Re: Hardening IIS



Jon Phipps wrote:
> Besides running the IIS lockdown tool and MBSA, as well as a good
> firewall and all the updates and patches, what steps can be taken to
> harden an IIS installation against hackers. I have a friend whos site
> has been hacked and he wanted the help to harden things. I am not
> sure if he built the site off the default website(something I am not
> keen on doing because it is the only one which can be hit by an ip
> surf, learned this in the days of red alert and some other worms) how
> ever I would like to help make the site as hard as it can with out
> investing lots of cash.

Without knowing the details of how the previous hacks have succeeded or how
the platform is configured it is impossible to provide any useful tips that
would be of any use to someone who knows enough to use lockdown and MBSA
tools already.

The server could be perfectly secure but the web app/site it is running
could be poorly designed and let the side down. If the webserver is on a LAN
with other machines it could be that one of these is compromised and is
giving up the webserver's secrets.

It could even be that someone has installed a keylogger on the user's
workstation and hence just happens to know all the required usernames and
passwords to gain access to what actually is a perfectly secure site.

--
--
Rob Moir, MS MVP
Website - http://www.robertmoir.co.uk
Virtual PC 2004 FAQ - http://www.robertmoir.co.uk/win/VirtualPC2004FAQ.html
Kazaa - Software update services for your Viruses and Spyware.


.



Relevant Pages

  • RE: MBSA: error occurred while scanning for security updates. (0x8
    ... security updates. ... The Windows Firewall is turned off on all machines that are logged onto the ... Also I assumed as I am running the MBSA scan from an internal server ... [CallerId = MBSA] ...
    (microsoft.public.windowsupdate)
  • Re: SMS Not Seeing Updates Needed by XP Clients
    ... Thanks Richard - Just for others who may be reading this the majority of differences between MBSA and Windows Update are listed here: ... > can push this out via standard Software Distribution. ... > Product updates, like 828026 for WMP below, aren't critical security updates ... >> The reason that differences occur between Windows Update and the SMS SUS ...
    (microsoft.public.sms.swdist)
  • Re: MBSA ans SUS
    ... I run MBSA on a secure Windows 2000 Active ... > Directory network which also has a SUS server on it. ... performed against the list of approved security updates on the ... about all the security updates released by Microsoft. ...
    (microsoft.public.security)
  • Re: 843183 MBSA-12 Urgent: Unsupported security scan tool - please u
    ... Inventory Tool and the Microsoft Office Inventory Tool for Updates, ... exsisting SMS20 site to using SMS2003 where MBSA 1.2 is supported. ... > when I invoke the dstribute software updates wizard the list of available ...
    (microsoft.public.sms.admin)
  • IIS lock down killed Updates?
    ... This morning I tried the MS IIS Lockdown Tool on my XP Pro SP2 Workstation. ... Web site, copied some folders from another machine and added a certificate ... for SSL.(I also tested the updates with IIS Admin and Web Publishing OFF). ... even when the mentioned services are set to auto and verified that ...
    (microsoft.public.windowsupdate)

Quantcast