Re: IIS Seperate Partition?

From: Roger Abell [MVP] (mvpNoSpam_at_asu.edu)
Date: 05/31/04


Date: Mon, 31 May 2004 07:25:22 -0700

Placing the content on a separate partition offers some amount
of added difficulty to an invader, but do not believe it is very great.
Mostly that is a measure that will guard you against misuse of the
accounts granted permissions in your web server and/or your
misconfiguration of them
If someone does get in, and gets ahold of the processes, they
will have little difficulty walking around your system.

-- 
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCDBA,  MCSE W2k3+W2k+Nt4
"Ryan Riddell" <anonymous@discussions.microsoft.com> wrote in message 
news:DDB4975B-E550-47E7-AF08-68DD979B09FB@microsoft.com...
> I'm running Server 03 with a web server and file server as well as acting 
> as a domain controller.
>
> My question is if it would be more secure or considered a good idea to 
> have the web server on its own partition?
>
> The idea being that if a malicious user manages to take control of IIS 
> they are sort of stuck on the individual partition.  Also, if they manage 
> to hose the partition it won't effect the other functions of the server.
>
> Thanks,
> Ryan 


Relevant Pages

  • Re: Rebuilding SBS Server 2003 SP2
    ... issues with exchange system manager because the SSL server name ... figured a rebuild was the perfect time to investigate these (chuck more RAM ... lot with re-installs but havent a clue with partition sizes with SBS, ...
    (microsoft.public.windows.server.sbs)
  • Software Raid for clones
    ... Personally I inherited this E6750 ASUS motherboard and wanted thought I'd build a nice server for general use. ... I added 4 SATA 250 Gb disc drives and after reading about the horrors & failures of the cheapie Raid controllers, I decided to try Linux software raid. ... I got a message from every MD partition that there were not ... Disk partitions and LVM limits ...
    (RedHat)
  • Re: SBS2003 Partitioning
    ... sell a server to a customer to maximise billing hours. ... I realise that capacity is all down to the business that you are selling to ... just makes our experiences different. ... If the partition is on the same set of spindles then I could care ...
    (microsoft.public.windows.server.sbs)
  • Re: Is it possible to redirect the default user shares?
    ... The server is a rack mounted HP ProLiant ML 350 G4 and the integrated NIC ... I understand most people thatr design a server around W2k3 SBS Premium start ... OS partition and only a single additional partition if the underlying drive ... RAID1+RAID5) it may be worthwhile putting the shadowcopies from one array on ...
    (microsoft.public.windows.server.sbs)
  • RE: use of base image / delta image for automated recovery from a ttacks
    ... base disk image shared by multiple virtual machine instances. ... your basic web application might have a web server ... partition and the changeable datafiles on another partition. ... Apache to install a trojan or a backdoor on the more exposed web server. ...
    (SecProg)