I learned a lot about IIS servers. Today I will learn how to minimize the number of attacks on IIS servers in your environment, only necessary Web service extensions should be enabled on the IIS server.
Only enable the Web service extensions required for websites and application software running in your IIS server environment. by streamlining the server features to the maximum extent, you can reduce the attack surface of each IIS server, this enhances security.
For more information about Web service extensions, see how to identify IIS 2003 components in Windows Server 6.0.
Place content in a dedicated disk volume
IIS stores the default Web site files to inetpubwwwroot, which is the drive for installing the Windows Server 2003 operating system.
In the three environments defined in this Guide, all files and folders that constitute Web sites and applications should be placed in the dedicated disk volumes of the IIS server.
Placing these files and folders to a dedicated disk volume on the IIS server-excluding the disk volume of the Operating System-helps prevent directory traversal attacks. Directory traversal attacks are attacks that allow attackers to send requests to a file located outside the directory structure of the IIS server.
For example, cmd.exe is located in the System32 folder. Attackers may request access to the following locations:
....Windowssystemcmd.exe, an attempt to call the command prompt
If the content of the Web site is located on a separate disk volume, this type of directory traversal attack cannot be successful for two reasons. First, the permission of cmd.exe has been reset as part of the basic structure of Windows Server 2003, thus limiting its access to a very limited user group.
After the change, cmd.exe is no longer in the same disk volume as the Web root directory of the IIS server. Currently, there is no known method to use this attack to access commands on different drives.
In addition to security considerations, placing site and application files and folders in a dedicated disk volume makes management tasks such as backup and recovery easier. In addition, placing this type of content in a separate dedicated physical drive helps reduce disk contention in the system partition and improve the overall access performance of the disk. For more information about IIS servers, see here.