Security Basics mailing list archives

Seeking IIS v6 checklist and clarification on authentication


From: "Pranav Lal" <pranav.lal () gmail com>
Date: Tue, 2 May 2006 22:01:31 +0530

Hi all,

I need a checklist for hardening IIS that is internet Information Services
v6. I have found several guides on IIS v5 but very little on v6. This brings
me to my next point. I have found an article or 2 that explains the
differences between iis V5 and v6. One key difference was regarding
authentication. The IIS v5 checklist suggests that basic and direct
authentication should be disabled in IIS v5 since reversible encryption is
used especially in direct authentication. Is this true? I believe this has
changed in IIS v6 but what is the change?

Pranav


Current thread: