All Tagssecurity risks (RSS)
  • Risks of unmanaged IIS7

    Hi, I've got myself a hard question: I'm devloping a process control system that consists of a Windows Vista PC combined with a Windows XP machine (connected through windows network, separate adapter). On the Vista PC, IIS 7 is running with an ASP.NET application with form based authentication...
    Posted to Forum by giis2 on 04-27-2009, 8:56 AM
  • IIS 6.0 with out Anti-virus and no firewall

    Hello All, Due to performance reasons, can i run IIS 6.0 on a public ip without Anti-virus and firwall. I am actively patching the server 2003. Any thoughts about it, i really appreciate. Jenefa
    Posted to Forum by jenefa on 04-15-2009, 10:34 AM
  • Guest account

    to add to the security of our web server it has been recommended that the guest account be removed from the guest group, since annonymous is not allowed. Does anyone see any issues in IIS 6.0 if this is done?
    Posted to Forum by dwheeler on 11-18-2008, 3:28 PM
  • UrlScan not blocking URL segments

    I'm using UrlScan 3.0 on IIS 6.0 (IIS 7.0 is not an option). I need to block all requests for URLs which contain "NR" as a path segment: http://localhost/ NR /.... Here's my UrlScan.ini file (most settings are the defaults, changes are in italics, things I think are significant are...
    Posted to Forum by RedCrystal on 09-30-2008, 2:45 PM
  • Security considerations w/Front Page 2002 Server Extensions?

    Good morning, all. New to the forum. I have been looking, but can't find much data, and need info quickly. Would there be any deal-breaking security implications with installing FPSE 2002 on an INTRANET server? Better yet, does anyone know of a usable page hit counter that would not require FSPE...
    Posted to Forum by Lizard King 49 on 09-18-2008, 12:12 PM
  • URLScan Recycle

    In our URLScan logs we get the following quite a bit - - - - - - - - - - - - - - - - - - - - - - - - #Software: Microsoft UrlScan 3.0 #Version: 1.0 #Date: 2008-09-04 01:01:20 - - - - - - - - - - - - - - - - - - - - - - - - Does anyone know if this means that UrlScan is recycling and we have a period...
    Posted to Forum by jeremyn11 on 09-05-2008, 2:24 PM
  • Re: Anyone know about www.nihaorr1.com/1.js?

    Hi, Im a System Administrator of a Hosting Company, and one of our website has been hacked with SQL injection, At first the hacker inserted nihaorr1.com/1.js most of the website table are being affected with this attacked, after that incident I developed a SQL validation that is similar on the asp script...
    Posted to Forum by ejhay on 05-21-2008, 10:11 PM
  • Re: Anyone know about www.nihaorr1.com/1.js?

    Hi, Im a System Administrator of a Hosting Company and one of our website has been hack with SQL injection, At first the hacker inserted nihaorr1.com/1.js most of the website table are being affected with this attacked, after I created that a created a SQL validation like one that you have posted in...
    Posted to Forum by ejhay on 05-21-2008, 10:08 PM
  • Re: White-Paper on Secure Scalability of IIS 6.0 web apps (Windows Server 2003 R2)

    This is excatly what I have been doing for a few years, A collegue and I are in the middle of writing it up as a high level design, hopefully if we can remove the corporate references we will publish this as a paper but a few thing to note so far are We use CIFS (windows shares on sep file server for...
    Posted to Forum by species5618 on 04-18-2008, 2:44 PM
  • IUSR_SERVER Write permissions unacceptable?

    I've read in a number of articles that giving IUSR_SERVER write permissions creates a huge security risk. I'm working with a databaseless CMS using ASP/VBScript that needs IUSR set to read/write in order to function. Is there a way to allow the CMS to modify files without creating a security...
    Posted to Forum by rlang on 11-20-2007, 3:06 PM
Page 1 of 2 (11 items) 1 2 Next >
Microsoft Communities