Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


February 2006

Not News: Security Is Your #1 IIS Concern

News: IIS 7.0 tackles security, manageability, the metabase, and componentization
RSS
Subscribe to Windows IT Pro | See More Administration Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

CGI is an example. "It's always on the IIS 6 box, whether you use CGI or not. It's off by default in IIS 6, but it's always there. So if a CGI patch comes out, you have to install it. With IIS 7, we've ported all those features that were previously baked into that one DLL on top of a new API, and we're porting them as individual modules—individual DLLs. So now if you're not using CGI, you don't have to install the CGI module. We now have more than 40 modules you can add and remove independently, which helps admins reduce their attack surface more than ever. Also, if you're not using the CGI module and a CGI patch comes out, you'll never even see it because the binary that implements it is not on the box."

What about rebooting? "A lot of the binaries that run inside the worker process are already installable without a reboot," Bill explained. "You can install the patch and recycle the worker process, and it automatically picks up the new DLL. Actually, I don't think there's any IIS reason for reboots. Sometimes you have to restart the service, but no reboots. Often, rebooting results from the patching infrastructure for Windows OS, but the Windows team is also working to minimize reboots."

Are We Secure Yet?
The security strategy for IIS 6 was locking down potential attack vectors. "As a result," Bill pointed out, "we haven't had a single critical security fix for IIS 6 since release." However, my takeaway from talking with Bill and Eric was that they realize they have to go beyond lockdown with IIS 7 and rebuild the product to incorporate security throughout.

Eric said they recognized that "there's a hangover effect from NT 4.0. Back then, we designed IIS for ease of use and getting up on the Internet fast. Code Red and Nimda cost our customers millions of dollars and hours of downtime. That's why now we think about how far out will security go."

Bill added, "Customers want Microsoft not only to prevent security issues but also to be proactive by helping customers stay secure in terms of detecting new vulnerabilities and helping customers understand how to cope better with the hostile environment on the Internet. So because of the secure defaults, internal code reviews, and new features we've built in, IIS 7 has multiple layers now protecting customers."

End of Article

   Previous  1  [2]  Next  


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Learning Path For a summary of security enhancements to IIS 7.0
"More Flexible Security Controls in IIS 7.0, October 2005"


For more about IIS 7.0's componentization
"As We See IT, IIS 7.0 is slim, trim, and more secure, August 2005"


Read Brett Hill's report on his first look at IIS 7.0
"Betabox, TechNet Magazine, November-December 2005"


Top Viewed ArticlesView all articles
Microsoft Kills OneCare, Will Launch Free Security Solution

Microsoft on Tuesday announced that it would retire its $50-a-year security subscription product, Windows Live OneCare, and replace it with a free solution codenamed "Morro." Unlike OneCare, however, Morro will focus only on core anti-malware features and ...

The website is down because someone removed the X-Box

What happens when a manager mistakes a server for a games console. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing