RE: IIS6 on W2k3 DCs

From: Devin Ganger (DevinG_at_3sharp.com)
Date: 01/15/05

  • Next message: Jason Short: "Re: PGP and Outlook"
    Date: Fri, 14 Jan 2005 16:40:46 -0800
    To: <focus-ms@securityfocus.com>
    
    

    Susan Bradley wrote:

    > But Small Business Server 2003 runs with IIS on our domain controller.
    > Where's MY security risks these days? Not my server..nope......it's
    > my desktops where my security risks lie.

    Anything you expose to the Internet is a security risk, especially when
    it's just sitting there listening.

    > Port 80 is closed on my server but IIS is still on there.

    Which is why IIS is a lesser risk *for you*.

    > Am "I" freaking out over IIS on my domain controller? Nope.
    > Not at this moment.
     
    As is good and proper, but when you're specifically being asked to put a
    live (publicly accessible) webserver on a DC, that's different. To do so
    is idiocy, not to put too fine a point on it, even if you're using SBS.
    While SBS has a lot of value, the single-server configuration breaks a
    lot of best practices in the name of financial convenience. (Exchange on
    a DC, forex -- supported but not recommended.)

    -- 
    Devin L. Ganger             Email: deving@3sharp.com
    3Sharp LLC                  Phone: 425.882.1032 x 109
    15311 NE 90th Street        Cell: 425.239.2575
    Redmond, WA  98052          Fax: 425.702.8455
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Jason Short: "Re: PGP and Outlook"

    Relevant Pages

    • Re: how to host multiple websites on sbs2003 std
      ... you're likely to find your posts going ... SBS and Router with built-in firewall - in my opinion are quite capable ... I understand the security risks and have hopefully covered them. ... that just crap on for ages about the securoty risks of SBS server being ...
      (microsoft.public.windows.server.sbs)
    • Re: how to host multiple websites on sbs2003 std
      ... SBS and Router with built-in firewall - in my opinion are quite capable ... of securing themselves if configured correctly. ... I understand the security risks and have hopefully covered them. ... that just crap on for ages about the securoty risks of SBS server being ...
      (microsoft.public.windows.server.sbs)
    • Re: How Do You Build Firewall Rules to Restrict RPC Traffic?
      ... > are not exposed to the Internet, so RPC is never exposed to the Internet. ... The worst security risks on most networks are not from the outside coming ... our network, the domain controller will be used to authenticate, perform DNS ...
      (microsoft.public.isa)
    • Re: OT: Gone from topic, now on security Re: For PGP Users-Likes and Dislikes of PGP
      ... David Wagner wrote: ... use it as my mailer, does it expose me to security risks that I wouldn't ...
      (sci.crypt)
    • Re: Connect over internet
      ... to connect to a remote server via internet. ... That depends on if your Oledb driver supports a TCP/IP connection and you are ... willing to assume the security risks of an a connection through the Internet ...
      (borland.public.delphi.database.ado)