Securing Microsoft IIS

Cornell University Security Seminar
July 25th, 2001
Moe Arif and Thomas P. Braun
CIT, Systems & Operations

This web page is also available as PowerPoint slides

Overview

  • Introduction:
    NNvulnerabilities, exploits and scope
  • Tutorial on prevention:
    NNsetup, configuration, and patching
  • Discussion:
    NNmaintain current patch levels
    NNprevent "rogue servers"
    NNalert mechanisms
    NNalternatives
    NN...
BLANK

Contents

Vulnerabilities: Internet Information Services 5.0

Exploits: "code red"

Exploits: "UNICODE"

Scope

Responses

Why is IIS Insecure?

What can we do?

Installation

Configuration

Patches

Subscribing to the Microsoft Security Notification Service

To Summarize


Last updated 7/25/01
Part of Cornell University's Security Issues
for Network and System Administrators
site