Skip to main content

Securing IIS6: From the OS, Up

The dark side of the Internet can test even the most diligent System Administrator's ability to get, and keep their web server secure. WWW attacks targeted at both web applications and the servers that offer them are growing at an ever-increasing rate. This document provides a detailed look at securing Internet Information Services v6.0 (IIS6), using a combination of security templates and manual techniques. In order to provide the most secure installation of IIS possible, the paper first looks at securing the base operating system, Windows Server 2003 (Win2K3). The process will be covered completely; creating a hardened baseline on which to install IIS6, hardening the web server itself, and manually tweaking settings to conform to a custom environment. Finally, the paper also explains methods of analyzing and verifying the prescribed security settings.

1238 (PDF, 2.08MB)

5 Nov 2003
ByJoey Peloquin
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.