Home > Security Tips > Web Security Advisor > How to safely install IIS
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

How to safely install IIS


Ross Tsolakidis
03.15.2002
Rating: -3.46- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   




This tip was submitted to the SearchSecurity.com Tip Exchange Contest by user Ross Tsolakidis. Let other users know how useful it is and help Ross win a prize by rating the tip below.


I've seen a lot of people install a Windows 2000 server while the machine is connected to the network (live IP address). What they are unaware of is as soon as the install is completed and the Web server reboots, they are vulnerable to all the exploits that IIS has "out of the box," and that is a LOT.

I've seen Web servers attacked within seconds of going live, i.e., Code Red Worm. You'd be surprised how many people do this!

Here's the way I install a server:

  • I make sure the server is unplugged from the network while installing the OS.
  • Once the OS install has been completed and the machine reboots, I stop IIS completely via the IIS console.
  • Now I plug it into the network.
  • Next, I update all the patches and Service Packs.
  • I reboot the server, start IIS again and I'm done.

    If you do what I do, you won't have a vulnerable Web server live on the Internet while you are patching it.


    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Web Security Advisor,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Web Security Advisor
    DNS rebinding defenses still necessary, thanks to Web 2.0
    New defenses for automated SQL injection attacks
    PCI compliance and Web applications: Code review or firewalls?
    Worst practices: Bad security incidents to avoid
    Web scanning and reporting best practices
    Social networking Web site threats manageable with good enterprise policy
    Enterprise security in 2008: Building trust into the application development process
    PCI DSS Section 6: A plan for tackling application security
    Making the case for Web application vulnerability scanners
    Preparing for uniform resource identifier (URI) exploits

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Research Solutions for Network Security, Access Control and Security Threats
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts