Tip: how to reinforce IIS server security on the Internet

Source: Internet
Author: User

The following six steps are involved in IIS server security:

1. Use the Security Configuration Wizard to determine the minimum functions required by the web server, and then disable other functions that are not required. Specifically, it can help you

1> disable unwanted services

2> block unused ports

3> further restrictions on accessible addresses and other security measures for opened ports

4> disable unnecessary IIS web extensions if feasible

5> reduce the exposure of SMB, LAN Manager, and LDAP protocols

6> define a countermeasure with High Signal-to-Noise Ratio

2. Place the website file on a non-system partition to prevent directory traversal defects and perform NTFS permission inspection (Audit) on the content ).

3. Perform regular security scanning and inspection on your system, and discover your weaknesses as early as possible before others discover problems.

4. Perform regular log analysis to find multiple failed login attempts, and the 404,401,403 error that occurs repeatedly, instead of the request records for your website.

5. If IIS 6 is used, Host Headers and URL scanning are used to implement automatic website content and IIS Metabase Replication, and standard names are used for IUSR_servername accounts.

6. Overall web architecture design philosophy: Do not put your internet web server in the Active Directory of the Intranet, do not run IIS Anonymous Authentication with the Active Directory account, and consider real-time monitoring, carefully set the application pool settings, and strive to log any activity and prohibit Internet Explorer on the server.


You are reading: tip: how to reinforce IIS server security on the Internet

  1. Database Server security permission control policy
  2. Network Management Tips: How to easily manage servers
  3. Guide CD to troubleshoot server faults in Linux

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.