IIS Server Security - best practices

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > June 2004 > best practices





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author best practices
Hernán Castelo

2004-06-28, 7:33 pm

i deploy
the "best practices"
according to MS
but it was not enough

what should i do now?

how can i secure the web server now ?



--
atte,
Hernán


"Hernán Castelo" <hcastelo@cedi.frba.utn.edu.ar> escribió en el mensaje news:%23GBjOhRXEHA.2636@TK2MSFTNGP10.phx.gbl...
hi
someone was hacked my site
i have 2 servers :
web--> IIS 5 / w2k adv Srv IIS lockdown
sql--> SQL2k / w2k adv Srv

i found the web srv doing "beeps"
soon i found it serves html pages
but don't serves asp with an error like
"Error in the server application"

sql srv lost sa password
and don't recognize the local admin
then i can't access to sql applications

except of that,
servers appears to work normal

the web srv log is saying
that attacked the iwam_
and many "login misses" under DCOMSCM
and then, "login hits"

i go now to restore
my backup and images
but
what can i do to prevent the next attack ?
how can i protect better the site ?

thanks


--
atte,
Hernán

Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com