Re: Setting up IIS 6.0 tutorial



IIS 6.0 is fairly secure by default in that it is very locked down compared
with previous versions and not enabled by default. The links below should
help. General procedures such as a firewall, disabling unneeded services,
using antivirus, strong passwords, log monitoring, and keeping current with
critical security updates are also important steps. The free Microsoft
Baseline Security Analyzer is also a great tool to check certain security
vulnerabilities on your computer including for IIS as is the Security
Configuration Wizard for SP1. --- Steve

http://technet2.microsoft.com/WindowsServer/en/Library/ace052a0-a713-423e-8e8c-4bf198f597b81033.mspx
http://technet2.microsoft.com/windowsserver/en/technologies/featured/iis/default.mspx
http://www.microsoft.com/technet/security/tools/mbsahome.mspx --- MBSA
http://www.microsoft.com/windowsserver2003/technologies/security/configwiz/default.mspx
--- Security Configuration Wizard

"Surre" <u18972@uwe> wrote in message news:5c3a96d2979f3@xxxxxx
Hi,

is there any good tutorial for a semi-newbie on how to set up IIS 6.0 on a
windows 2003 server to make it as safe as possible?
I mean a step-by-step guide to follow that will make the webserver safe.

Thanks
/Surre


.



Relevant Pages

  • Re: Mac Server Hacked In Less Than 6 Hours
    ... Windows has RAS, and for it is built in since NT 3.1 ... | A typical IIS box and this Mac are not the same thing so the comparison ... IIS has been subject to quite a few bugs and so have ... Security isn't a proprietary attribute. ...
    (sci.crypt)
  • Re: DCOM calls fails - access denied
    ... That's exactly how I understood the ASP.NET security. ... But why does one configuration work but not the other? ... should get the token from IIS. ... If you set there a domain account, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: How to secure IIS?
    ... XP as well, because even if you don't install IIS, there are still a number ... If you think Windows 98 is secure, ... easy to attack, if there's no firewall... ... IIS security checklists] 3) install firewall and antivirus, ...
    (microsoft.public.inetserver.iis.security)
  • RE: .pdf security using ASP.NET security...
    ... I am wondering if using the aspnet_isapi.dll to handle PDF files security ... IIS has a list of Application Mappings which dictate whether a particular ... entries that tell aspnet_isapi.dll what to do with various file types. ... Files that do have app mappings require all the same steps, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: impact of mapping .??? to ASP.NET ISAPI???
    ... security issue, either from ASP.NET or IIS (this is something that my ISP ... > entries that tell aspnet_isapi.dll what to do with various file types. ... > process the request. ...
    (microsoft.public.dotnet.framework.aspnet.security)