Re: ZoneAlram IIS and port 80

From: Duane Arnold (notme_at_notme.com)
Date: 04/20/04


Date: Tue, 20 Apr 2004 11:59:35 GMT


"Sims" <siminfrance@hotmail.com> wrote in
news:c62r0v$78edh$1@ID-162430.news.uni-berlin.de:

> Hi,
>
> I am using ZoneAlarm, (the free one), IIS 5.1 and XP pro, SP1 and all
> the Updates.
> I am connected to the web 24/7 using an ADSL line.

That's not a good thing to have a machine directly connected to the
Internet with IIS running. You should have a NAT router setting there in
front of the machine to protect it.

>
> I am doing a small php web site on my machine and one thing the site
> does is to log the IP address of whoever tried to access the
> http://localhost, been on my machine I was a bit surprised to see
> other IP addresses appearing.
>
> How can I block all outside access to my http://localhost/ , port 80,
> 22?

You should not only learn how to lockdown IIS but also the O/S as well
for a machine running IIS. If neither are secure, then the machine will
be *hacked*.

I suggest you search Google and the MS Knowledge Base for the information
on how to secure IIS and the O/S.

I can tell you that the free ZA would be out of the picture.

Duane :)



Relevant Pages

  • Re: ZoneAlram IIS and port 80
    ... > Internet with IIS running. ... Would it not be cheaper to remove IIS and put Apache? ... > on how to secure IIS and the O/S. ...
    (comp.security.firewalls)
  • Re: Is a firewall required...
    ... trying to protect IIS. ... the registry, O/S, file system, accounts, and IIS are secured. ... kind of a blow by blow as to what is needed to secure a Windows workstation ... being exposed to the public Internet. ...
    (comp.security.firewalls)
  • Unix Files on IIS 5.0. Cannot Nuke!
    ... I have compiled an extensive IIS security procedures ... Procedures for Secure IIS 4.0 Server Builds. ... When I enabled UNIX ...
    (microsoft.public.inetserver.iis.security)
  • Re: Nimda is bothering too much..
    ... > Just stop using MS Windows' IIS. ... > Gartner group recommends Apache on Win32 instead. ... person can't secure IIS, they most likely will have some degree of trouble ... but switching from IIS to Apache simply because ...
    (microsoft.public.win2000.security)
  • Re: How to protect multiple IIS Web Farms
    ... "Michael J. Pelletier" wrote in ... etc but IIS is sooo ... knows how to secure IIS and the applications that run on IIS properly. ...
    (comp.security.firewalls)