Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

IIS supports anonymous access, Basic, and Windows NT Challenge/Response (NTLM) authentication. The authentication mechanism in IIS could reveal the type of authentication in use to a remote attacker

Posted on 2009-04-03
16
Medium Priority
?
390 Views
Last Modified: 2012-05-06
Microsoft Internet Information Server (IIS) supports anonymous access, Basic, and Windows NT Challenge/Response (NTLM) authentication. The authentication mechanism in IIS could reveal the type of authentication in use to a remote attacker. A remote attacker can send a specially-crafted GET request to verify the authentication type in use, depending on the error message returned by the host.-How to remove these kind of Vulnerabilities from IIS
0
Comment
Question by:Brijeshk9
  • 9
  • 7
16 Comments
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24066104
Have you tried the IIS lockdown wizard?

You can't remove the GET request that asks for the authentication type.  That is required for the browser to submit authentication.  If you turn it off, only anonymous authentication will work.

You are better off using firewalls or monitoring software that detect malicious activity.
0
 

Author Comment

by:Brijeshk9
ID: 24071436
ok, what will be the better solution on it...!
0
 

Author Comment

by:Brijeshk9
ID: 24083927
Please help me to get the solution for IIS 5/6 & for Apache running on unix...
0
Veeam Disaster Recovery in Microsoft Azure

Veeam PN for Microsoft Azure is a FREE solution designed to simplify and automate the setup of a DR site in Microsoft Azure using lightweight software-defined networking. It reduces the complexity of VPN deployments and is designed for businesses of ALL sizes.

 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24083975
If you want information on protecting web servers using firewalls or monitoring then I'd recommend you ask another more specific question in those sections.
0
 

Author Comment

by:Brijeshk9
ID: 24083986
I want to remove this kind of Website Vulnerabilities..?
0
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24084021
Once again, use the IIS Lockdown Wizard and even the Microsoft Baseline Security Analyzer.  There isn't a simple 'Click this' 'click that' answer for this.  People have careers specializing in locking down web applications.  I can't relay all that knowledge here.

http://www.iis.net/downloads/default.aspx?CategoryName=Microsoft&CategoryID=96&sort=modifieddate&direction=ascending&tabid=35&start=0&g=6
0
 

Author Comment

by:Brijeshk9
ID: 24084048
hmm, I have installed both the tool on my server, let me try to give my best on it...
Thanks for the suggestion
0
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24084105
They are excellent tools.  However, they won't protect your server from badly written code.
0
 

Author Comment

by:Brijeshk9
ID: 24084550
i have installed the iis lockdown with urlscan 2.5 on my Server Win 2k(IIS5) and is there any more configuration required on it. to get the web server more secure from this kind of Vulnerabilities.
Thanks in advance..!
0
 

Author Comment

by:Brijeshk9
ID: 24094144
below is the evidence for the problem i am facing.

Basic auth

GET / HTTP/1.1
Host: 192.168.1.15
Authorization: Basic cTFraTk6ZDA5a2xt

No response from server
Try manually



NTLM auth

GET / HTTP/1.1
Host: 192.168.1.15
Authorization: Negotiate TlRMTVNTUAABAAAAB4IAoAAAAAAAAAAAAAAAAAAAAAA=

No response from server
Try manually
0
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24104877
Why do you think that is a problem?  Is authentication failing?
0
 

Author Comment

by:Brijeshk9
ID: 24104928
ok, then what to do with this failure have installed IIS lockdown tool on my server, will  there any more configuration required..?
0
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24135078
Sorry I didn't make my comment clear.  I see nothing wrong with the 'problem' you described in http:#2409144  That is normal by design handshaking by a web server.
0
 

Author Comment

by:Brijeshk9
ID: 24138417
I tried to get more on iis lockdown tool to get my iis more secure can you give some more idea about iis lockdown tool....?
0
 
LVL 51

Accepted Solution

by:
Ted Bouskill earned 1500 total points
ID: 24143163
Simply run it and respond to it's comments.  It will validate your server using the latest recommendations from Microsoft and provide recommendations about how to lock your server down.  The Baseline Security Analyzer will also highlight issues.
0
 

Author Closing Comment

by:Brijeshk9
ID: 31566352
will do more research on it
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
Preparing an email is something we should all take special care with – especially when the email is for somebody you may not know very well. The pressures of everyday working life stacked with a hectic office environment can make this a real challen…
this video summaries big data hadoop online training demo (http://onlineitguru.com/big-data-hadoop-online-training-placement.html) , and covers basics in big data hadoop .
Want to learn how to record your desktop screen without having to use an outside camera. Click on this video and learn how to use the cool google extension called "Screencastify"! Step 1: Open a new google tab Step 2: Go to the left hand upper corn…
Suggested Courses

971 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question