Re: IIS 6.0 Resource Kit

From: Phillip LeMaster (PhillipLeMaster_at_discussions.microsoft.com)
Date: 03/17/05


Date: Thu, 17 Mar 2005 06:15:02 -0800

Thank you Jason. I agree to some extent. Our servers are in a remote
location and when working with Microsoft support in the past they have asked
that the resouce kit be installed for them to trouble shoot. I also agree
partially that tools should not be installed unless used. Our tools are used
al least every month, but to take the time to install and uninstall is too
cumbersome. And my last point. If a security professional writes up
something then they should be able to relate that issue to a known bug or
case where this is an issue and not just their personal preferences. So for
the sake of being professional we need to know what Microsoft's view is if
possible. I thought most tools and especially yhe system32 directories are
locked down pretty much. If someone has already gotten to your system32
directory then those tools are not going to prevent them from doing
irreprable damage.

"Jason Brown [MSFT]" wrote:

> To agree with Bernard, I don't see any specific threat posed by the RK
> tools, however it's usually a good policy to keep production servers in as
> clean a state as possible, and only install the tools if you have a specific
> need. This goes for pretty muchtools not directly related to the day-to-day
> running of a production box.
>
> Most, if not all of the tools in the kit can be used from a connected
> workstation, so there isn't necessarily a need for them to be there anyway,
> but at the end of the day the choice is yours. As far as I'm aware,
> Microsoft provides no specific guidance on the IIS 6.0 resource kit in this
> direction, though I'll be happy to check this out further if you like.
>
>
> --
> Jason Brown
> Microsoft GTSC, IIS
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
> "Phillip LeMaster" <PhillipLeMaster@discussions.microsoft.com> wrote in
> message news:8BD7C351-37C1-4504-A409-82A90A839154@microsoft.com...
> > We just had our annual security audit. We were advised that we should not
> > have IIS 6.0 tools installed on web server connected to the internet. I
> > can
> > not find any information that states this. Does anyone know Microsoft's
> > policy on resource kit installations?
>
>
>



Relevant Pages

  • RE: Fix the Office 2007 Beta Activation. It DOESNt work.
    ... The problem that would make someone NOT want to install this program ... Servers which they are using in a production/non-beta fashion. ... This post is a suggestion for Microsoft, ...
    (microsoft.public.office.misc)
  • Re: DR - Active Directory
    ... certain servers and applications at an off-site location. ... Active Directory for a particular domain is in scope. ... Certified Trainer) teaching MOC (Microsoft Official Curriculuum) courses, ... install our own classroom setups. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Server restarting every night at 3am.
    ... As for the fix, yes, nothing from microsoft yet. ... All 3 servers are ok now. ... it to just notify of updates and not even download, forget about reboot. ... Microsoft Update and Install them automatically? ...
    (microsoft.public.windows.server.sbs)
  • Post SP6 SRP Q299444i
    ... outside servers. ... further downloads from Microsoft to install. ...
    (microsoft.public.security)
  • Re: Possible virus!
    ... > didn't work then we might have to do a fresh install. ... Microsoft has these suggestions for Protecting your computer from the ... I'll mainly work around Windows XP, as that is what the bulk of this ...
    (microsoft.public.windowsxp.general)