Free Republic
Browse · Search
General/Chat
Topics · Post Article

An iis6 guy putting his money where his mouth is. I dont advocate hacking other peoples boxes but as a hardening test it should be interesting
1 posted on 05/05/2005 12:52:07 PM PDT by N3WBI3
[ Post Reply | Private Reply | View Replies ]


To: Swordmaker


2 posted on 05/05/2005 12:52:21 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 1 | View Replies ]

To: N3WBI3
We want to put IIS 6.0 to the test to see if it is highly secure when you implement it correctly.

And your reasoning for this is ...?

3 posted on 05/05/2005 12:54:19 PM PDT by softwarecreator (Facts are to liberals as holy water is to vampires)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: N3WBI3

These kinds of things typically don't amount to much - even if it stays up, that's hardly proof of invulnerability. Frankly, if I had a reliable, repeatable way of cracking into IIS, I'd want a heck of a lot more than an XBox in exchange for that information.


5 posted on 05/05/2005 12:55:48 PM PDT by general_re ("Frantic orthodoxy is never rooted in faith, but in doubt." - Reinhold Niebuhr)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: N3WBI3

I know I'm going to look at this, simply because we do multi million dollar secure bank transactions where I work. And the sites require IE.


6 posted on 05/05/2005 12:56:41 PM PDT by stylin_geek (Liberalism: comparable to a chicken with its head cut off, but with more spastic motions)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

9 posted on 05/05/2005 1:05:50 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: N3WBI3

huh...? oh.
10 posted on 05/05/2005 1:09:51 PM PDT by struggle ((The struggle continues))
[ Post Reply | Private Reply | To 1 | View Replies ]

To: N3WBI3
I know a guy that worked as a consultant to Microsoft when they did this for Windows 2000, and that box never got hacked. He said all they did was lock every port but 80 down with IPSec, and shut down every unneccesary service.

Despite what some people will tell you, a fully patched box with proper usernames/passwords implemented is practically impossible to hack, the only way is if you have access to a "zero day" exploit that no one knows about or has had time to develop a defense for. Anybody that has one of those probably isn't going to waste it for an XBOX, unless they really want to try to humiliate Microsoft. But give MS some credit, not only have they already tried this before, and succeeded, they're willing to risk it again.

18 posted on 05/05/2005 4:03:58 PM PDT by Golden Eagle (Team America)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson