Groups | Blog | Home
all groups > iis security > march 2005 >

iis security : Requisites for a very unsafe IIS5!


John Leerentveld
3/8/2005 3:18:19 PM
Hi,
for an ethical hacking training I need to have a IIS configuration that's
very unsecure, so I can test
and show the vulnerability.
What should I do? Install Windows 20000 out-of-the-box without any
SP's/patches?

John

Miha Pihler [MVP]
3/8/2005 6:10:49 PM
Hi John,

If you really want to teach users something, then have a fully patched up
computer; then show them vulnerabilities...

I don't see much point in showing off 4 or more years old holes that were
patched up long time ago.

--
Mike
Microsoft MVP - Windows Security

[quoted text, click to view]

Jason Brown [MSFT]
3/9/2005 12:04:32 PM
Unless of course that's the point of the presentation - ongoing improvement,
the importance of patching your boxes, keeping naked installs offline,
slipstreaming patches into fresh installs to mitigate the danger from new
installs etc...

otherwise agreed. I'd also be looking at vulnerabilities in the the
application layer such as SQL injection, Session hijacking, cross-site
scripting, packet sniffing and so on - they're more common than unpatched
IIS boxes by far, and easier to demo exploits on.


--
Jason Brown
Microsoft GTSC, IIS

This posting is provided "AS IS" with no warranties, and confers no rights.



[quoted text, click to view]

jeff.nospam NO[at]SPAM zina.com
3/9/2005 5:18:08 PM
On Tue, 8 Mar 2005 15:18:19 +0100, "John Leerentveld"
[quoted text, click to view]

Keep in mind that IIS security depends heavily on the security of the
underlying box and file system. Use "password" as the admin password
for example, and give all accounts full access to everything. Make
sure there are no firewall, no authentication and all the default
shares are there.

Though it makes for a pretty poor class since realistically you should
never come across such a setup.

AddThis Social Bookmark Button