RE: iis config

From: Bryant (bryantc@microsoft.com)
Date: 05/13/02


From: bryantc@microsoft.com ("Bryant")
Date: Mon, 13 May 2002 19:42:36 GMT


Hello Chris,

James has informed you correctly. Please look over the base line check
lists and information available at
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
tools/chklist/iis4cl.asp

There are baseline security checklists for both IIS4 and IIS5. You will
want to become very familiar with these. Also note that Anti Virus programs
such as Norton provide a "Script Blocking Feature" that you do not want to
run on your web server if you plan to host dynamic content such as .ASP.
The feaure will try to shut down any dynamic content treating it as a
malicious script. Carefully review the security white papers and should you
have any questions feel free to repost. Start with the baseline changes and
then carefully choose and other products you want to integrate with IIS.

I'm pretty sure that all your answers regarding security can be found at
the site referenced.
An alternate site is http://www.iisfaq.com

Best regards,
Bryant Carr

 This posting is provided “AS IS” with no warranties, and confers no
rights.
You assume all risk for your use. © 2001 Microsoft Corporation. All rights
reserved.



Relevant Pages

  • Re: Secure shared web hosting using MAC Framework
    ... run the web server and web users shell in a jail, ... Those rights should have priority on any traditional unix file ... This directive allows you to disable certain functions for security reasons. ... Web users and executed web scripts shouldn't be able to read ...
    (FreeBSD-Security)
  • Orwell meets Kafka
    ... THE OTHER DAY, the new secretary of homeland security, Michael Chertoff, scrapped the moronic rule requiring everyone to stay seated for 30 minutes coming in or out of Ronald Reagan Washington National Airport. ... If the American republic was built on any core principle, that principle is the rights of people to be free from the abuses of unchecked power. ...
    (soc.culture.australian)
  • RE: Rights
    ... the benefit is improved security. ... in restricting rights in favor of increased security. ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic ...
    (Security-Basics)
  • Re: Mailboxes instead of new users
    ... You are always welcomed to call PSS and open a Exchange security related ... Open the properties of the mailbox store in the Exchange System Manager, ... This posting is provided "AS IS" with no warranties, and confers no rights. ... > security group for the distribution group and give her "send as" rights. ...
    (microsoft.public.windows.server.sbs)
  • Re: WordPerfect
    ... could add Domain Users to the Power User group on each computer and this ... Win 2k's security is tightened down considerably more that Win NT ... >> and had profiles for other users to use the same icon to access WP8 and ... So we know it is a rights thing of some sort. ...
    (microsoft.public.win2000.security)

Quantcast