Re: Yet another IIS compromise

From: Bronek Kozicki (brok_at_rubikon.pl)
Date: 07/18/01


> The most effective way to limit your risk here is to open up the mmc and
> verify all of the websites do not have the (all unassigned) setting in
> the ip address. By default Microsoft configures the default site with
> all unassinged.

Hello,

here are my 0.02 EU:

1. never, ever run default web site in production environment
2. you may examine _exactly_ how W3SVC is configured using metaedit, which
can be downloaded from
http://support.microsoft.com/support/kb/articles/q232/0/68.asp ;
documentation of metabase values can be found in Platform SDK. It's also
usefull for quick metabase backup.
3. I though that W3SVC will always bind to all IP configured addresses;
however, I was wrong. It's default behaviour, which can be changed in
metabase; visit
http://support.microsoft.com/support/kb/articles/Q238/1/31.ASP . You may
also want to read articles Q300509 and Q300238
4. in case you do not want to edit metabase (it can be dangerous, similary
to editing registry) you may just firewall unneeded IP addresses. If you do
not have external firewall, you may use IPSec policies for this purpose.

Regards

B.



Relevant Pages

  • Re: Exchange 2003 and Outlook Web Access.
    ... I made a backup off IIS after the re-install of IIS and Exchange when ... Then I backed up the metabase config via Microsoft's instructions on ... >>that are not allowed to access the Web site, and the IP address of your ... > that after getting Exchange running and before making any changes to ...
    (microsoft.public.exchange.admin)
  • RE: [Urgent] SBS 2003 missing Default Web Site
    ... Outlook Web Access, Exchange ActiveSync, and Outlook Mobile Access services ... Do you have a IIS metabase backup file before the issue happened? ... Open IIS management console, expand the default web site node, then capture ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • Re: Web Site name using Port
    ... >tell how to get web site name,path the website is mapped, web site ... Maybe iterating through the metabase in a script, ...
    (microsoft.public.inetserver.iis)
  • Re: IIS6 Fails To Start - WWW Service Error out of no where
    ... Please check whether the nodes "W3SVC" and "W3SVC/1" exist in your ... Unfortunatly there are no backup files in history folder before the issue ... We can conclude that metabase is OK, IISadmin, smtp and FTP runs fine, I ave ... >> preventing IIS from writing to it, and causing some sort of corruption -- ...
    (microsoft.public.inetserver.iis)
  • Re: Websites Stopped : Address Already In Use
    ... I have checked all the properties of each of the websites several times. ... Even if I add a host header and try to start one website with all the other ... How do you view the metabase? ... I have a report ...
    (microsoft.public.inetserver.iis)

Loading