Results 1 to 3 of 3

Thread: Should I be paranoid?

  1. #1

    Thread Starter
    Black Cat JoshT's Avatar
    Join Date
    Nov 2000
    Location
    WNY, USA
    Posts
    4,032

    Should I be paranoid?

    I have W2K Pro (Workstation) SP1 with IIS running on it if I ever need it. IIS5 is installed but I haven't yet configured anything or changed the default installation. Are there any security holes with it or its default installation. Because I recieved the following Web Server / OS sniff the other day (this is the entire logfile). Also, I changed the IP address because it appears to be one my parent company owns, (it's running HP-UX) and I have no control over how secure their network is.

    I'm probably being too paranoid, they were probably just doing a security audit or something.

    Thanks,
    Josh


    #Software: Microsoft Internet Information Services 5.0
    #Version: 1.0
    #Date: 2001-04-24 23:12:12
    #Fields: time c-ip cs-method cs-uri-stem sc-status
    23:12:12 192.168.254.55 HEAD /iisstart.asp 200
    Josh
    Get these: Mozilla Opera OpenBSD
    I have books for sale: "MCSD in a Nutshell" and "VB Distributed Exam Cram" - PM me for details. Will also trade for a decent ATX Pentium 2 MB/CPU/RAM combo.

  2. #2
    Junior Member
    Join Date
    Nov 1999
    Location
    Socal, USA
    Posts
    25

    Smile Paraniod? Never!

    Hi.
    When it comes to security when dealing with web servers, you can never to be paraniod. To answer your question, yes. IIS5 has many security problems what are (I'm sorry to say) easy to exploit. One such problem is the uni-code problem.

    If you are not using the service full time, I would recommend turning it off. Not only will turning the service off help your security, but it will also free (always) valuable system resources. However, there are some times when you must leave IIS on, in which case all I can tell you to do is: Do your homework and research flaws!

    Hope I have helped you somewhat out of your paranioa. You can never to be paraniod .
    Thanks,
    JT
    To error is human, and stupid.
    I may be inconsistent, but not all the time.
    He who laughs last thinks slowest.

  3. #3
    Addicted Member
    Join Date
    Nov 2000
    Location
    UK
    Posts
    164
    You may find this list of articles of use:

    http://www.4guysfromrolla.com/webtec...e/Security.asp

    Alex
    ASP, SQL, VB6, Java Script and dubious guitar playing skills.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  



Click Here to Expand Forum to Full Width