Re: How to secure a web server?

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 10/15/04


Date: Thu, 14 Oct 2004 21:47:10 -0500

Hi Colin.

The IIS Lockdown tool is not needed on Windows 2003 with IIS6.0 and I am not
sure whether it will even run. URLscan can still be used on IIS6.0 though
IIS6.0 is much hardened by default compared to erlier versions of IIS. The
link below explains more on this. It is getting harder to keep track of all
the various operating systems and applications! --- Steve

http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/deployguide/en-us/Default.asp?url=/resources/documentation/windowsserv/2003/all/deployguide/en-us/iisdg_mei_nsjz.asp

"Colin Nash [MVP]" <cnash x@x mvps.org> wrote in message
news:ubF8M4ksEHA.1220@TK2MSFTNGP10.phx.gbl...
>
> "Colin Nash [MVP]" <cnash x@x mvps.org> wrote in message
> news:e07%23Y2ksEHA.1272@TK2MSFTNGP12.phx.gbl...
>>
>>>
>>
>> How To Install and Use the IIS Lockdown Wizard
>> http://support.microsoft.com/default.aspx?scid=kb;EN-US;325864
>>
>
> I'm not clear on whether it works on 6.0... kb is a little murky on that
> and I've never actually tried it.
>
> Anyway, more info: http://support.microsoft.com/kb/814874
>



Relevant Pages

  • Re: Exchange 2000 and Software Update Services SUS
    ... you'll need to configure URLScan to allow continued access to OWA. ... I would not recommend running SUS on a Domain Controller. ... IIS Lockdown and URLscan Configurations in an Exchange Environment ... : Windows 2000 standard server. ...
    (microsoft.public.inetserver.iis.security)
  • Re: OWA Page not found with special characters
    ... Neither the IIS lockdown tool or URLSCAN have ever been run on this ... I have found several references to others with the same problem, no URLSCAN ... > Modify the Default URLScan Configuration File ...
    (microsoft.public.exchange.clients)
  • Re: How to tell if IIS lockdown Tool is installed?
    ... easily tell if the IIS lockdown Tool as been installed on a machine. ... there but URLscan may have not been installed. ... I have compared the Inetsrv folder whilst IIS lockdown was installed on my ... machines and after I uninstalled it by running the IIS lockdown installation ...
    (microsoft.public.inetserver.iis.security)
  • Help -- W32.Nimda Virus in InetpubScripts Directory
    ... I am not a network ... I believe I have Windows 2000 with SP2, ... but now these viruses are coming in. ... >Patch your machine and run the IIS Lockdown tool from ...
    (microsoft.public.win2000.security)
  • Re: How to get IIS5 functional again
    ... > applying IIS Lockdown tool some time ago. ... > this now doesn't work (with a "Server Application Unavailable" error). ... URLScan Security Tool ...
    (microsoft.public.security)