Microsoft has released its latest security-oriented utility, this time
addressing the many vulnerabilities in Internet Information Server (IIS) with
its free 'IIS
Lockdown Tool'. The purpose here is not to patch systems like the
HFNetChk hotfix checker, but to configure IIS for improved security
independent of patching. The IIS utility will automatically remove script
mappings, sample Web files, the scripts virtual directory, and the MSADC virtual
directory. It disables active server pages (asp), the index server Web interface
(ida), server-side includes, Internet printing, and distributed authoring and
versioning (WebDAV). It also sets file permissions to prevent the anonymous user
account from writing to Web content directories or executing system utilities.
|