Solved

IIS supports anonymous access, Basic, and Windows NT Challenge/Response (NTLM) authentication. The authentication mechanism in IIS could reveal the type of authentication in use to a remote attacker

Posted on 2009-04-03
16
382 Views
Last Modified: 2012-05-06
Microsoft Internet Information Server (IIS) supports anonymous access, Basic, and Windows NT Challenge/Response (NTLM) authentication. The authentication mechanism in IIS could reveal the type of authentication in use to a remote attacker. A remote attacker can send a specially-crafted GET request to verify the authentication type in use, depending on the error message returned by the host.-How to remove these kind of Vulnerabilities from IIS
0
Comment
Question by:Brijeshk9
  • 9
  • 7
16 Comments
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24066104
Have you tried the IIS lockdown wizard?

You can't remove the GET request that asks for the authentication type.  That is required for the browser to submit authentication.  If you turn it off, only anonymous authentication will work.

You are better off using firewalls or monitoring software that detect malicious activity.
0
 

Author Comment

by:Brijeshk9
ID: 24071436
ok, what will be the better solution on it...!
0
 

Author Comment

by:Brijeshk9
ID: 24083927
Please help me to get the solution for IIS 5/6 & for Apache running on unix...
0
The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24083975
If you want information on protecting web servers using firewalls or monitoring then I'd recommend you ask another more specific question in those sections.
0
 

Author Comment

by:Brijeshk9
ID: 24083986
I want to remove this kind of Website Vulnerabilities..?
0
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24084021
Once again, use the IIS Lockdown Wizard and even the Microsoft Baseline Security Analyzer.  There isn't a simple 'Click this' 'click that' answer for this.  People have careers specializing in locking down web applications.  I can't relay all that knowledge here.

http://www.iis.net/downloads/default.aspx?CategoryName=Microsoft&CategoryID=96&sort=modifieddate&direction=ascending&tabid=35&start=0&g=6
0
 

Author Comment

by:Brijeshk9
ID: 24084048
hmm, I have installed both the tool on my server, let me try to give my best on it...
Thanks for the suggestion
0
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24084105
They are excellent tools.  However, they won't protect your server from badly written code.
0
 

Author Comment

by:Brijeshk9
ID: 24084550
i have installed the iis lockdown with urlscan 2.5 on my Server Win 2k(IIS5) and is there any more configuration required on it. to get the web server more secure from this kind of Vulnerabilities.
Thanks in advance..!
0
 

Author Comment

by:Brijeshk9
ID: 24094144
below is the evidence for the problem i am facing.

Basic auth

GET / HTTP/1.1
Host: 192.168.1.15
Authorization: Basic cTFraTk6ZDA5a2xt

No response from server
Try manually



NTLM auth

GET / HTTP/1.1
Host: 192.168.1.15
Authorization: Negotiate TlRMTVNTUAABAAAAB4IAoAAAAAAAAAAAAAAAAAAAAAA=

No response from server
Try manually
0
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24104877
Why do you think that is a problem?  Is authentication failing?
0
 

Author Comment

by:Brijeshk9
ID: 24104928
ok, then what to do with this failure have installed IIS lockdown tool on my server, will  there any more configuration required..?
0
 
LVL 51

Expert Comment

by:Ted Bouskill
ID: 24135078
Sorry I didn't make my comment clear.  I see nothing wrong with the 'problem' you described in http:#2409144  That is normal by design handshaking by a web server.
0
 

Author Comment

by:Brijeshk9
ID: 24138417
I tried to get more on iis lockdown tool to get my iis more secure can you give some more idea about iis lockdown tool....?
0
 
LVL 51

Accepted Solution

by:
Ted Bouskill earned 500 total points
ID: 24143163
Simply run it and respond to it's comments.  It will validate your server using the latest recommendations from Microsoft and provide recommendations about how to lock your server down.  The Baseline Security Analyzer will also highlight issues.
0
 

Author Closing Comment

by:Brijeshk9
ID: 31566352
will do more research on it
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Prologue It is often required to host multiple websites on a single instance of IIS, mostly in development environments instead of on production servers. I am sure it is not much a preferred solution on production servers but this is at least a pos…
Lync server 2013 or Skype for business Backup Service Error ID 4049 – After File Share Migration
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question