Re: Hosting Web Services





"Mr. Arnold" wrote:


"davebythesea" <davebythesea@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:558124AD-B3E5-4800-9A2A-D918A2D290D6@xxxxxxxxxxxxxxxx
Hi,

Thanks for your replies. Yeh I'd considered just buying some hosting, but
think it might be fun to have a play with my own server - obviously using
caution in terms of security. The last thing i want is to have my server
hacked! Still, its probably easier to just buy a host package, but I might
want to transfer unlimited amounts of data and dont want to end up paying
over the odds if I can host it all locally and be in more control. We'll
see
I guess...

Like I said, Web server and Security admins can hardly do it, and they have
read the books, and they have been given the proper training, to secure a
Web Server, running the Windows platform, and the Web server is being
exposed to the public Internet.

There is no such thing as caution in terms of security. You had better know
what you're doing security wise with the Windows O/S and IIS, as otherwise,
it's just hack bait you're putting out there to be attacked and used as a
jumping off point to attack others.



Would you care to offer some tips on how to secure a web server so it is not
hack bait? You must have learned the secrets somewhere, care to share a good
reference to doing it 'right'?

Cheers,
dav

Dav
.



Relevant Pages

  • [NT] VisNetic WebSite Denial of Service
    ... Beyond Security would like to welcome Tiscali World Online ... VisNetic WebSite is a secure ... Windows-based web server that supports multiple domains, ... It should be noted that an attack will still be caught in the log file for ...
    (Securiteam)
  • [NT] Poisoning Cached HTTPS Documents in Internet Explorer
    ... Get your security news from a reliable source. ... "poison" a user's browser cache with a malicious document that will later ... The attacker can exploit this vulnerability for "replacing" HTML ... to communicate with a malicious web server over HTTPS without the browser ...
    (Securiteam)
  • [NT] Webserver 4D Weak Password Preservation Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... complete Web Server environment written entirely on top of 4th Dimension, ... WS4D web server saves the passwords somewhere insecure. ...
    (Securiteam)
  • Re: 2003 Web Server Security flaw
    ... "Locked-down windows 2003 Web Server used only to host web sites". ... What is your logic/rationale for Media Player being a required install ... The Media Player patch was the ONLY that FAILED. ... > When talking about computer security, there are areas that have no such ...
    (microsoft.public.windows.server.security)
  • Web session tracking security prob. Vulnerable: IIS and ColdFusion (maybe others)
    ... SECURITY PROBLEMS WITH WEB SERVERS' SESSION TRACKING MECHANISMS. ... 2001 we reported the following problem (with specifics to IIS and SITESERVER) to the Microsoft Security Response Center. ... These vulnerabilities, especially when combined with well-known cross-site scripting vulnerabilities, could cause loss of confidentiality, failure of non-repudiation and fraud. ... The browser stores and returns the "ASPSESSIONID" or "CFID/CFTOKEN" values with each subsequent request to the web server. ...
    (Vuln-Dev)

Quantcast