WebApp Sec mailing list archives

RE: Securig IIS Server


From: "Tiago Halm" <thalm () netcabo pt>
Date: Wed, 6 Aug 2003 16:46:18 +0100

IIS Lockdown does effectively change your NTFS permissions and determines
the Win32 services you need accordingly to a specific objective. Its all
based in the Microsoft IIS-based products. Your should use it.

As for UrlScan, since it does not cover all the HTTP spectrum in terms of
security, you should take a look at IISShield (it is also freeware) and
really does covers all HTTP protocol issues that may arise and protects your
IIS-based assets effectively.

IISShield is available at: http://www.kodeit.org/tools/iisshield.htm

Hope it helps,
Tiago Halm
http://www.kodeit.org

-----Original Message-----
From: NR [mailto:nr6106 () hotmail com] 
Sent: terça-feira, 5 de Agosto de 2003 11:20
To: webappsec () securityfocus com
Subject: Securig IIS Server






Hi,



I have IIS Server in which i want to install IIS lockdown and URLScan,

i heard they are very good to protect IIS server,

are they worth installing,

and if not, is there any other tools i can use to secure my IIS ?



Thanks and Regards

NR


Current thread: