Welcome to MobyThreads.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in
All support for the MobyThreads Threaded phpBB MOD can now be found on welsolutions at this forum

How to secure a web server?

 
   Web Hosting and Web Master Forums (Home) -> IIS RSS
Next:  Class not registered error  
Author Message
user2286

External


Since: Oct 15, 2004
Posts: 1



(Msg. 1) Posted: Fri Oct 15, 2004 3:39 am
Post subject: How to secure a web server?
Archived from groups: microsoft>public>inetserver>iis, others (more info?)

Hi There!

I'm using Windows Server 2003 with IIS6 for my ASP.NET website.

What programs do I need on my server to secure my web server 99%? I've got
ZoneAlarm on my web server. However, I'm sure I need much more than just a
firewall, to prevent attacks such as Denial of Service, hackers, data
theft...etc.

So I would like to know if you guys can point me out the security programs
that a web server must have?

And thinking out of the square, should I install hardware firewall? If so,
which are the good ones? Please advice!

Many thanks in advance!!

David

 >> Stay informed about: How to secure a web server? 
Back to top
Login to vote
nospam_arek

External


Since: Oct 14, 2004
Posts: 1



(Msg. 2) Posted: Fri Oct 15, 2004 3:39 am
Post subject: Re: How to secure a web server? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

If you are serious about securing the web server, you should consider a
professional firewall/proxy combination, such as ISA Server. If you want to
find out more about ISA, check here:
<a style='text-decoration: underline;' href="http://www.microsoft.com/isaserver/" target="_blank">http://www.microsoft.com/isaserver/</a>

--
Arek Iskra
MVP for Windows Server - Software Distribution


"David Freeman" <no-email DeleteThis @mailingspam.com> wrote in message
news:OjxB6JesEHA.1308@tk2msftngp13.phx.gbl...
 > Hi There!
 >
 > I'm using Windows Server 2003 with IIS6 for my ASP.NET website.
 >
 > What programs do I need on my server to secure my web server 99%? I've got
 > ZoneAlarm on my web server. However, I'm sure I need much more than just a
 > firewall, to prevent attacks such as Denial of Service, hackers, data
 > theft...etc.
 >
 > So I would like to know if you guys can point me out the security programs
 > that a web server must have?
 >
 > And thinking out of the square, should I install hardware firewall? If so,
 > which are the good ones? Please advice!
 >
 > Many thanks in advance!!
 >
 > David
 ><!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: How to secure a web server? 
Back to top
Login to vote
jackieja

External


Since: Aug 26, 2003
Posts: 392



(Msg. 3) Posted: Fri Oct 15, 2004 3:39 am
Post subject: RE: How to secure a web server? [Login to view extended thread Info.]
Archived from groups: microsoft>public>inetserver>iis (more info?)

You might want to check out this web site:
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/secmod/html
/secmod104.asp

This has a checklist on how to secure your web server.

Hope this helps!

Thank you,

Jackie Jaynes [MSFT]
Microsoft IIS
JackieJa RemoveThis @online.microsoft.com

Please do not send email directly to this alias. This
is our online account name for newsgroup participation only.

This posting is provided "AS IS" with no warranties, and confers no rights.
You assume all risk for your use. © 2001 Microsoft Corporation. All rights
reserved.
 >> Stay informed about: How to secure a web server? 
Back to top
Login to vote
user2287

External


Since: Oct 14, 2004
Posts: 2



(Msg. 4) Posted: Fri Oct 15, 2004 3:39 am
Post subject: Re: How to secure a web server? [Login to view extended thread Info.]
Archived from groups: microsoft>public>inetserver>iis, others (more info?)

"David Freeman" <no-email.DeleteThis@mailingspam.com> wrote in message
news:OjxB6JesEHA.1308@tk2msftngp13.phx.gbl...
 > Hi There!
 >
 > I'm using Windows Server 2003 with IIS6 for my ASP.NET website.
 >
 > What programs do I need on my server to secure my web server 99%? I've got
 > ZoneAlarm on my web server. However, I'm sure I need much more than just a
 > firewall, to prevent attacks such as Denial of Service, hackers, data
 > theft...etc.
 >
 > So I would like to know if you guys can point me out the security programs
 > that a web server must have?
 >
 > And thinking out of the square, should I install hardware firewall? If so,
 > which are the good ones? Please advice!
 >
 > Many thanks in advance!!
 >
 > David
 >

How To Install and Use the IIS Lockdown Wizard
<a style='text-decoration: underline;' href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;325864" target="_blank">http://support.microsoft.com/default.aspx?scid=kb;EN-US;325864</a><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: How to secure a web server? 
Back to top
Login to vote
user2287

External


Since: Oct 14, 2004
Posts: 2



(Msg. 5) Posted: Fri Oct 15, 2004 3:39 am
Post subject: Re: How to secure a web server? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Colin Nash [MVP]" <cnash x@x mvps.org> wrote in message
news:e07%23Y2ksEHA.1272@TK2MSFTNGP12.phx.gbl...
 >
  >>
 >
 > How To Install and Use the IIS Lockdown Wizard
<font color=purple> > <a style='text-decoration: underline;' href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;325864</font" target="_blank">http://support.microsoft.com/default.aspx?scid=kb;EN-US;325864</font</a>>
 >

I'm not clear on whether it works on 6.0... kb is a little murky on that and
I've never actually tried it.

Anyway, more info: <a style='text-decoration: underline;' href="http://support.microsoft.com/kb/814874" target="_blank">http://support.microsoft.com/kb/814874</a><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: How to secure a web server? 
Back to top
Login to vote
n9rou

External


Since: Oct 14, 2004
Posts: 2



(Msg. 6) Posted: Fri Oct 15, 2004 3:39 am
Post subject: Re: How to secure a web server? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi Colin.

The IIS Lockdown tool is not needed on Windows 2003 with IIS6.0 and I am not
sure whether it will even run. URLscan can still be used on IIS6.0 though
IIS6.0 is much hardened by default compared to erlier versions of IIS. The
link below explains more on this. It is getting harder to keep track of all
the various operating systems and applications! --- Steve

<a style='text-decoration: underline;' href="http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/deployguide/en-us/Default.asp?url=/resources/documentation/windowsserv/2003/all/deployguide/en-us/iisdg_mei_nsjz.asp" target="_blank">http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/...loyguid</a>

"Colin Nash [MVP]" <cnash x@x mvps.org> wrote in message
news:ubF8M4ksEHA.1220@TK2MSFTNGP10.phx.gbl...
 >
 > "Colin Nash [MVP]" <cnash x@x mvps.org> wrote in message
 > news:e07%23Y2ksEHA.1272@TK2MSFTNGP12.phx.gbl...
  >>
   >>>
  >>
  >> How To Install and Use the IIS Lockdown Wizard
<font color=green>  >> <a style='text-decoration: underline;' href="http://support.microsoft.com/default.aspx?scid=kb;EN-US;325864</font" target="_blank">http://support.microsoft.com/default.aspx?scid=kb;EN-US;325864</font</a>>
  >>
 >
 > I'm not clear on whether it works on 6.0... kb is a little murky on that
 > and I've never actually tried it.
 >
<font color=purple> > Anyway, more info: <a style='text-decoration: underline;' href="http://support.microsoft.com/kb/814874</font" target="_blank">http://support.microsoft.com/kb/814874</font</a>>
 ><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: How to secure a web server? 
Back to top
Login to vote
kenremove

External


Since: Aug 23, 2003
Posts: 2901



(Msg. 7) Posted: Fri Oct 15, 2004 5:26 pm
Post subject: Re: How to secure a web server? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Whilst some have made recommendations with regard to software you can use
(ISA Server, URLScan), you need to remember that security is not "a product"
you install, but a process.

Security involves evaluating threats, and working out what the consequences
are to you and what the likelihood of them occuring is, and whether it makes
sense to take the time and money to stop/mitigate the threat. Security is
often described as "a journey not a destination - there is no such thing as
the perfectly secure system".

For information on best practise security options, check the Windows 2003
and IIS security centres here:
<a style='text-decoration: underline;' href="http://www.microsoft.com/technet/security/default.mspx" target="_blank">http://www.microsoft.com/technet/security/default.mspx</a>

But remember, installing a firewall doesn't help you if you don't patch you
server and someone discovers a buffer overflow in IIS. A firewall doesn't
help if you have a weak password, and you allow terminal services through
your firewall. Firewall doesn't help if someone comes and steals your box
(etc, etc, etc). There is a lot more to "security" than just installing some
software.

