IIS Lockdown Wizard 2.1

From: Liss, John (lissj@COMMERCEPATH.COM)
Date: 12/18/01


Date:         Tue, 18 Dec 2001 09:37:48 -0800
From: "Liss, John" <lissj@COMMERCEPATH.COM>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

For all the IIS nuts out there that love tools to lock things down. MS Has
released a new flavor of their IIS Lockdown tool. Though I haven't tested
it yet, it appears that they took the URLScanner and squashed it into to it,
as well as giving some templates for the major IIS-dependent products.

I have heard, (have not tested) that you do need to apply the (now regular)
hot fixes after you have applied the IIS Lockdown wizard fixes.
You can download the wizard from Microsoft's Web site.
http://www.microsoft.com/downloads/release.asp?releaseid=33961
More info:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
tools/locktool.asp
and of course the good old check list pages:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
tools/tools.asp

============================================================================
Delivery co-sponsored by VeriSign - The Internet Trust Company
============================================================================
Protect your servers with 128-bit SSL encryption!
Get VeriSign's FREE guide, "Securing Your Web Site for Business." You will
learn everything you need to know about using SSL to encrypt your e-commerce
transactions for serious online security. Click here!
http://www.verisign.com/cgi-bin/go.cgi?a=n016065650057000
============================================================================



Relevant Pages

  • Re: VS.NET - IIS Lockdown
    ... I feel the main concern here is what whether IIS Lockdown tool can bring ... setup wrongly in IIS server. ... So I feel you can install IIS Lockdown tool and test it. ... Microsoft Mobile Information Server: ...
    (microsoft.public.vsnet.general)
  • RE: MS IIS Lockdown tool
    ... Well I used it and it broke OWA:) So now I have to figure out what OWA ... > Subject: MS IIS Lockdown tool ... that email messages will be free of errors or viruses. ...
    (Security-Basics)
  • Re: IIS Lockdown
    ... IIS Lockdown Tool. ... in the IIS Lockdown Tool, which might help you determine which options you ... Install and Use the IIS Lockdown Wizard ... Is there a particular reason why you want the functionality of the Lockdown ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS Hack : Anyone explain cause...
    ... I have no idea what "IIS Lockdown" tool from 1997-98 you are referring to. ... The IIS Lockdown tool that you just downloaded is the one that just about ... on IIS4 here which for instance does not have a devent rollback system ...
    (microsoft.public.inetserver.iis)
  • Re: IIS Lockdown tool Problem with Setup and Help is needed
    ... Leif, ... logs the logs wasn't there. ... >> I am running IIS Lockdown tool on SBS2k and I don't get any configuration ... Why doesn't the IIS lockdown tool give me option to lock ...
    (microsoft.public.exchange2000.general)