|
| |
|
|
c1sissy
Posts: 5084 Joined: 7/20/2002 From: NJ Status: offline
|
IIS Lockdown tool - 3/16/2003 12:20:32
Could someone explain the IIS lockdown tool for me? I have a program called Microsoft Baseline Security Analizer, which I ran on my computer and it says that I need this. It refers to this as me being in high risk because I don' t have this. Like I said, I am below beginner on this one, so appreciate any help that comes my way.
_____________________________
Deb-aka-c4Ksissy high panjandurum and alpha female of the silverback tribe As decreed by Jesper 5-24-2003. The only stupid question is... the one that is never asked!! http://directory.css-styling.com http://fmsforum.com http://positioniseverything.net/ http://www.tanfa.co.uk/
|
|
|
|
Doug G
Posts: 1189 Joined: 12/29/2001 From: SoCal Status: offline
|
RE: IIS Lockdown tool - 3/16/2003 13:28:24
This is a security tool that disables various features of IIS that may pose a security risk. If your web server is exposed to the Internet you should consider using the IIS lockdown wizard. In many cases the tool is too restrictive and disables things you need for development purposes, like asp processing & such, and you should consider what features you want off & on. http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/tools/locktool.asp
_____________________________
====== Doug G ======
|
|
|
|
c1sissy
Posts: 5084 Joined: 7/20/2002 From: NJ Status: offline
|
RE: IIS Lockdown tool - 3/16/2003 13:33:41
Doug: Thanks again for coming to my rescue with an answer! I' ll read the information at the link that you provided before I pose any more questions that I have in regards to your answer. I need to remember to use Microsoft a bit more. I always forget about it. Though I do search these things, I never thought about MS. Have a great day! Thanks again.
_____________________________
Deb-aka-c4Ksissy high panjandurum and alpha female of the silverback tribe As decreed by Jesper 5-24-2003. The only stupid question is... the one that is never asked!! http://directory.css-styling.com http://fmsforum.com http://positioniseverything.net/ http://www.tanfa.co.uk/
|
|
|
|
Doug G
Posts: 1189 Joined: 12/29/2001 From: SoCal Status: offline
|
RE: IIS Lockdown tool - 3/16/2003 15:57:34
The link above came from a google search for " iis lockdown tool" . I' d be lost without my Google toolbar :)
_____________________________
====== Doug G ======
|
|
|
|
caywind
Posts: 1479 From: USA Status: offline
|
RE: IIS Lockdown tool - 3/16/2003 17:49:35
Please note: It is highly recommended that you back everything up, before running the tool. Also, the baseline security analyzer is probably going to report that to all installations of IIS on NT or W2K. Here' s what happened. The default installation of IIS created some other webs like admin and ???. The admin website is used to administer IIS from a web browser. It was soon realized that this pretty much left the web server (IIS) wide open. The lockdown tool was implemented to close down access to this site and address a lot of other security issues in IIS. Unfortunately, it tends to go overboard, and after it runs, nobody can get access to any sites. If possible, I would just run it on a test server first, but you may not have a " spare" server laying around....
|
|
|
|
storm
Posts: 421 Status: offline
|
RE: IIS Lockdown tool - 3/20/2003 6:16:38
Looking for security guidelines...visit the NSA website. Yes, The National Secuirty Agency. All manner of good recommendations for locking down Windows boxes. http://www.nsa.gov/snac/index.html
_____________________________
storm..." Someone put forth the proposition that you can petition the lord with prayer, petition the lord with prayer, petition the lord with prayer...YOU CANNOT PETITION THE LORD WITH PRAYER"
|
|
New Messages |
No New Messages |
Hot Topic w/ New Messages |
Hot Topic w/o New Messages |
Locked w/ New Messages |
Locked w/o New Messages |
|
Post New Thread
Reply to Message
Post New Poll
Submit Vote
Delete My Own Post
Delete My Own Thread
Rate Posts
|
|
|