IIS Server - How to secure IIS6.0

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server > September 2005 > How to secure IIS6.0





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author How to secure IIS6.0
MPLB21

2005-09-26, 6:02 pm

Hi

This is my first attempt at installing and using IIS (I've also enabled
ASP.NET) on a Windows 2003 Server (std edition) SP1 server.

Is there a simple, easy-to-follow guide that can explain what I need to do
(if anything) to secure this IIS installation as well as the server itself
after I have installed the IIS?

Also, once it's installed and up and running is there a quick way that I can
disable it without uninstalling it?

Thanks

Matthew
Tom Kaminski [MVP]

2005-09-26, 6:02 pm

"MPLB21" <MPLB21@discussions.microsoft.com> wrote in message
news:2D627D9C-B4F4-42CB-940E-FA4CB026FD66@microsoft.com...
> Hi
>
> This is my first attempt at installing and using IIS (I've also enabled
> ASP.NET) on a Windows 2003 Server (std edition) SP1 server.
>
> Is there a simple, easy-to-follow guide that can explain what I need to do
> (if anything) to secure this IIS installation as well as the server itself
> after I have installed the IIS?
>
> Also, once it's installed and up and running is there a quick way that I
> can
> disable it without uninstalling it?


Start here:
http://www.microsoft.com/technet/se...odtech/iis.mspx

To disable, just go into the Services control panel applet and disable the
WWW Publishing Service.

--
Tom Kaminski IIS MVP
http://www.microsoft.com/windowsser...ty/centers/iis/
http://mvp.support.microsoft.com/
http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS


Kristofer Gafvert [MVP]

2005-09-26, 6:02 pm

In addition to Tom's recommendations, i would also recommend you to close
port 80 when/if you need to disable IIS to be even more secure.

Also see these links:

http://msdn.microsoft.com/library/e...ml/secmod88.asp
http://msdn.microsoft.com/library/e...ml/secmod89.asp
http://msdn.microsoft.com/library/e...ml/secmod90.asp
http://msdn.microsoft.com/library/e...ml/secmod92.asp


http://msdn.microsoft.com/library/e...l/secmod104.asp

--
Regards,
Kristofer Gafvert (IIS MVP)
http://www.gafvert.info/iis/ - IIS Related Info


MPLB21 wrote:

>Hi
>
>This is my first attempt at installing and using IIS (I've also enabled
>ASP.NET) on a Windows 2003 Server (std edition) SP1 server.
>
>Is there a simple, easy-to-follow guide that can explain what I need to do
>(if anything) to secure this IIS installation as well as the server itself
>after I have installed the IIS?
>
>Also, once it's installed and up and running is there a quick way that I
>can
>disable it without uninstalling it?
>
>Thanks
>
>Matthew

Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com