IIS Server Security - virtual server authorization

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > October 2005 > virtual server authorization





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author virtual server authorization
Aric

2005-10-24, 11:03 am


I am currently about to launch an ecommerce solution for my company and
was wonder about securing the administration section. Currently the
plans are to have the administration site in a virtual server using
windows authentication and restricted to local ips only. While looking
at all the documentation I can find this should work perfectly I'm still
a little worried about having it on a server connected directly to the
net. Anyone know of security flaws in IIS 6.0 running on w2k3 that
would allow users to get into the administration site?


--
Aric
------------------------------------------------------------------------
Aric's Profile: http://www.highdots.com/forums/m1128
View this thread: http://www.highdots.com/forums/t3038625

David Wang [Msft]

2005-10-24, 11:03 am

Here are some thoughts on what "security" really means:
http://blogs.msdn.com/david.wang/ar..._vs_Apache.aspx
http://blogs.msdn.com/david.wang/ar...t_
2.aspx


If you are uneasy, I would suggest that you put two NIC in the server and
bind the administration website to the internal-facing NIC. Then, you can
trust in your network routing configuration skills to make sure that network
traffic goes to the right place.

Personally, if the administration site requires authentication, that's about
all the protection you need, even Internet facing.

--
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//
"Aric" <Aric.1x60ly@no-mx.forums.yourdomain.com.au> wrote in message
news:Aric.1x60ly@no-mx.forums.yourdomain.com.au...

I am currently about to launch an ecommerce solution for my company and
was wonder about securing the administration section. Currently the
plans are to have the administration site in a virtual server using
windows authentication and restricted to local ips only. While looking
at all the documentation I can find this should work perfectly I'm still
a little worried about having it on a server connected directly to the
net. Anyone know of security flaws in IIS 6.0 running on w2k3 that
would allow users to get into the administration site?


--
Aric
------------------------------------------------------------------------
Aric's Profile: http://www.highdots.com/forums/m1128
View this thread: http://www.highdots.com/forums/t3038625


Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com