Cheers
Ken


"David Freeman" <no-email.DeleteThis@mailingspam.com> wrote in message
news:OjxB6JesEHA.1308@tk2msftngp13.phx.gbl...
 > Hi There!
 >
 > I'm using Windows Server 2003 with IIS6 for my ASP.NET website.
 >
 > What programs do I need on my server to secure my web server 99%? I've got
 > ZoneAlarm on my web server. However, I'm sure I need much more than just a
 > firewall, to prevent attacks such as Denial of Service, hackers, data
 > theft...etc.
 >
 > So I would like to know if you guys can point me out the security programs
 > that a web server must have?
 >
 > And thinking out of the square, should I install hardware firewall? If so,
 > which are the good ones? Please advice!
 >
 > Many thanks in advance!!
 >
 > David
 ><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: How to secure a web server? 
Back to top
Login to vote
mvpnospam1

External


Since: Feb 25, 2004
Posts: 4



(Msg. 8) Posted: Sat Oct 16, 2004 3:15 am
Post subject: Re: How to secure a web server? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

All prior comment in stride, and not intending to discount,
may I add two ideas/opinions:
1. ditch the ZA, use the W2k3 provided or IPsec as a filter
if you feel you need another layer after your hw firewall
or your proxy. Besides, in my experience on dev IIS client
machine, ZA post 5.x kills convenient use of http
2. look at the best practices for Asp.Net - its design/authoring
and its admin. Your biggest threat is a bad Asp.Net app.

--
Roger Abell
Microsoft MVP (Windows Server System: Security)
MCSE (W2k3,W2k,Nt4) MCDBA
"David Freeman" <no-email.TakeThisOut@mailingspam.com> wrote in message
news:OjxB6JesEHA.1308@tk2msftngp13.phx.gbl...
 > Hi There!
 >
 > I'm using Windows Server 2003 with IIS6 for my ASP.NET website.
 >
 > What programs do I need on my server to secure my web server 99%? I've got
 > ZoneAlarm on my web server. However, I'm sure I need much more than just a
 > firewall, to prevent attacks such as Denial of Service, hackers, data
 > theft...etc.
 >
 > So I would like to know if you guys can point me out the security programs
 > that a web server must have?
 >
 > And thinking out of the square, should I install hardware firewall? If so,
 > which are the good ones? Please advice!
 >
 > Many thanks in advance!!
 >
 > David
 >
 ><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: How to secure a web server? 
Back to top
Login to vote
mohammadsh

External


Since: Oct 16, 2004
Posts: 1



(Msg. 9) Posted: Sat Oct 16, 2004 6:07 am
Post subject: RE: How to secure a web server? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

i would really recommend reading the "Improving Web Application
Security-Threats and Countermeasures" beast practices guide from Microsoft

"David Freeman" wrote:

 > Hi There!
 >
 > I'm using Windows Server 2003 with IIS6 for my ASP.NET website.
 >
 > What programs do I need on my server to secure my web server 99%? I've got
 > ZoneAlarm on my web server. However, I'm sure I need much more than just a
 > firewall, to prevent attacks such as Denial of Service, hackers, data
 > theft...etc.
 >
 > So I would like to know if you guys can point me out the security programs
 > that a web server must have?
 >
 > And thinking out of the square, should I install hardware firewall? If so,
 > which are the good ones? Please advice!
 >
 > Many thanks in advance!!
 >
 > David
 >
 >
 ><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: How to secure a web server? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
"a secure communications channel could not be established .. - Everytime I click on the Custom Errors dialog, I get the error message: "a secure communications channel could not be established with the target server" I am connecting to the server from the local console, so I don't understand what the p...

Secure FTP - I need help setting up a secure (encrypted) FTP site. I use IIS 5.0 Can anyone offer any good advice, resources? thanks! jason.whitaker@titan.com

Secure SMTP - Where might I find GOOD documentation on securing the SMTP Service on my IIS 5.0 server?

secure certificate - Hi, i have my web site ready to be launched. Some parts of the site need to be secure (using SSL). how do I specify which directories need to use SSL and which do not? thanks rafael

Secure Certificates - Hi Everyone, I have a client is hosting their site on a secure server....however, they are linking out to another server where the content is not secure (using http) and they get the dialog box saying stuff about non-secure items. They have asked if the...
   Web Hosting and Web Master Forums (Home) -> IIS All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]