Security Basics mailing list archives

Re: Securing IIS Server


From: salgak () speakeasy net
Date: Tue, 05 Aug 2003 17:03:56 +0000

-----Original Message-----
From: NR [mailto:nr6106 () hotmail com]
Sent: Tuesday, August 5, 2003 10:22 AM
To: security-basics () securityfocus com
Subject: Securing IIS Server

Hi,

I have IIS Server in which i want to install IIS lockdown and URLScan,
i heard they are very good to protect IIS server,
are they worth installing, and if not, is there any other tools i can use 
to secure my IIS ?

FDISK /MBR and Install Linux or FreeBSD ???  (sorry, couldn't resist)

First, what version of IIS are we talking here ?  IIS 3 or 4 running on NT, IIS 5 on 2000, or IIS 6 on 2003 ?

Then comes the task of hardening not just the IIS, but the server you're running it on.  IIS is only PART of the task.  

If it's 2000,  start here:

http://nsa2.www.conxion.com/win2k/download.htm





---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: