Microsoft .NET, ASP.NET, and IIS - any opinions?

From: Tracy Martin (tracy@arisiasoft.com)
Date: 12/12/01


From: "Tracy Martin" <tracy@arisiasoft.com>
To: <focus-ms@securityfocus.com>
Date: Wed, 12 Dec 2001 15:52:01 -0500

Greetings,

We all know that IIS has it's flaws - and that for many of these there are
patches available (or at least workarounds). However, with the immanent
release of VisualStudio.NET and ASP.NET, I'm expecting to see installs of
IIS and the .NET runtimes (which, if I understand it correctly, basically
amounts to installing the full SDK - including command line compilers) on
servers all over.

And this begs the question - has anyone who has insight into this done any
security studies on this combination? Is the addition of .NET to IIS going
to cause any additional security holes (over and above those already present
in IIS itself)? And are there recommendations for closing these types of
holes if encountered?

I already know I'm going to be asked to set up such a server, and I'd like
to get a feel for what I'm letting myself in for. I know there are patches
available for IIS (and I've already applied them to the IIS server we have
live right now), but I'm curious if the addition of .NET to the mix is going
to introduce new problems (and also interested in potential solutions to
those problems while waiting for "official fixes" from Microsoft).

Any takers?

Tracy



Relevant Pages

  • Re: Security of IIS - Secure Intranet web site on SBS2003 box
    ... I guess a lot of those patches would be required anyway to ensure the HTTPS ... Because if IIS via HTTPS only is still not considered secure then surely the ... > to rebuild their server and return everything to normal. ...
    (microsoft.public.windows.server.sbs)
  • Re: Open Ports....How to block them all....?
    ... > I keep it up to date with SP's and Patches but find that the server keeps ... Frequently this happens through an IIS ... Ways to secure your system are detailed at: ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS Hack : Anyone explain cause...
    ... If you never secured the server and now wonder why it was hacked -- I hope ... you realize that it is an absolute waste of time to figure out now. ... MBSA, IIS Lockdown tool. ... NOTE: We were missing the following patches: ...
    (microsoft.public.inetserver.iis)
  • Re: IIS Hack : Anyone explain cause...
    ... it looks like you cleaned up the server -- if you care about security, ... Microsoft tries and mostly succeeds to release patches PRIOR to ... weeks/months/years prior to exploitation. ... > protected rant as we all know that IIS and indeed lots of software has ...
    (microsoft.public.inetserver.iis)
  • Re: Server attack?
    ... Just running the latest SP is not enough to secure your IIS site. ... will plug the most common security holes, but the problem is that new holes ... > Now, i have downloaded and installed SP3 prior to finding this and i assumed that the server was quite safe, but was surprised to> see the server return the success code 200. ...
    (microsoft.public.inetserver.iis.security)

Loading