IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Actually you can secure IIS - with a trick
I can't find the article right now, but I saw a detailed article about how someone secured an IIS server against all past, present, and future security holes in IIS. The idea was simple, the implementation not quite so.

What they did is put up a reverse proxy in front of it which did very strict validations of what it would allow to be proxied. If they didn't know why a request should be allowed through, or if the request matched certain parameters for a buffer overflow, it was blocked. There was no way from the internet to directly access the IIS server.

It was a lot of work, but their reason for doing it is that they had a web application which didn't successfully port to a newer version of IIS, which they didn't have the luxury to rewrite immediately, which they couldn't just discontinue, and which they needed to have secured against bugs in the old IIS. So they analyzed the application, and produced their reverse proxy.

Cheers,
Ben

PS The admins in this case were uncommonly competent. Not surprisingly, they considered this secure version of IIS to be a stopgap measure, and they planned to rewrite it for Apache when they got time. :-)
New Sounds like a good money spinner...

"All around me are nothing but fakes
Come with me on the biggest fake of all!"

New And that trick is...
...uninstallation.

;-)
-YendorMike

"The problems of the world cannot possibly be solved by the skeptics or the cynics whose horizons are limited by the obvious realities. We need people who dream of things that never were." - John F. Kennedy
     The Olympic Winter Games Web Site: IIS on Windows . . - (Andrew Grygus) - (10)
         "if" it gets hacked? - (wharris2) - (9)
             If. - (addison)
             Not necessarily. - (pwhysall) - (6)
                 Not necessarily. - (addison) - (5)
                     Re: Not necessarily. - (pwhysall)
                     Actually you can secure IIS - with a trick - (ben_tilly) - (2)
                         Sounds like a good money spinner... -NT - (static)
                         And that trick is... - (Yendor)
                     You missed one... - (jb4)
             While a hack would not shock me . . - (Andrew Grygus)

Eschew obfuscation.
39 ms