3 Steps to resolve IIS Web site security to prevent Web sites from being hacked

Source: Internet
Author: User
Keywords Website hacked

Intermediary transaction http://www.aliyun.com/zixun/aggregation/6858.html ">seo diagnose Taobao guest cloud host technology Hall

Some time ago, the author said in the previous article, "the site was injected Trojan caused the network paralysis," the method, but summed up, feeling not comprehensive, today I dedicate this article to improve the safety of the website to prevent the site is black.

Web site by black generally refers to the site is injected Trojan or black chain, inject a variety of methods, there are SQL injection, there are Web site permissions injected and so on. The author takes IIS as an example to explain how to prevent the website from being hacked.

1, open the IIS Information Services Manager, under the "Web site" option to set the Site Directory--Properties, the site directory data and upload set to not write, execute permissions set to None (see Figure 2).

2, the IIS Web site in the home directory of "script resource Access", "Write", "directory Browsing" and record access options such as the selection of removal, right-click the site Directory---properties into the interface, as shown in the following figure:

  

3. Set the "Execute permission" of all directory files on the website to pure script (except data and upload files), as shown in the following figure:

  

4, through the above simple settings that complete the site permissions of the security settings, we can detect through http://webscan.360.cn, such as the author's two Web site results are as follows:

  

Note: This applies to Discuz, Phpwind, Dedecms, and most open source programs as long as you are using a Web site created by IIS.

This article original from http://www.45fan.com/a/luyou/590.html, reprint should indicate the source!

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.