Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

IIS security question

Thread Tools
 
Search this Thread
 
Old 21 June 2002, 12:24 PM
  #1  
Rob Walker
Scooby Regular
Thread Starter
 
Rob Walker's Avatar
 
Join Date: Nov 1999
Location: Stockport
Posts: 474
Likes: 0
Received 0 Likes on 0 Posts
Post

Hi,

I'm in the process of setting up an IIS server for work. Do I need to run a firewall and virus checker on the server or should it be ok without as long as all the latest patches/fixes are installed?

Cheers
Rob
Old 21 June 2002, 12:28 PM
  #2  
ADP
Scooby Regular
 
ADP's Avatar
 
Join Date: Apr 2001
Posts: 3,823
Likes: 0
Received 1 Like on 1 Post
Post

Well is it sat behind any other firewalls???
Old 21 June 2002, 12:40 PM
  #3  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Post

needs a virus scanner regardless... dont care what you say...

David
Old 21 June 2002, 01:10 PM
  #4  
Rob Walker
Scooby Regular
Thread Starter
 
Rob Walker's Avatar
 
Join Date: Nov 1999
Location: Stockport
Posts: 474
Likes: 0
Received 0 Likes on 0 Posts
Post

No its not behind any other firewall, its just a bare server connected to the net.

Cheers
Rob
Old 21 June 2002, 01:28 PM
  #5  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Post

Connected to the net as in Internet or internal Lan?

If its just sat on internet I would at a minimum block all ports other than 80 and open up whatever you need...

David
Old 21 June 2002, 01:35 PM
  #6  
Rob Walker
Scooby Regular
Thread Starter
 
Rob Walker's Avatar
 
Join Date: Nov 1999
Location: Stockport
Posts: 474
Likes: 0
Received 0 Likes on 0 Posts
Post

Sorry.. its connected to the internet.

Can you block ports from within IIS or would I have to run a firewall to do that?

Cheers
Rob
Old 21 June 2002, 01:45 PM
  #7  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Post

do it under network properties, tcp/ip, properties, advanced, enable security.... I would still recommend a firewall though!

David
Old 21 June 2002, 01:58 PM
  #8  
Rob Walker
Scooby Regular
Thread Starter
 
Rob Walker's Avatar
 
Join Date: Nov 1999
Location: Stockport
Posts: 474
Likes: 0
Received 0 Likes on 0 Posts
Post

Nice one. Thanks for your help. I'll go and have a look at firewalls now.

Cheers
Rob
Old 21 June 2002, 03:08 PM
  #9  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

You need to strip out some of the installed samples etc.

There's a basic lock down guide on for IIS 5 on microsoft.com/technet
Old 21 June 2002, 03:17 PM
  #10  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post


Sorry, but the safest thing would be to not install IIS unless you absolutely have to. Can't you use apache ?

And block all ports apart from 80 , and rename the administrator account and run an anti-virus and sit it behind a firewall and all of the other lockdown stuff .

Steve
Old 21 June 2002, 03:53 PM
  #11  
Rob Walker
Scooby Regular
Thread Starter
 
Rob Walker's Avatar
 
Join Date: Nov 1999
Location: Stockport
Posts: 474
Likes: 0
Received 0 Likes on 0 Posts
Post

Have to use IIS unfortunately. Need it for ASP and we're using custom COM components as well...

Old 21 June 2002, 03:58 PM
  #12  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

Tie it all down then. Run a firewall in front of it - if you are tight on time or the beancounters are having an off day, then a smoothwall will be enough. Don't use a software firewall on anything like a production machine.

Steve
Old 21 June 2002, 04:24 PM
  #13  
kryten
Scooby Regular
 
kryten's Avatar
 
Join Date: May 2000
Posts: 869
Likes: 0
Received 0 Likes on 0 Posts
Post

1) Patch IIS
2) Get a firewall (you could use a software one, hardware is better)
3) Patch IIS (there will be a new one by now!)

Bascially, you want to disable everything you're not going to be using. If this is your first attempt then I would suggest you leave the machine on the net for a week or so BEFORE you add anything even remotely important to it!

Also, make sure its not connected to the rest of your network - if it is then pay someone who knows what they're going (because you'll need a DMZ for it and its SO easy to get it wrong).

If you're determined to DIY then Securing win2k/NT servers for the Internet by O'Reilly is a must have as is the IIS Lockdown tool from MS (does a lot of the stuff for you).
Old 21 June 2002, 05:11 PM
  #14  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Baseline Security Scanner from MS is very handy as well.
Old 21 June 2002, 05:20 PM
  #15  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

As is the off button.

Old 21 June 2002, 06:44 PM
  #16  
Rob Walker
Scooby Regular
Thread Starter
 
Rob Walker's Avatar
 
Join Date: Nov 1999
Location: Stockport
Posts: 474
Likes: 0
Received 0 Likes on 0 Posts
Post

A hardware firewall is out of the question at the moment. The server is in a remote location at the moment. We'll possibly move it in house in the future depending on how things go.

Anyone got any suggestions for a good (cheap) firewall. Personally I use Sygate at the moment and was thinking of using that. Not too keen on Zonealarm cos I've had a few problems with that in the past.

Cheers for all the help
Rob
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
Brzoza
Engine Management and ECU Remapping
1
02 October 2015 05:26 PM
BLU
Computer & Technology Related
11
02 October 2015 12:53 PM
Mad Hammer
Subaru Parts
2
29 September 2015 08:15 PM
The Joshua Tree
Computer & Technology Related
30
28 September 2015 02:43 PM



Quick Reply: IIS security question



All times are GMT +1. The time now is 10:01 AM.