Security Basics mailing list archives
RE: Securing IIS Server
From: "MeaCulpa" <meaculpa () punkass com>
Date: Tue, 5 Aug 2003 21:46:49 +0200
It kinda depends on the functionality you want to keep.... IIS UrlScan will protect you from various malformed URL's and you can use it to only allow (for instance) http get and http put. You can also allow some webdav commands, or entirely disable it (there is a registry key that can do the same...). IIS LockDown will just enable or disable stuff like ASP, SSI and will protect some system files. The docs provided with the tools are good enough to figure out what to expect.... meaculpa
-----Original Message----- From: NR [mailto:nr6106 () hotmail com] Sent: Tuesday, August 05, 2003 12:22 PM To: security-basics () securityfocus com Subject: Securing IIS Server Hi, I have IIS Server in which i want to install IIS lockdown and URLScan, i heard they are very good to protect IIS server, are they worth installing, and if not, is there any other tools i can use to secure my IIS ? Thanks and Regards NR -------------------------------------------------------------- ------------- -------------------------------------------------------------- --------------
--- Outgoing mail is has been checked with AVG, Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.504 / Virus Database: 302 - Release Date: 7/24/2003 --------------------------------------------------------------------------- ----------------------------------------------------------------------------
Current thread:
- Securing IIS Server NR (Aug 05)
- RE: Securing IIS Server dave kleiman (Aug 05)
- Data Compression Hendra Santosa (Aug 06)
- Re: Data Compression Glenn English (Aug 07)
- Re: Data Compression Gabriel Orozco (Aug 07)
- RE: Data Compression Paul Farag (Aug 07)
- Data Compression Hendra Santosa (Aug 06)
- Re: Securing IIS Server Simon Gray (Aug 06)
- RE: Securing IIS Server MeaCulpa (Aug 06)
- <Possible follow-ups>
- RE: Securing IIS Server Robinson, Sonja (Aug 06)
- Re: Securing IIS Server salgak (Aug 06)
- Re: Securing IIS Server chris (Aug 06)
- RE: Securing IIS Server Jay Woody (Aug 06)
- RE: Securing IIS Server Justin Martin (Aug 06)
- RE: Securing IIS Server Roland Venter (Aug 11)
- RE: Securing IIS Server Marc Maiffret (Aug 11)
- RE: Securing IIS Server Roland Venter (Aug 11)
- RE: Securing IIS Server Chris Neppes (Aug 06)
- RE: Securing IIS Server dave kleiman (Aug 05)