• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

IIS insecurity

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    IIS insecurity

    I need to install IIS locally to do some testing. Machine is win2k + running norton personal firewall. After installing iis what will I need to do to ensure that it is secure ? (other than downloading latest patches / updates)

    #2
    make sure

    you run iislockdown...

    Comment


      #3
      Re: make sure

      Also, urlscan is quite useful.

      It blocks 'funny' urls, i.e. ones that try fancy unicode in the url or access to system directories. Combined with lockdown and latest patches, makes IIS 1000x more secure.

      Comment


        #4
        maybe you chuck a personal firewall on and lock down who can connect to it?

        Comment

        Working...
        X