Go Back   PCMech Forums > Help & Discussion > Internet, Web Applications, & The Cloud

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 02-27-2006, 11:01 AM   #1
Member (8 bit)
 
Join Date: Mar 2004
Posts: 213
Concerns running IIS

What are some security concerns running IIS 6 if any? How do I minimize some of these security holes? Mainly I'm going to use IIS for running WSUS. It is require by this application. What are some suggestions on how to configure IIS so that it will at the very minimal for WSUS?
ljCharlie is offline   Reply With Quote
Old 02-27-2006, 11:18 AM   #2
Staff
Premium Member
 
mairving's Avatar
 
Join Date: Jul 1999
Location: Arlington, TN
Posts: 5,538
Will this server be on the public internet?
__________________

Want to Make $$$$ with your Computer? No Risk! Simply press shift-4 four times in a row
mairving is offline   Reply With Quote
Old 02-27-2006, 01:29 PM   #3
Member (8 bit)
 
Join Date: Mar 2004
Posts: 213
This server is intended for private use but it does have a public IP.
ljCharlie is offline   Reply With Quote
Old 02-27-2006, 02:03 PM   #4
Come in Ray...
 
faulkner132's Avatar
 
Join Date: Sep 2004
Posts: 1,668
IIS is pretty secure out of the box. You shouldn't have to do anything just to get an html/asp/php site running.

The only thing which introduces security holes is when you start tinkering with accounts the IIS services run as. Very seldom do you have to do this though.
faulkner132 is offline   Reply With Quote
Old 02-27-2006, 02:15 PM   #5
Member (8 bit)
 
Join Date: Mar 2004
Posts: 213
Thanks!
ljCharlie is offline   Reply With Quote
Old 02-27-2006, 02:21 PM   #6
Staff
Premium Member
 
mairving's Avatar
 
Join Date: Jul 1999
Location: Arlington, TN
Posts: 5,538
Quote:
Originally Posted by faulkner132
IIS is pretty secure out of the box. You shouldn't have to do anything just to get an html/asp/php site running.

The only thing which introduces security holes is when you start tinkering with accounts the IIS services run as. Very seldom do you have to do this though.
IIS 6 is certainly better and more secure than IIs 5. With V5, you had to run the lockdown tool and URLscan to secure it. Not as big an issue with 6.
mairving is offline   Reply With Quote
Old 02-27-2006, 03:43 PM   #7
Its the Dark Side!
 
ComputerNut's Avatar
 
Join Date: Jan 2004
Location: Kitchener, Ontario, Canada
Posts: 1,111
Send a message via MSN to ComputerNut
I used IIS for awhile when running an FTP/Web server. Then I learned of how it can be a danger using IIS for public use. I then switched to Apache, and my server has been running properly without a hitch. But for internal use, IIS shouldnt really pose a security hole.

HTH
__________________
CN
My Rig: "Dark Lord"
Asus P5B - Intel Core 2 Duo E6400 - 1GB DDR2 667 RAM - Seagate SATAII 80GB HDD - Seagate SATAII 250GB HDD - Lite-On DVD -/+ RW Drive - nVidia GeForce 7600 GS - ATi TV Wonder VE

ComputerNut is offline   Reply With Quote
Old 02-27-2006, 03:50 PM   #8
Member (8 bit)
 
Join Date: Mar 2004
Posts: 213
Okay, so if I only allow IP address of all my computers to access the IIS server then that should do it, right? What other things should I consider?
ljCharlie is offline   Reply With Quote
Old 02-27-2006, 03:58 PM   #9
Its the Dark Side!
 
ComputerNut's Avatar
 
Join Date: Jan 2004
Location: Kitchener, Ontario, Canada
Posts: 1,111
Send a message via MSN to ComputerNut
you shouldnt need to do that. Just dont foward any ports on your router that IIS will be using (i.e. If you were to use IIS as a web server, just dont foward port 80 on your router to direct any incoming requests on that port to your server IP. Beyond that, you can set it up so you would need to type the IP address of the server on whatever client computer you are on.

HTH
ComputerNut is offline   Reply With Quote
Old 02-27-2006, 04:31 PM   #10
Come in Ray...
 
faulkner132's Avatar
 
Join Date: Sep 2004
Posts: 1,668
ComputerNut,

If he wants to publish his website using IIS on a public IP, he will have to set up port forwarding on his router. Otherwise port 80 would be blocked.

What security issues did you find with IIS 6? I would be interested to know as I have about 100 ASP.Net sites running off IIS 6.
faulkner132 is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 12:59 AM.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0