Build your professional network on facebook via our app Go to app
 
<< Prev  4 of 5 in Topic  Next >>
Topic : Security Programming in .NET
  Rate : 
Industry : Communications and Networking Functional Area : Architecture
Keywords :

.NET

Down

IIS

6.0

Locking

Activity:  2 comments  261 views  last activity : 07 06 2010 20:18:04 +0000
Share
 
 
 
Yeah, you’ve heard it a million times. How often you hear that IIS has been hacked, another unchecked buffer (the millionth one this year) and no, not another service pack or hot fix!

Now, the minute you install and start up the IIS 6.0 product on Windows .NET Server, you are hit with the words “security” immediately with a new Wizard. First off, IIS 6.0 had to be installed on my version of Windows .NET Server. It was not running by default (another good thing), and can be installed in the Control Panel, Add/remove programs applet, and then by selecting to add a Windows based component. Once you installed Windows IIS 6.0, then you can launch it from the Administrative tools folder within the Console Panel or the Start menu programs folder.

The minute you open the IIS 6.0 MMC, you launch a new Wizard immediately. The Wizard seen here is the Web Server Security Lockdown Wizard. This Wizard is used to help you lock down default services, CGI and ISAPI handlers down before you even launch the console.

 

 

You are also shown in the above Wizard dialog box that you can access this later if you want to cancel is now by going to the Computer Icon, going to the Action Menu in the MMC and selecting ‘security’

You will then proceed to be able to set your services up that run by default. They are:

·         HTTP (Hypertext Transfer Protocol)

·         FTP (File Transfer Protocol)

·         SMTP (Simple Mail Transfer Protocol)

·         NNTP (Network News Transfer Protocol)

 

 

At times though, you may want to disable certain services or set them to only run manually when you initiate them. For purposes of this exercise, I am setting my HTTP and FTP services to run automatically, but I would like news and email to be disabled.

 

 

Clicking Next advances you to the next screen, which is to let you enable or disable handlers. CGI (Common Gateway Interface) is almost always exploited by hackers and finally you can enable or disable by default.

 

 

What are Event Handlers you ask? Event Handlers allow embedded scripting languages to trap events and actions that occur as a reader experiences a page. These optional attributes then trigger script code.  OnMouseOver is one of the most common.

Once you select what you want to enable, you can click next. Now, you have successfully completed the IIS Security Lockdown Wizard. (notice the name change from Web Server to IIS?

 

 

Now you can open the IIS console and view your web site. One last check for the security minded will show you that this wizard did its job. Close the IIS MMC.

 

 

Go the Administrative tools folder within the Control Panel and click on the services Icon. When you open the Icon, browse to the Simple Mail Transfer protocol and click on it. You can see it is definitely disabled now.

 

 

We have now gone through and experienced the new version of IIS 6.0 and its new security features that will help to aid in Microsoft security.

 
2 comments on "Locking Down IIS 6.0 with .NET"
  Commented by  vijayvkvelu, System Security, IBM    | 01 19 2009 14:54:34 +0000
Good one i appreciate it .. 
  Commented by  Darpan Sinha, Solution Architect, Fujitsu Consulting India Pvt Ltd    | 10 22 2008 07:25:26 +0000
Nice One
Add your comment on "Locking Down IIS 6.0 with .NET"

Rate:
Submit
Think Intellectual Capital
Think Intellectual capital
Viewers also viewed
After a cluster of disconcerting e-mails and documents surfaced last week from climate...
 
267 referals 5 comments, 67 views
PHP vs ASP.NET
 
0 referals 10 arguments, 2778 views
more...  
Recent Knowledge (107)
Today i saw a post on yahoo : http://in.lifestyle.yahoo.com/10-ideal-habits-better-lifestyle-074...
 
648 referals 10 comments, 379 views
Kingfisher is a big banner and we see this brand doing many things including lavish waste of...
 
2283 referals 32 comments, 452 views
Married men, Enjoy this !!  Unmarried men, Learn from this !! Married/unmarried Women, It is...
 
152 referals 22 comments, 499 views
more...  
More From Author
Its Too Gud....
Too good man.....nice to read....
मुझे तो मर ही जाना होता है,पर मैं अमर रहता हूँ। कोई समझ पाए या नहीं मेरे प्रेम की कीमत,पर होती वो मेरी जान के बराबर है। मैं एक छोटा सा पतंगा ये जानते हुए कि कभी भी कहीं से एक लौ के वार से मैं अपनी साँसें खो दूँगा। मैं चल पड़ता हूँ पागलों की तरह...
more...