Solved

Windows Server 2003 and URL Scan

Posted on 2014-04-21
8
1,415 Views
Last Modified: 2014-04-23
My company converted to McAffee server scans and it is flagging an event

Windows Server 2003 (Service Pack 2)  5182  Microsoft Internet Information Services Remote DoS   Microsoft Internet Information Services contains a vulnerability that may allow for remote denial-of-service attacks.   High      Microsoft Internet Information Server (IIS) is an industry-standard Web server for the Windows platform.

Microsoft Internet Information Services contains a vulnerability that may allow for remote denial-of-service attacks. A specially crafted request sent to the server may render it unresponsive."      CVE-2007-2897       "McAfee is currently unaware of a vendor-supplied patch or update (07/16/2013).

To mitigate the impact of this vulnerability, URLScan can be configured to filter URL requests that cause the denial of service. http://www.iis.net/downloads/microsoft/urlscan

I am wondering what impact this will have on my server if I add it.  It's an old server and I would hate to mess it up but I think they are going to force me to install it.
0
Comment
Question by:kdschool
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 2
8 Comments
 
LVL 19

Expert Comment

by:Miguel Angel Perez Muñoz
ID: 40012520
Any app increases CPU and RAM, thats depends of how many clients has your webserver, if your server has 1 connection per hour URLScan not work same as you have 2k connections.

Best practices recommends do on a lab test before live environment, you can clone your webserver and run on a virtual machine for testing purposes.
0
 
LVL 80

Expert Comment

by:David Johnson, CD, MVP
ID: 40012603
you should have installed urlscan a long time ago.. it has minimal impact and prevents a lot of attacks including sql injection attacks.  Urlscan is a recommended best practice as defined by Microsoft
0
 

Author Comment

by:kdschool
ID: 40012667
When I install it will the default have any impact on who can access the site or will that only be impacted if I add URL's to be restricted.  I am not clear on how it works.
0
What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

 

Author Comment

by:kdschool
ID: 40012699
It looks like they have already addressed this with automatic updates?  This is a really old hardware server with very little memory left.  We are currently migrating to a new server so if I don't have to add anything at this point I think I would be better off.  Is this the right article for this item?

https://technet.microsoft.com/library/security/ms10-065
0
 
LVL 80

Accepted Solution

by:
David Johnson, CD, MVP earned 500 total points
ID: 40012760
have you run the Microsoft Baseline Security Analyzer? (MBSA) http://www.microsoft.com/en-ca/download/confirmation.aspx?id=7558
0
 

Author Comment

by:kdschool
ID: 40013045
This is a 32 bit server when I go to this page it's saying.  Will this work on a 32 bit OS?

MBSASetup-x64-EN.msi
0
 

Author Comment

by:kdschool
ID: 40013150
Never mind I found the x86 version will let you know when I install it.
0
 

Author Comment

by:kdschool
ID: 40013182
I ran this and scanned the server. Says everything is good,  no security updates missing and did not flag anything under vunerabilities.  Everything checked out ok.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When it comes to showing a 404 error page to your visitors, you do not want that generic page to show, and you especially do not want your hosting provider’s ad error page to show either. In this article, I will show you how to enable the custom 40…
As tax season makes its return, so does the increase in cyber crime and tax refund phishing that comes with it
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question