Solved

IIS Security

Posted on 2006-11-25
8
1,157 Views
Last Modified: 2013-12-04
hello,experts
  i can see such info in win2k system log (security log):
  successful network logon : user:IUSR_Server domain:Server logon ID:(0x0,0x9D3DD)
                             logon model: 3      logon procedure: IIS
                             authentication process:MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
                             workstation:Server
  how this happen?can they really logon my system? what can they do on my machine? i have stoped the SERVER process.but the same infomation still  happen at about 03:00~05:00.
  what can i do then?i want to make my system more strong.    
0
Comment
Question by:martinbjlee
8 Comments
 
LVL 9

Accepted Solution

by:
trenes earned 84 total points
Comment Utility
Hi martinbjlee,

Run the Microsoft Baseline Security Tool to see if you are well protected or not.
IUSR user is used by IIS and I think its just the IIS process that logs on not a user but run the MBSA tool.
http://www.microsoft.com/technet/security/tools/mbsahome.mspx


Cheers!
regards,

Trenes
0
 
LVL 27

Expert Comment

by:Jason Watkins
Comment Utility
The IUSR_Server account is the generic account used to access resources over HTTP that the server is providing.  This account should not be used to access anything but web-content.  If this server is running IIS 5.0, then you must consider running the IIS lock-down tool to secure Windows 2000 and IIS.

A better option would be to ugrade your installation to Windows Server 2003 and IIS 6.0.

/F
0
 

Author Comment

by:martinbjlee
Comment Utility
Hi Firebar,
     what shall i do to get "This account should not be used to access anything but web-content".whether the account should be delete from the guest groups?     i will study the IIS lock-down tool.

Hi Trenes,
     i intall the MBSA tool on the server at Friday,but it can't run ,i don't konw what 's the problem.
     what document i can study  to find what the IUSR_Server 's info,i think i must study it .
0
Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

 

Author Comment

by:martinbjlee
Comment Utility
Hi Firebar,
     where can i download the IIS lock_down tool ?the tool is for IIS 5.0 security ?
0
 
LVL 27

Assisted Solution

by:Jason Watkins
Jason Watkins earned 83 total points
Comment Utility
The IIS lock-down tool can be downloaded from Microsoft's web-site.  

Try:  http://www.google.com/microsoft  and search for the IIS lock-down tool.  I am sorry, I don't know the exact URL.

I would start by determining the group membership the IUSR account has involvment.  Take the critical areas of the filesystem and make sure that user account and it's groups do not have unauthorized access to that filesystem.  The IIS lock-down tool will help to do exactly that.

/F
0
 
LVL 23

Assisted Solution

by:Tim Holman
Tim Holman earned 83 total points
Comment Utility
Please don't delete the IUSR account, otherwise your web server won't work, and IIS will undoubtedly need reinstalling!
MSBA 2.0 is a good start - but think about other things too -ie physical security, policies, procedures, run regular vulnerability scans, as MSBA alone will not offer you compelte protection.
0
 
LVL 1

Expert Comment

by:Computer101
Comment Utility
Forced accept.

Computer101
EE Admin
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

In a recent article here at Experts Exchange (http://www.experts-exchange.com/articles/18880/PaperPort-14-in-Windows-10-A-First-Look.html), I discussed my nine-month sandbox testing of the Windows 10 Technical Preview, specifically with respect to r…
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now