Welcome to HostingForumz.com!
FAQFAQ   SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Newbee Needs Advise on IIS Security

 
   Web Hosting Problem Solving Community! (Home) -> IIS RSS
Next:  IS  
Author Message
jrwolfe

External


Since: Oct 13, 2003
Posts: 8



(Msg. 1) Posted: Fri Oct 24, 2003 6:07 pm
Post subject: Newbee Needs Advise on IIS Security
Archived from groups: microsoft>public>inetserver>iis (more info?)

I just installed IIS on one of my Windows XP Pro systems. These computers
are running on a LAN with a cable modem and Linksys router.

I'm running some simple web pages on the server just as a learning
experience. Since I've had to open port 80, I'm somewhat concerned about the
security of this particular computer. For example, how would I know who
accesses my site and can they hack the computer? Also, would a program such
as Zone Alarm be useful here?

I've looked at some of the IIS documentation but I don't feel very
comfortable with the security issues.

Appreciate any suggestions.

Jim

 >> Stay informed about: Newbee Needs Advise on IIS Security 
Back to top
Login to vote
user641

External


Since: Aug 22, 2003
Posts: 1637



(Msg. 2) Posted: Fri Oct 24, 2003 7:07 pm
Post subject: Re: Newbee Needs Advise on IIS Security [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Jim" <jrwolfe.RemoveThis@desupernet.net> wrote in message
news:uwA9JImmDHA.1728@TK2MSFTNGP09.phx.gbl...
 > I just installed IIS on one of my Windows XP Pro systems. These computers
 > are running on a LAN with a cable modem and Linksys router.
 >
 > I'm running some simple web pages on the server just as a learning
 > experience. Since I've had to open port 80, I'm somewhat concerned about
the
 > security of this particular computer. For example, how would I know who
 > accesses my site and can they hack the computer? Also, would a program
such
 > as Zone Alarm be useful here?
 >
 > I've looked at some of the IIS documentation but I don't feel very
 > comfortable with the security issues.
 >
 > Appreciate any suggestions.

<a style='text-decoration: underline;' href="http://securityadmin.info/faqget.asp#iis" target="_blank">http://securityadmin.info/faqget.asp#iis</a>
<a style='text-decoration: underline;' href="http://www.microsoft.com/windowsserver2003/community/centers/iis/iis_security_faq.mspx" target="_blank">http://www.microsoft.com/windowsserver2003/community/centers/iis/iis_s...rity_fa</a>

--
Tom Kaminski IIS MVP
<a style='text-decoration: underline;' href="http://www.iistoolshed.com/" target="_blank">http://www.iistoolshed.com/</a> - tools, scripts, and utilities for running IIS
<a style='text-decoration: underline;' href="http://mvp.support.microsoft.com/" target="_blank">http://mvp.support.microsoft.com/</a>
<a style='text-decoration: underline;' href="http://www.microsoft.com/windowsserver2003/community/centers/iis/" target="_blank">http://www.microsoft.com/windowsserver2003/community/centers/iis/</a><!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: Newbee Needs Advise on IIS Security 
Back to top
Login to vote
jrwolfe

External


Since: Oct 13, 2003
Posts: 8



(Msg. 3) Posted: Fri Oct 24, 2003 8:06 pm
Post subject: Re: Newbee Needs Advise on IIS Security [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Many thanks to all who replied.

Jim

"Jim" <jrwolfe.TakeThisOut@desupernet.net> wrote in message
news:uwA9JImmDHA.1728@TK2MSFTNGP09.phx.gbl...
 > I just installed IIS on one of my Windows XP Pro systems. These computers
 > are running on a LAN with a cable modem and Linksys router.
 >
 > I'm running some simple web pages on the server just as a learning
 > experience. Since I've had to open port 80, I'm somewhat concerned about
the
 > security of this particular computer. For example, how would I know who
 > accesses my site and can they hack the computer? Also, would a program
such
 > as Zone Alarm be useful here?
 >
 > I've looked at some of the IIS documentation but I don't feel very
 > comfortable with the security issues.
 >
 > Appreciate any suggestions.
 >
 > Jim
 >
 ><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Newbee Needs Advise on IIS Security 
Back to top
Login to vote
kgafvert

External


Since: Aug 23, 2003
Posts: 3146



(Msg. 4) Posted: Sat Oct 25, 2003 12:25 am
Post subject: Re: Newbee Needs Advise on IIS Security [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi,

You can look in the iis log files to see who is connecting to your website
(you'll see the IP).
If the only port open is port 80, the only way a hacker could hack you is
thru port 80 (assuming no bug in the firewall). This means that you should
install all IIS patches, and always keep an eye on when new patches are
available.

A firewall is always good, but it will only protect ports that you have not
told it to be open. Since port 80 is open, and should be open, IIS (and you
in the way you configure IIS) is responsible for the security.

--
Regards,
Kristofer Gafvert
<a style='text-decoration: underline;' href="http://www.ilopia.com" target="_blank">http://www.ilopia.com</a> - FAQ & Tutorials for Windows Server 2003, and SQL
Server 2000
Reply to newsgroup only. Remove NEWS if you must reply by email, but please
do not.

Problems with spam and viruses? See
<a style='text-decoration: underline;' href="http://www.ilopia.com/security/newsposting.aspx" target="_blank">http://www.ilopia.com/security/newsposting.aspx</a>


"Jim" <jrwolfe DeleteThis @desupernet.net> wrote in message
news:uwA9JImmDHA.1728@TK2MSFTNGP09.phx.gbl...
 > I just installed IIS on one of my Windows XP Pro systems. These computers
 > are running on a LAN with a cable modem and Linksys router.
 >
 > I'm running some simple web pages on the server just as a learning
 > experience. Since I've had to open port 80, I'm somewhat concerned about
the
 > security of this particular computer. For example, how would I know who
 > accesses my site and can they hack the computer? Also, would a program
such
 > as Zone Alarm be useful here?
 >
 > I've looked at some of the IIS documentation but I don't feel very
 > comfortable with the security issues.
 >
 > Appreciate any suggestions.
 >
 > Jim
 >
 ><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Newbee Needs Advise on IIS Security 
Back to top
Login to vote
eddieb

External


Since: Oct 24, 2003
Posts: 19



(Msg. 5) Posted: Sat Oct 25, 2003 1:23 am
Post subject: RE: Newbee Needs Advise on IIS Security [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Make sure you have all the current patches and know what general
vulnerabilities you have by running the Baseline Security Tool:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
tools/mbsahome.asp

Then look into using the IIS Lockdown tool:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
tools/mbsahome.asp

Keep in mind that the lockdown tool will require that you know what type of
content you will be running on the machine to only allow the features your
need.
Don't just take the defaults without knowing what the mean first.

-Eddie
 >> Stay informed about: Newbee Needs Advise on IIS Security 
Back to top
Login to vote
Display posts from previous:   
   Web Hosting Problem Solving Community! (Home) -> IIS All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]