Riguy Index and Archive:
|
URLScan = IIS protection. IIS has come a long way since Nimda and Code Red. Most now consider IIS generally secure, although security threat potential is always around the corner. http://support.microsoft.com/default.aspx?scid=KB;EN-US;Q307608& The importance of Logging, demonstrated here. The log shows how URLScan fends off various sinister GET requests and other nefarious connection attempts: ** Excellent description of Code Red, from the people who actually diagnosed it in the first place: http://www.eeye.com/html/Research/Advisories/AL20010717.html MS IIS Pages: http://www.microsoft.com/technet/iis/default.asp IIS clearinghouse: IIS FAQ: It's not just IIS that has had some security lapses! Imagine, even the hallowed APACHE Web Server has had flaws. Back to: Last Modified: Winter, 2006 |