Try to find a bug in IIS over the 2-3 years. With a good search, you MAY be able to find 2, 3, maybe even 4 if you're lucky.
Almost 100% of the bugs related to IIS, or blamed on IIS are actually ISAPI extensions that ship with Windows.
Code Red? HTR exploit
Nimda? Http Printing exploit (or maybe it was IDX files, I can't remember)
etc, etc, etc.
If you followed the IIS Security Checklist MS released for NT4/IIS4 many years ago, you wouldn't have been affected by any of the worms released for IIS to day.
That checklist has remained largely unchanged (I think they added the IISLockdown tool and UrlScan)
|