On MSDN forums I was told to look somewhere else too :) http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=3328705&SiteID=1
I've tried all sorts of things now, from IIS 5.0 registry settings, to IIS manager web server extensions, and even tried to deny Everyone access to the httpetx.dll from C:\WINDOWS\system32\inetsrv... and of course did an iisreset after each change... and I still can open the WSS web site using DAV client :) There's also the IIS lockdown tool, but that's only for IIS 4.0, 5.0..
This is very, very strange...