RE: Looking for an article on identities used in IIS 6.0 web appli

From: Wei-Dong XU [MSFT] (v-wdxu_at_online.microsoft.com)
Date: 10/24/05


Date: Mon, 24 Oct 2005 06:29:12 GMT

Hi Chris,

The best public content I have read for IIS authenticaiton and
authorization is from the book "Design Secure Web-based Applications for
Windows 2000", written by Michael Howard with Marc Levy and Richard
Waymire. Though it faces Windows 2000, the underlying IIS security
mechanism are still the same in windows 2003. I am sure the chapter 5 will
explain them for you very well.
http://www.microsoft.com/mspress/books/sampchap/4293.asp#SampleChapter

In addition, this book also introduces the windows system security deisgn
regarding SQL, COM+, WMI etc. From my personal view, this is a must-read
book for mastering the administration of windows security.

Please feel free to let me know if you have any further question on this
matter.

Best Regards,
Wei-Dong XU
Microsoft Product Support Services
This posting is provided "AS IS" with no warranties, and confers no rights.
It is my pleasure to be of assistance.



Relevant Pages

  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)
  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)
  • Re: The Myth of the secure Mac
    ... OEM Windows XP Home goes for a bit under $100. ... >> secure than Home. ... Though this really has nothing to do with security. ... Microsoft counts on third-party developers to provide more ...
    (comp.sys.mac.advocacy)
  • SecurityFocus Microsoft Newsletter #120
    ... Strengthening Network Security: FREE Guide Network security is a ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows File Protection Signed File Replacement... ... PlatinumFTPServer Information Disclosure Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter # 149
    ... MICROSOFT VULNERABILITY SUMMARY ... EveryBuddy Long Message Denial Of Service Vulnerability ... Intellitactics Network Security Manager ... Windows operating systems. ...
    (Focus-Microsoft)