Has anyone else tried the Microsoft IIS lockdown tool? I've tried it on one server that was regularly getting hit, and it seems to have stopped all vulnerabiliites so far.
If you went for the default lockdown, try customising the lockdown until you get the response you want. NB You can only undo one lockdown at a time, so you have to undo before reapplying. Sorry, I can't remember the options off the top of my head.
Okay, here is what I figured out. I had to go with the UseAllowExtensions=0 to get my default page to display. The log said that since (null) wasn't set as an allowed option it wouldn't display the page. Anyone know how to add null to the list of allowed extensions? (null) doesn't work.
I also figured out that I had to allow read access to the directory through the IIS manager to view images.
Finally, if you use a programming language like Cold Fusion you need to allow scripts to run.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.