Solved

IIS supports anonymous access, Basic, and Windows NT Challenge/Response (NTLM) authentication. The authentication mechanism in IIS could reveal the type of authentication in use to a remote attacker

Posted on 2009-04-03
16
372 Views
Last Modified: 2012-05-06
Microsoft Internet Information Server (IIS) supports anonymous access, Basic, and Windows NT Challenge/Response (NTLM) authentication. The authentication mechanism in IIS could reveal the type of authentication in use to a remote attacker. A remote attacker can send a specially-crafted GET request to verify the authentication type in use, depending on the error message returned by the host.-How to remove these kind of Vulnerabilities from IIS
0
Comment
Question by:Brijeshk9
  • 9
  • 7
16 Comments
 
LVL 51

Expert Comment

by:tedbilly
Comment Utility
Have you tried the IIS lockdown wizard?

You can't remove the GET request that asks for the authentication type.  That is required for the browser to submit authentication.  If you turn it off, only anonymous authentication will work.

You are better off using firewalls or monitoring software that detect malicious activity.
0
 

Author Comment

by:Brijeshk9
Comment Utility
ok, what will be the better solution on it...!
0
 

Author Comment

by:Brijeshk9
Comment Utility
Please help me to get the solution for IIS 5/6 & for Apache running on unix...
0
 
LVL 51

Expert Comment

by:tedbilly
Comment Utility
If you want information on protecting web servers using firewalls or monitoring then I'd recommend you ask another more specific question in those sections.
0
 

Author Comment

by:Brijeshk9
Comment Utility
I want to remove this kind of Website Vulnerabilities..?
0
 
LVL 51

Expert Comment

by:tedbilly
Comment Utility
Once again, use the IIS Lockdown Wizard and even the Microsoft Baseline Security Analyzer.  There isn't a simple 'Click this' 'click that' answer for this.  People have careers specializing in locking down web applications.  I can't relay all that knowledge here.

http://www.iis.net/downloads/default.aspx?CategoryName=Microsoft&CategoryID=96&sort=modifieddate&direction=ascending&tabid=35&start=0&g=6
0
 

Author Comment

by:Brijeshk9
Comment Utility
hmm, I have installed both the tool on my server, let me try to give my best on it...
Thanks for the suggestion
0
 
LVL 51

Expert Comment

by:tedbilly
Comment Utility
They are excellent tools.  However, they won't protect your server from badly written code.
0
Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

 

Author Comment

by:Brijeshk9
Comment Utility
i have installed the iis lockdown with urlscan 2.5 on my Server Win 2k(IIS5) and is there any more configuration required on it. to get the web server more secure from this kind of Vulnerabilities.
Thanks in advance..!
0
 

Author Comment

by:Brijeshk9
Comment Utility
below is the evidence for the problem i am facing.

Basic auth

GET / HTTP/1.1
Host: 192.168.1.15
Authorization: Basic cTFraTk6ZDA5a2xt

No response from server
Try manually



NTLM auth

GET / HTTP/1.1
Host: 192.168.1.15
Authorization: Negotiate TlRMTVNTUAABAAAAB4IAoAAAAAAAAAAAAAAAAAAAAAA=

No response from server
Try manually
0
 
LVL 51

Expert Comment

by:tedbilly
Comment Utility
Why do you think that is a problem?  Is authentication failing?
0
 

Author Comment

by:Brijeshk9
Comment Utility
ok, then what to do with this failure have installed IIS lockdown tool on my server, will  there any more configuration required..?
0
 
LVL 51

Expert Comment

by:tedbilly
Comment Utility
Sorry I didn't make my comment clear.  I see nothing wrong with the 'problem' you described in http:#2409144  That is normal by design handshaking by a web server.
0
 

Author Comment

by:Brijeshk9
Comment Utility
I tried to get more on iis lockdown tool to get my iis more secure can you give some more idea about iis lockdown tool....?
0
 
LVL 51

Accepted Solution

by:
tedbilly earned 500 total points
Comment Utility
Simply run it and respond to it's comments.  It will validate your server using the latest recommendations from Microsoft and provide recommendations about how to lock your server down.  The Baseline Security Analyzer will also highlight issues.
0
 

Author Closing Comment

by:Brijeshk9
Comment Utility
will do more research on it
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Join & Write a Comment

First of all, clustering IIS is something you should rarely consider doing. In almost all cases, Microsoft Network Load Balancing (NLB) (http://technet.microsoft.com/en-us/library/cc758834(WS.10).aspx) is a much better solution when you need to p…
What is an ISAPI filter?   •      It's an assembly (.dll file) that can add or change the way IIS works.   •      They can be enabled globally for your web server or on a site-by-site basis.   When the IIS server receives a request, enabling the ISAPI fi…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now