IIS Security

hello,experts
  i can see such info in win2k system log (security log):
  successful network logon : user:IUSR_Server domain:Server logon ID:(0x0,0x9D3DD)
                             logon model: 3      logon procedure: IIS
                             authentication process:MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
                             workstation:Server
  how this happen?can they really logon my system? what can they do on my machine? i have stoped the SERVER process.but the same infomation still  happen at about 03:00~05:00.
  what can i do then?i want to make my system more strong.    
martinbjleeAsked:
Who is Participating?
 
trenesConnect With a Mentor Commented:
Hi martinbjlee,

Run the Microsoft Baseline Security Tool to see if you are well protected or not.
IUSR user is used by IIS and I think its just the IIS process that logs on not a user but run the MBSA tool.
http://www.microsoft.com/technet/security/tools/mbsahome.mspx


Cheers!
regards,

Trenes
0
 
Jason WatkinsIT Project LeaderCommented:
The IUSR_Server account is the generic account used to access resources over HTTP that the server is providing.  This account should not be used to access anything but web-content.  If this server is running IIS 5.0, then you must consider running the IIS lock-down tool to secure Windows 2000 and IIS.

A better option would be to ugrade your installation to Windows Server 2003 and IIS 6.0.

/F
0
 
martinbjleeAuthor Commented:
Hi Firebar,
     what shall i do to get "This account should not be used to access anything but web-content".whether the account should be delete from the guest groups?     i will study the IIS lock-down tool.

Hi Trenes,
     i intall the MBSA tool on the server at Friday,but it can't run ,i don't konw what 's the problem.
     what document i can study  to find what the IUSR_Server 's info,i think i must study it .
0
Improved Protection from Phishing Attacks

WatchGuard DNSWatch reduces malware infections by detecting and blocking malicious DNS requests, improving your ability to protect employees from phishing attacks. Learn more about our newest service included in Total Security Suite today!

 
martinbjleeAuthor Commented:
Hi Firebar,
     where can i download the IIS lock_down tool ?the tool is for IIS 5.0 security ?
0
 
Jason WatkinsConnect With a Mentor IT Project LeaderCommented:
The IIS lock-down tool can be downloaded from Microsoft's web-site.  

Try:  http://www.google.com/microsoft  and search for the IIS lock-down tool.  I am sorry, I don't know the exact URL.

I would start by determining the group membership the IUSR account has involvment.  Take the critical areas of the filesystem and make sure that user account and it's groups do not have unauthorized access to that filesystem.  The IIS lock-down tool will help to do exactly that.

/F
0
 
Tim HolmanConnect With a Mentor Commented:
Please don't delete the IUSR account, otherwise your web server won't work, and IIS will undoubtedly need reinstalling!
MSBA 2.0 is a good start - but think about other things too -ie physical security, policies, procedures, run regular vulnerability scans, as MSBA alone will not offer you compelte protection.
0
 
Computer101Commented:
Forced accept.

Computer101
EE Admin
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.