Re: security on iis 5 open port router

From: Ian Hastie (ian_a_hastie@hotmail.com)
Date: 07/24/02


From: Ian Hastie <ian_a_hastie@hotmail.com>
Date: Tue, 23 Jul 2002 23:02:13 +0000 (UTC)


In article <A26%8.4467$DN4.652251@news20.bellglobal.com>,
   tester wrote:
>
> Currently I am running a webserver on 2000 Advanced Server using IIS 5.(I
> set to "browse and read only). I open my port 80 on my router (netgear
> 314). I have the server hacked as well virus in the server (Dont know
> how)--- and the server hsa been running for about 2 months...

There are two alternatives I can think of.

Get all the current patches from MS and apply them. Hope that there are
no new major security holes waiting to be exploited. Given IIS's
security record you will most likely be unlucky.

Get Apache for Windows and run it instead. It has a much better
security track record than IIS. Obviously problems will arise so,
again, make sure you stay up to date with any security fixes.

-- 
Ian.
EOM


Relevant Pages

  • RE: NT/IIS decoy
    ... Does anyone know how to hide or mask the identity of a IIS 4.0 or 5.0 server ... Principal Security Consultant ... Best Individual Income Protection Provider 2001 - Health Insurance Magazine ...
    (Pen-Test)
  • Re: IIS6 on W2k3 DCs
    ... How many times in big server land do I see folks that don't have backups ... >But Small Business Server 2003 runs with IIS on our domain controller. ... >Where's MY security risks these days? ... >>By referring to numerous security guides written specifically for NT4 ...
    (Focus-Microsoft)
  • Re: SBS 2003 After Service Pack 1 for SBS
    ... Controllers" groups have been added to the new CERTSVC_DCOM_ACCESS security ... we can have Certificate Services update the DCOM security settings ... down time for the server - probably over a weekend. ... Then please run command "iisreset" to refresh IIS ...
    (microsoft.public.windows.server.sbs)
  • [NT] Cumulative Patch for Internet Information Services
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... security patches released for IIS 4.0 since Windows NT 4.0 Service Pack ... encoding transfer mechanism via Active Server Pages in IIS 4.0 and 5.0. ... attacker who exploited this vulnerability could overrun heap memory on the ...
    (Securiteam)
  • Re: REPOST: IIS4 Security Advice
    ... Well, I assume you know you need more than the latest IIS security patch, ... win 2000, one for IIS, one for Index Server, etc.] ... After installing iislockdown ...
    (microsoft.public.inetserver.iis.security)