Solved

Hardening Window Web servers(IIS 6, 7)

Posted on 2010-11-29
3
947 Views
Last Modified: 2012-05-10
Hello Experts,

I just wondering if you can provide me with some docs, links, and your recommendations in how to hardening Windows Web servers IIS 6, IIS 7, and deploy full security on these boxes

Any feedback is really appreciated

Thank you in advance
0
Comment
Question by:Jerry Seinfield
3 Comments
 
LVL 1

Expert Comment

by:JrLz
ID: 34236263
Hi,

there's a tool called IIS LockDown from Microsoft, you can take a look for the details
before applying the tool.

hope it helps
0
 
LVL 9

Accepted Solution

by:
shalabhsharma earned 500 total points
ID: 34236401
0
 
LVL 9

Expert Comment

by:losip
ID: 34236963
My favorite is "Improving Web Application Security: Threats and Countermeasures" which is a Microsoft publication and available online.  It complements the "out-of-the-box" security afforded by IIS6 and IIS7 by pointing out that the applications have to be secure, too.

It is a fairly old publication but still has relevant guidelines for application developers. It can be downloaded from: http://www.microsoft.com/downloads/en/details.aspx?FamilyId=E9C4BFAA-AF88-4AA5-88D4-0DEA898C31B9&displaylang=en  

The thread that shalabsharma pointed out on formus.iis.net has some useful pointers, too
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Suggested Solutions

When it comes to showing a 404 error page to your visitors, you do not want that generic page to show, and you especially do not want your hosting provider’s ad error page to show either. In this article, I will show you how to enable the custom 40…
New Windows 7 Installations take days for Windows-Updates to show up and install. This can easily be fixed. I have finally decided to write an article because this seems to get asked several times a day lately. This Article and the Links apply to…
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now