navigation
a webmaster learning community
     Home    Register     Search      Help      Login    
Sponsors

Shopping Cart Software
Ecommerce software integrated into Frontpage, Dreamweaver and Golive templates. No monthly fees and available in ASP and PHP versions.

Website Templates
We also have a wide selection of Dreamweaver, Expression Web and Frontpage templates as well as webmaster tools and CSS layouts.

Frontpage website templates
Creative Website Templates for FrontPage, Dreamweaver, Flash, SwishMax

Search Forums
 

Advanced search
Recent Posts

 Todays Posts
 Most Active posts
 Posts since last visit
 My Recent Posts
 Mark posts read

Microsoft MVP

 

IIS Lockdown tool

 
View related threads: (in this forum | in all forums)

Logged in as: Guest
Users viewing this topic: none
Printable Version 

All Forums >> Web Development >> Server Issues >> IIS Lockdown tool
Page: [1]
 
c1sissy

 

Posts: 5084
Joined: 7/20/2002
From: NJ
Status: offline

 
IIS Lockdown tool - 3/16/2003 12:20:32   
Could someone explain the IIS lockdown tool for me? I have a program called Microsoft Baseline Security Analizer, which I ran on my computer and it says that I need this. It refers to this as me being in high risk because I don' t have this.

Like I said, I am below beginner on this one, so appreciate any help that comes my way.

_____________________________

Deb-aka-c4Ksissy
high panjandurum and alpha female of the silverback tribe
As decreed by Jesper 5-24-2003.
The only stupid question is... the one that is never asked!!
http://directory.css-styling.com
http://fmsforum.com
http://positioniseverything.net/
http://www.tanfa.co.uk/
Doug G

 

Posts: 1189
Joined: 12/29/2001
From: SoCal
Status: offline

 
RE: IIS Lockdown tool - 3/16/2003 13:28:24   
This is a security tool that disables various features of IIS that may pose a security risk.

If your web server is exposed to the Internet you should consider using the IIS lockdown wizard. In many cases the tool is too restrictive and disables things you need for development purposes, like asp processing & such, and you should consider what features you want off & on.

http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/tools/locktool.asp



_____________________________

======
Doug G
======

(in reply to c1sissy)
c1sissy

 

Posts: 5084
Joined: 7/20/2002
From: NJ
Status: offline

 
RE: IIS Lockdown tool - 3/16/2003 13:33:41   
Doug:
Thanks again for coming to my rescue with an answer!

I' ll read the information at the link that you provided before I pose any more questions that I have in regards to your answer.

I need to remember to use Microsoft a bit more. I always forget about it. Though I do search these things, I never thought about MS.

Have a great day! Thanks again.

_____________________________

Deb-aka-c4Ksissy
high panjandurum and alpha female of the silverback tribe
As decreed by Jesper 5-24-2003.
The only stupid question is... the one that is never asked!!
http://directory.css-styling.com
http://fmsforum.com
http://positioniseverything.net/
http://www.tanfa.co.uk/

(in reply to Doug G)
Doug G

 

Posts: 1189
Joined: 12/29/2001
From: SoCal
Status: offline

 
RE: IIS Lockdown tool - 3/16/2003 15:57:34   
The link above came from a google search for " iis lockdown tool" . I' d be lost without my Google toolbar :)



_____________________________

======
Doug G
======

(in reply to c1sissy)
c1sissy

 

Posts: 5084
Joined: 7/20/2002
From: NJ
Status: offline

 
RE: IIS Lockdown tool - 3/16/2003 17:39:17   
Doug:
I usually use google search, however, I didn' t use it for this subject this time. I did search for some sort of tutorials. I also have the copernic search engine, which I love.

Guess I' ll do some more googling!:)

_____________________________

Deb-aka-c4Ksissy
high panjandurum and alpha female of the silverback tribe
As decreed by Jesper 5-24-2003.
The only stupid question is... the one that is never asked!!
http://directory.css-styling.com
http://fmsforum.com
http://positioniseverything.net/
http://www.tanfa.co.uk/

(in reply to Doug G)
caywind

 

Posts: 1479
From: USA
Status: offline

 
RE: IIS Lockdown tool - 3/16/2003 17:49:35   
Please note: It is highly recommended that you back everything up, before running the tool. Also, the baseline security analyzer is probably going to report that to all installations of IIS on NT or W2K.

Here' s what happened. The default installation of IIS created some other webs like admin and ???. The admin website is used to administer IIS from a web browser. It was soon realized that this pretty much left the web server (IIS) wide open. The lockdown tool was implemented to close down access to this site and address a lot of other security issues in IIS. Unfortunately, it tends to go overboard, and after it runs, nobody can get access to any sites.

If possible, I would just run it on a test server first, but you may not have a " spare" server laying around....

(in reply to c1sissy)
c1sissy

 

Posts: 5084
Joined: 7/20/2002
From: NJ
Status: offline

 
RE: IIS Lockdown tool - 3/18/2003 20:08:37   
Caywind:

The IIS is on my computer. No spare server! I have a windows xp pro with the IIS 5.1.

Also, back up, good idea, lol, my computer wiz nephew always does this for me. Not something that I have ever done. (The one time that I tried, I lost a group of pictures somehow. Of which I am still hanging onto in the hopes that someone in the future will come up with the perfect program to replace what is missing.:))

quote:

Also, the baseline security analyzer is probably going to report that to all installations of IIS on NT or W2K


Please dont think that I' m a duh on this one, but could you please explain this a bit better? Thanks.

_____________________________

Deb-aka-c4Ksissy
high panjandurum and alpha female of the silverback tribe
As decreed by Jesper 5-24-2003.
The only stupid question is... the one that is never asked!!
http://directory.css-styling.com
http://fmsforum.com
http://positioniseverything.net/
http://www.tanfa.co.uk/

(in reply to caywind)
storm

 

Posts: 421
Status: offline

 
RE: IIS Lockdown tool - 3/20/2003 6:16:38   
Looking for security guidelines...visit the NSA website. Yes, The National Secuirty Agency. All manner of good recommendations for locking down Windows boxes.

http://www.nsa.gov/snac/index.html

_____________________________

storm..." Someone put forth the proposition that you can petition the lord with prayer, petition the lord with prayer, petition the lord with prayer...YOU CANNOT PETITION THE LORD WITH PRAYER"

(in reply to c1sissy)
c1sissy

 

Posts: 5084
Joined: 7/20/2002
From: NJ
Status: offline

 
RE: IIS Lockdown tool - 3/20/2003 7:02:05   
Thanks much Storm, I really appreciate this.

_____________________________

Deb-aka-c4Ksissy
high panjandurum and alpha female of the silverback tribe
As decreed by Jesper 5-24-2003.
The only stupid question is... the one that is never asked!!
http://directory.css-styling.com
http://fmsforum.com
http://positioniseverything.net/
http://www.tanfa.co.uk/

(in reply to storm)
Page:   [1]

All Forums >> Web Development >> Server Issues >> IIS Lockdown tool
Page: [1]
Jump to: 1





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts