Configuring Additional Security Measures for IIS 6.0

In IIS 6.0, Microsoft increased the default security measures for IIS. IIS is no longer installed by default when you install Windows Server 2003, and the default installation locks down the service to limit the server to hosting static HTML initially. Table 24-2 compares the default installation states for IIS 5.0 and IIS 6.0.

Table 24-2. Default Installation States for IIS 5.0 and IIS 6.0
IIS ComponentIIS 5.0 Default InstallationIIS 6.0 Default Installation
Static file supportEnabledEnabled
Active Server PagesEnabledDisabled
Server-side includesEnabledDisabled
Internet Data ConnectorEnabledDisabled
WebDAVEnabledDisabled
Index Server ISAPIEnabledDisabled
Internet Printing ISAPIEnabledDisabled
CGI ...

Get Microsoft® Windows® Security Resource Kit, Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.