Re: How secure is IIS 6?

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 07/16/05


Date: Sat, 16 Jul 2005 14:55:53 GMT

On Sat, 16 Jul 2005 04:12:01 -0700, "James"
<James@discussions.microsoft.com> wrote:

>I am a newbie to IIS but I need to host a forum on my own server for various
>reasons. I am wondering how secure is IIS, it will be on win Server 2003 and
>behind a simple Netgear Router firewall, that is it.

IIS and Server 2003 are as secure as you make them. Just like a
padlock is secure, if you don't lock it, there is no security.

>Will I need to purchase a proper firewall or some extra software, or do you
>think that will be enough?

Server 2003 has a firewall you can use. The Netgear also has firewall
functions. Configured correctly they work fine. Remember that a
firewall doesn't make your system secure, it simply blocks some
avenues of access. Security depends on you as well. See:

http://www.microsoft.com/technet/security/default.mspx

Especially:

http://www.microsoft.com/technet/security/prodtech/iis.mspx
http://www.microsoft.com/technet/security/prodtech/windowsserver2003.mspx

Jeff



Relevant Pages

  • Re: Firewall - Limit Geographic Area
    ... Firewall - Limit Geographic Area ... > times more secure than a Microsoft Windows machine can be). ... Redhat is conservative about what they release ... > - do not reuse passwords between your server and, say, random ...
    (RedHat)
  • RE: Securing a Terminal Services user
    ... Add these users to a group and implicitly deny this group access to any ... applications, i.e. Citrix Secure Gateway, Web Interface & publish the exact ... I am setting up a TS server inside my firewall. ...
    (microsoft.public.windows.terminal_services)
  • Re: Remote Management
    ... authentication. ... I manage a remote windows SBS 2003 server; I have enabled TS in admin ... My question is this secure. ... If you want to allow RD into the Terminal Server, setup your firewall to ...
    (microsoft.public.windows.terminal_services)
  • Re: What to use for a Firewall device?
    ... >> I have two NIC's in the SBS 2003 server, ... may be the ISA server or some other Firewall OS/software ... >> If I had my way this office network would NEVER see the Internet at ... This network must be very Secure, very tight, think of it as if I ...
    (microsoft.public.windows.server.sbs)
  • SSH implementation
    ... Windows Servers and SSH Secure Shell for Workstations ... mail server on mail through SVR ... and Server are behind firewall (checkpoint and Cisco ...
    (SSH)

Loading