Re: Security problem with IIS5

From: Jeff Cochran (jcochran.nospam_at_naplesgov.com)
Date: 03/29/04


Date: Mon, 29 Mar 2004 18:17:31 GMT

On Sun, 28 Mar 2004 12:46:05 -0500, Dave Navarro <dave@dave.dave>
wrote:

>We are running IIS5 in Windows Server 2000. Two days ago, a hacker
>managed to install a trojan on our server through IIS.
>
>I have run the IIS lockdown utility and besides automatic updates, I
>*manually* check for updates every other day, so I have the latest
>updates.
>
>How can I make 100% certain that I have all of the IIS security updates
>installed?
>
>I run the Microsoft Baseline Security Analyzer weekly and with the
>exception of multiple admin accounts (necessary) everything checks out
>fine.

Try these links:

Security Checklists:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/Default.asp

>From Blueprint to Fortress: A Guide to Securing IIS 5.0:
http://www.microsoft.com/technet/prodtechnol/iis/iis5/deploy/depovg/securiis.asp

Also:

http://securityadmin.info/

Jeff



Relevant Pages

  • Re: Help with Sharepoint 2001 - Script Execution Error: Invalid qu
    ... me (barring those irritating Script Execution Error messages on the ... but I quickly learnt to leave IIS administration alone and let ... Sharepoint handle all that. ... Automatic Updates has ...
    (microsoft.public.sharepoint.portalserver)
  • Re: Windows Update related to IIS
    ... read this URL on how to properly configure IIS access to shared ... those Updates, and creatively. ... if you reset the IIS then this function starts working fine for a while. ... Wednesday, August 13, 2008 Automatic Updates   ...
    (microsoft.public.inetserver.iis.security)
  • Re: Mac Server Hacked In Less Than 6 Hours
    ... Windows has RAS, and for it is built in since NT 3.1 ... | A typical IIS box and this Mac are not the same thing so the comparison ... IIS has been subject to quite a few bugs and so have ... Security isn't a proprietary attribute. ...
    (sci.crypt)
  • Re: DCOM calls fails - access denied
    ... That's exactly how I understood the ASP.NET security. ... But why does one configuration work but not the other? ... should get the token from IIS. ... If you set there a domain account, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: How to secure IIS?
    ... XP as well, because even if you don't install IIS, there are still a number ... If you think Windows 98 is secure, ... easy to attack, if there's no firewall... ... IIS security checklists] 3) install firewall and antivirus, ...
    (microsoft.public.inetserver.iis.security)