IIS server skills and tools knowledge class

Source: Internet
Author: User
Tags ntfs permissions

We all pay attention to the security of IIS servers, which are often attacked. We know that by marking the security level and availability policies of IIS servers, the network administrator can easily deploy various software tools on different operating systems.

IIS server NTFS security:

By default, your NTFS drive uses EVERYONE/full control permissions unless you manually turn them off. The key is not to lock yourself out. Different people need different permissions, administrators need full control, and backend accounts need full control, each system and service requires a certain level of access permissions, depending on different files.

The most important folder is System32. The smaller the ACL for this folder, the better. Using NTFS permissions on Web servers helps you protect important files and applications.

IIS Server Management User Account:

If you have already installed the IIS server, you may have a TSInternetUser account. Unless you really need this account, you should disable it. This user is easily infiltrated and is a notable target of hackers. To help manage user accounts, make sure your Local Security Policy is correct. IUSR user permissions should be as small as possible.

Audit your IIS server:

Audit has a great impact on the performance of your computer. Therefore, if you do not check it frequently, do not audit it. If you can use it, Audit System Events and add audit tools as needed. If you are using the aforementioned WhosOn tool, auditing is not that important.

By default, IIS servers always record Access. WhosOn places these records in a very easy-to-read database. You can open them through Access or Excel. If you often view abnormal databases, you can find the server's vulnerabilities at any time.

All of the above IIS server skills and tools (except WhosOn) are provided by Windows. Do not forget to use these skills and tools one by one before testing your website accessibility. If they are deployed together, you may suffer heavy losses. You may need to restart them to lose access.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.