Groups | Blog | Home
all groups > iis security > june 2006 >

iis security : Windows Server Hardeing


Eng.Rana NO[at]SPAM gmail.com
6/19/2006 1:33:51 AM
Hi all,


I was wondering why do we need to harden Windows server 2003 by
applying rules like:
1.Remove any unneeded Services
2.Close unneeded ports
3.Rename Administrator account
4.Prevent users from installing printer drivers
5.Restrict CD-ROM and floppy access to locally logged-on user only


.... and many many more

why are we doing so ?????
and what is the main problem with the default installations.

i tried searching the net but all what i found is that what to do, but
not why do we do each step and what is the effect of not applying it.

thanks for ur help and time
Roger Abell [MVP]
6/19/2006 8:43:58 AM
Eng
See my reply to your identical posting to
microsoft.public.security
I did not see anything specific about IIS in your post,
but branching out from
www.microsoft.com/technet/security
you can find most all hardening and securing guides
by particular product.
Roger
[quoted text, click to view]

AddThis Social Bookmark Button