Re: Basic Security ?

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 03/06/05


Date: Sun, 06 Mar 2005 19:17:30 GMT

On Sun, 6 Mar 2005 11:36:20 -0500, "Robert A." <satan@invalid.org>
wrote:

>I use the IIS included in Windows XP Pro, I only use it on my home computer
>for development purposes (ASP, PHP, etc.) I looked up security techniques
>and it all seems pretty involved and for actually running a Web server.
>
>What's some basic stuff I should be doing in my situation ?

If you don't access this from outside your house, then block port 80
int he firewall (or actually, don't open it, since you should block
everything and only open what you need.)

You could disconnect from the internet when testing, then shut down
the web service when you reconnect. That's probably overkill, but
overkill isn't a bad thing in security terms.

>Also, I always keep my security patches up to date with
>windowsupdate.microsoft.com but I don't think that keeps IIS updated does it
>? Where should I go for that ?

IIS isn't "updated", it's a part of the OS so any security fixes for
your operating system will include any IIS fixes as well.

>Remember, I don't want to get too involved.

Then yu shouldn't be dealing with security. Security is all about
involvement.

See the help here as well:

http://www.microsoft.com/security/

Jeff



Relevant Pages

  • Re: How to secure access to private network files via IIS 6.0?
    ... available for internet users. ... If we open up ports 139 or 445 for the web server in ... If You want to use IIS provide this users with certificates and use ... Astaro Security Linux -- firewall with Spam/Virus Protection ...
    (Security-Basics)
  • Re: Replacement for unsecure telnet/ftp on Windows servers
    ... buffer-overrun flaws, and there are so many of those ... of security flaws then you've just locked yourself out of anything other ... you may want to take a long hard look at IIS 6. ... took a long hard look at the criticism of their previous web server ...
    (microsoft.public.security)
  • [NT] Poisoning Cached HTTPS Documents in Internet Explorer
    ... Get your security news from a reliable source. ... "poison" a user's browser cache with a malicious document that will later ... The attacker can exploit this vulnerability for "replacing" HTML ... to communicate with a malicious web server over HTTPS without the browser ...
    (Securiteam)
  • [NT] Webserver 4D Weak Password Preservation Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... complete Web Server environment written entirely on top of 4th Dimension, ... WS4D web server saves the passwords somewhere insecure. ...
    (Securiteam)
  • Re: 2003 Web Server Security flaw
    ... "Locked-down windows 2003 Web Server used only to host web sites". ... What is your logic/rationale for Media Player being a required install ... The Media Player patch was the ONLY that FAILED. ... > When talking about computer security, there are areas that have no such ...
    (microsoft.public.windows.server.security)

Quantcast