443371df076767fa665?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">thomassondergaard</media:title>
		</media:content>

		<media:content url="http://sharepointsharpener.files.wordpress.com/2008/08/image9.png" medium="image">
			<media:title type="html">image</media:title>
		</media:content>
	</item>
	</channel>
</rss>