Re: Securing Personal Web Servers

From: H Carvey (keydet89@yahoo.com)
Date: 10/26/01


Date: 26 Oct 2001 12:54:39 -0000
Message-ID: <20011026125439.28215.qmail@mail.securityfoucs.com>
From: H Carvey <keydet89@yahoo.com>
To: focus-ms@securityfocus.com
Subject: Re: Securing Personal Web Servers


('binary' encoding is not supported, stored as-is) Mailer: SecurityFocus
In-Reply-To: <OF5D1B103C.43AF458D-ON85256AF0.00454C90@nbc.gov>


>I've discovered that several of my Win NT
workstation users have the
>Personal Web Server product from Microsoft on
their machines. I haven't
>seen any security updates on how to patch these
installations. To secure
>these installations, I'm guessing that I would
just apply the IIS 4.0
>patches, but would like some feedback from anyone
who also has this
>situation.

Just a thought, but as you're posting from a .gov
domain...what do your policies say? Should these
users be running web servers? If not, wouldn't it
be prudent to remove, rather than patch, them?

Carv