ashleym
MIS
- Mar 30, 2001
- 375
I am curious, I have OWA and IIS installed (on my exchange 5.5 SP4 server) and configured for SSL, so only 56 or 128 bit encrypted browsers can access OWA. Am I protected from external attacks more because I am using SSL? I am referring to the attacks that hackers run when they type very long strings into a browsers address window trying to exploit IIS. I am using basic authentication for OWA with SSL. I am just curious if it is necessary to apply all of the relevant patches to IIS 4 after a new install if OWA is configured with SSL. I know I am still vulnerable to internal attacks such as Code Red and nimda.
Thanks
Thanks