About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
  #1   Add MunkeyQ to your ignore list  
Old 2007-06-24, 08:58
MunkeyQ MunkeyQ is offline
Regular
 
MunkeyQ is helpful
Default Server security

I finally got my webserver up and running but I need some advice on securing it properly.

It's running XP Pro with all the most recent updates and the newest version of IIS. I currently only have the basic crappy XP firewall on there - I guess it be a smart move to get something more advanced right? Which firewall?

It's behind a router but since it also acts as an internal fileserver, I have file sharing turned on. Is there anything I should modify to make this more secure? Or is it ok?

On the router, I've forwarded the remote desktop port and port 80. It isn't in a DMZ.

I have two virtual directories set up on IIS - the cgi-bin and the main website folder. FTP is turned off as I don't need it.

Thanks in advance.
Reply With Quote
  #2   Add sirholkms to your ignore list  
Old 2007-06-24, 09:08
sirholkms sirholkms is offline
Regular
 
[][][][][][][][][][][][][][][] Send a message via ICQ to sirholkms Send a message via AIM to sirholkms Send a message via MSN to sirholkms Send a message via Yahoo to sirholkms Send a message via Skype™ to sirholkms sirholkms is an unknown
Default Re: Server security

Well first step would be to disable the windows DCOM service, just do it they will find more exploits there it's a sitting duck. Then disable any unnecessary windows services and install some thing like zone alarm pro or AVG internet security suit (cracked of cause) and allow the web server access to the internet and set up rules so that it all works etc. Up to date windows boxes are fairly secure as it is so your pritty safe. Now heres the final step are you ready for it....
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
Now reformat your windows box and install linux the end.
Reply With Quote
  #3   Add Rubberducky to your ignore list  
Old 2007-06-25, 18:11
Rubberducky Rubberducky is offline
Regular
 
Rubberducky is an unknown
Default Re: Server security

Quote:
Originally Posted by sirholkms View Post
Well first step would be to disable the windows DCOM service, just do it they will find more exploits there it's a sitting duck. Then disable any unnecessary windows services and install some thing like zone alarm pro or AVG internet security suit (cracked of cause) and allow the web server access to the internet and set up rules so that it all works etc. Up to date windows boxes are fairly secure as it is so your pritty safe. Now heres the final step are you ready for it....
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
........................
Now reformat your windows box and install linux the end.
Could you please, please, learn basic spelling.
And fuck you, Linux isn't always better than Windows, buttface.
Reply With Quote
  #4   Add MunkeyQ to your ignore list  
Old 2007-06-25, 18:39
MunkeyQ MunkeyQ is offline
Regular
 
MunkeyQ is helpful
Default Re: Server security

Quote:
Could you please, please, learn basic spelling.
And fuck you, Linux isn't always better than Windows, buttface.
Thank you rubberducky.

sirholkms - Linux is not ALWAYS the best. I use NTFS USB HDs with the server as I need to carry lots of data around for use with Windows machines. Linux doesn't like USB NTFS drives.

I don't want the good ol' Linux vs Windows debate here - just advice on how to secure my IIS box.
Reply With Quote
  #5   Add MunkeyQ to your ignore list  
Old 2007-06-27, 19:32
MunkeyQ MunkeyQ is offline
Regular
 
MunkeyQ is helpful
Default Re: Server security

Sorry, I don't normally bump my own threads...but has anyone got any more advice?
Reply With Quote
  #6   Add ThunderChicken to your ignore list  
Old 2007-06-29, 03:47
ThunderChicken ThunderChicken is offline
Regular
 
Chicago ThunderChicken is an unknown
Default Re: Server security

i not being smart ass or anything

http://www.google.com/search?hl=en&c...ce&btnG=Search

Reply With Quote
  #7   Add MunkeyQ to your ignore list  
Old 2007-06-29, 06:25
MunkeyQ MunkeyQ is offline
Regular
 
MunkeyQ is helpful
Default Re: Server security

This may sound really stupid but I haven't actually tried Google yet; do I feel dumb.

Thanks. (and no I'm not being sarcastic...heh)
Reply With Quote
  #8   Add asdf90 to your ignore list  
Old 2007-06-29, 07:09
asdf90 asdf90 is offline
New Arrival
 
asdf90 is an unknown
Default Re: Server security

You also might try a basic vulnerability scan with a program like nessus to see how secure your machine is.
Reply With Quote
  #9   Add MunkeyQ to your ignore list  
Old 2007-06-29, 12:02
MunkeyQ MunkeyQ is offline
Regular
 
MunkeyQ is helpful
Default Re: Server security

Quote:
You also might try a basic vulnerability scan with a program like nessus to see how secure your machine is.
Thanks, that looks like a very handy tool.
Reply With Quote
  #10   Add baloo to your ignore list  
Old 2007-06-29, 14:08
baloo baloo is offline
Regular
 
Australia baloo is helpful
Default Re: Server security

Quote:
Originally Posted by MunkeyQ View Post
Linux doesn't like USB NTFS drives.
Sure they do.
Reply With Quote
Reply


Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics