![]() ![]() ![]() ![]() |
![]() Here are my notes on hardening (securing) Microsoft's Internet Information Server against attacks. All topics are in this one large file for quick searches through all topics. | Topics this page:
|
|
To check for the presence of a web server (IIS) on a local machine listening on port 80, open up an internet browser (Internet Explorer) and type:
If you see The webpage cannot be found a web server is not running on the machine.
By default, files are displayed from folder C:\inetpub\wwwroot, which after installation contains Default document file iisstart.htm.
Unless otherwise configured, the document displayed follows this priority of display (the top file is displayed, if defined):
Most people now use Microsoft Web Platform Installer, wpilauncher.exe (113 KB). As of May, 2014, the spotlight is on the Azure cloud rather than local instances. Click on Products, Server, Name. Scroll down. Note IIS is already Installed.
Click on Recommended Configuration.
IIS Express is required for use with WebMatrix.
IIS comes with Windows, so the service is installed from Start icon > Control Panel.
Start icon > right-click on Computer > select Manage. Within Computer Management, the Services and Applications tree.
| ![]()
| ![]() ![]() ![]() |
|
![]()
| ![]() ![]() ![]() |
|
Registry Key | Recommended Value |
---|---|
Tcpip\Parameters\SynAttackProtect | 0 |
Tcpip\Parameters\TcpMaxHalfOpen | 100 (500 on Advanced Server) |
Tcpip\Parameters\TcpMaxHalfOpenRetried | 80 (400 on Advanced Server) |
Tcpip\Parameters\EnablePMTUDiscovery | 0 |
NetBt\Parameters\NoNameReleaseOnDemand | 0 |
Tcpip\Parameters\EnabledDeadGWDetect | 0 |
Tcpip\Parameters\KeepAliveTime | 300,000 |
Tcpip\Parameters\Interfaces\PerformRouterDiscovery | 0 |
Tcpip\Parameters\EnableICMPRedirects | 0 |
Related Topics:
ASP Programming
Website Security
Win2000 Install
Active Directory
Win2000 Admin
WinNT4 Install
Keyboard Shortcuts
Free Training!
Tech Support
![]()
| Your first name: Your family name: Your location (city, country): Your Email address: |
Top of Page ![]() Thank you! |