Groups | Blog | Home
all groups > iis security > december 2003 >

iis security : IIS still vulnerable



Johnny
12/29/2003 8:26:53 AM
IIS with all the lastest updates/patches and some kid
executes code on the machine, uploads an FTP daemon then
and uploads 10gb of movies & games - he usually puts
everything into iissamples. - its all in German!!!

Keith W. McCammon
12/29/2003 11:59:45 AM
Is the system properly configured? Patching is worthless if you have weak
permissions and easy passwords.

And are you running any third-party software?

[quoted text, click to view]

Paul Lynch
12/29/2003 5:40:18 PM
On Mon, 29 Dec 2003 08:26:53 -0800, "Johnny"
[quoted text, click to view]

You have probably left anonymous FTP access enabled with write
permissions to your system.

You can have the best security systems in the world but if you leave
the front door wide open......

Start here :

http://securityadmin.info/faq.asp#ftpfolder


Regards,

Paul Lynch
a-chaun NO[at]SPAM NOSPAMmicrosoft.com
12/29/2003 6:55:07 PM

Yes, definitely lock permissions down on the ntfs level for the iusr
account if using anonymous access on any ftp sites. These kb articles
should help show the minimum levels.

187506 INFO: Basic NTFS Permissions for IIS 4.0
http://support.microsoft.com/?id=187506

271071 HOW TO: Set Basic NTFS Permissions for IIS 5.0
http://support.microsoft.com/?id=271071

812614 INFO: Default Permissions and User Rights for IIS 6.0
http://support.microsoft.com/?id=812614

Also consider looking at the ftp properties to lock down the site(s) with
certain ip address exclusions. The IIS logs (start > run > logfiles) may
show his IP address. Then you can lock him out that way.

Keep in mind that the intruder may have installed some more backdoors on
the system.
On the surface it doesn't sound like the intruder is very malevolent.
However, it may not be worth giving him the benefit of the doubt.
There is some good general advice at:
http://www.cert.org/tech_tips/win-UNIX-system_compromise.html

Hope that helps,

Chris - IIS Team
jcochran.nospam NO[at]SPAM naplesgov.com
12/29/2003 7:07:51 PM
On Mon, 29 Dec 2003 08:26:53 -0800, "Johnny"
[quoted text, click to view]

Then you obviously missed something. Updates and patches don't help
if you forget all the other security issues, such as weak passwords,
leaving port 137-139 open on the firewall, running SQL with a blank SA
password, etc.

Start here to fix this:

http://securityadmin.info/faq.asp#hackerstoc

AddThis Social Bookmark Button