Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IIS 5.0 Vunerable if anonymous disabled?

Status
Not open for further replies.

vexxed

MIS
Nov 29, 2002
18
0
0
CA
Hi, I am trying to secure IIS 5.0 on windows 2000 professionl for some developers.
My goal is to have IIS ( ftp) running on a workstation and not be vunerable to virus/trojan attacks from future weaknesses in IIS.
If I disable anonymous logons to the websites/services in IIS and restrict the IP that can connect to the websites to the only the localhost(127.0.0.1) and the local IP address, will the system be protected from future attacks?
Essentially the developer using the desktop is the only one that can use IIS services.
 
If you restrict it that way , then you will be only allowing that user in. It would be much harder but possible to get in, but as I said harder. So yes that would make you system only vulnerable to that user that you are allowing to connect.

However experience hackers can hijack a ip address if they know you are only allowing that IP in. But as I said that is harder to do, and usually not worth the time for a hacker to get into a system unless they can profit from it.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top