?
Solved

Windows Server 2003 and URL Scan

Posted on 2014-04-21
8
Medium Priority
?
1,454 Views
Last Modified: 2014-04-23
My company converted to McAffee server scans and it is flagging an event

Windows Server 2003 (Service Pack 2)  5182  Microsoft Internet Information Services Remote DoS   Microsoft Internet Information Services contains a vulnerability that may allow for remote denial-of-service attacks.   High      Microsoft Internet Information Server (IIS) is an industry-standard Web server for the Windows platform.

Microsoft Internet Information Services contains a vulnerability that may allow for remote denial-of-service attacks. A specially crafted request sent to the server may render it unresponsive."      CVE-2007-2897       "McAfee is currently unaware of a vendor-supplied patch or update (07/16/2013).

To mitigate the impact of this vulnerability, URLScan can be configured to filter URL requests that cause the denial of service. http://www.iis.net/downloads/microsoft/urlscan

I am wondering what impact this will have on my server if I add it.  It's an old server and I would hate to mess it up but I think they are going to force me to install it.
0
Comment
Question by:kdschool
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
8 Comments
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 40012520
Any app increases CPU and RAM, thats depends of how many clients has your webserver, if your server has 1 connection per hour URLScan not work same as you have 2k connections.

Best practices recommends do on a lab test before live environment, you can clone your webserver and run on a virtual machine for testing purposes.
0
 
LVL 82

Expert Comment

by:David Johnson, CD, MVP
ID: 40012603
you should have installed urlscan a long time ago.. it has minimal impact and prevents a lot of attacks including sql injection attacks.  Urlscan is a recommended best practice as defined by Microsoft
0
 

Author Comment

by:kdschool
ID: 40012667
When I install it will the default have any impact on who can access the site or will that only be impacted if I add URL's to be restricted.  I am not clear on how it works.
0
Percona Live Europe 2017 | Sep 25 - 27, 2017

The Percona Live Open Source Database Conference Europe 2017 is the premier event for the diverse and active European open source database community, as well as businesses that develop and use open source database software.

 

Author Comment

by:kdschool
ID: 40012699
It looks like they have already addressed this with automatic updates?  This is a really old hardware server with very little memory left.  We are currently migrating to a new server so if I don't have to add anything at this point I think I would be better off.  Is this the right article for this item?

https://technet.microsoft.com/library/security/ms10-065
0
 
LVL 82

Accepted Solution

by:
David Johnson, CD, MVP earned 2000 total points
ID: 40012760
have you run the Microsoft Baseline Security Analyzer? (MBSA) http://www.microsoft.com/en-ca/download/confirmation.aspx?id=7558
0
 

Author Comment

by:kdschool
ID: 40013045
This is a 32 bit server when I go to this page it's saying.  Will this work on a 32 bit OS?

MBSASetup-x64-EN.msi
0
 

Author Comment

by:kdschool
ID: 40013150
Never mind I found the x86 version will let you know when I install it.
0
 

Author Comment

by:kdschool
ID: 40013182
I ran this and scanned the server. Says everything is good,  no security updates missing and did not flag anything under vunerabilities.  Everything checked out ok.
0

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to showing a 404 error page to your visitors, you do not want that generic page to show, and you especially do not want your hosting provider’s ad error page to show either. In this article, I will show you how to enable the custom 40…
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question