Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


March 2002

Informant: Locating and Disabling Unauthorized IIS Servers

RSS
Subscribe to Windows Web Solutions | See More IIS and Web Administration Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

I have a large network with many IIS servers installed on various systems. How can I locate and disable unauthorized IIS servers on the network systems?

Locating IIS servers on your network is fairly straightforward, and several tools are available for accomplishing this task. All these tools involve scanning your IP address range to see whether a server responds to port 80—the default port for Web services. If you can't connect to port 80, some server application is listening on that port. In many companies, that server application is one of Microsoft's Web servers, such as a Windows 98 machine running Personal Web Server (PWS) or a beta version of Windows .NET Server (formerly code-named Whistler) running IIS 6.0.

You can go a step further than simply scanning your IP address range and obtain one of the hacker tools that not only scans for port 80 but records the server's response. The premier port-scanning tool is Insecure.Org's Network Mapper (nmap.exe) utility. Insecure.Org also has UNIX-based versions of the tool. eEye Digital Security has ported Nmap to a Windows version called Nmapnt.

In addition, the Network Security Hotfix Checker (hfnetchk.exe) tool, which is a free download from Microsoft's Web site, will scan a subnet and report on which hotfixes you've applied to a computer, as Figure 1 shows. Any system with IIS will include a list of required hotfixes. You can use a standard redirection at a command prompt, such as

hfnetchk>scanresults.txt

to capture this output to a text file.

Another useful tool is Rain.Forest.Puppy's Whisker. Whisker is a Web server vulnerability scanner at heart and serves well in detecting IIS servers.

End of Article



Reader Comments
Not really useful, none of this solutions are trustable, well perhaps port scanning, how ever this could cause problems in a monitored corporate network, I'd rather would use ADSI like in this page http://www.netnerds.net/resources/articles.asp?article=iisDiscovery

Cheers :)

Juan Carlos Calderon June 03, 2003


You could also use GFI's Security Scanner
http://www.gfi.com/lannetscan/

I does banner grabs, fingerprinting, and scans for Micro$oft patch levels.

redWolf June 04, 2003


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 24, 2008

An often irreverent look at some of the week's other news, including a Vista Capable dismissal request, Zune price reductions, Morrow musings, Novell and Microsoft sitting in a tree ... two years later, Yahoo!, IE 6 on Windows Mobile, and so much more ...


Related Events Delivering Reliable and Effective Web-Based Applications

Making Web Application Perform Better: What to Watch, How to Watch It, and How to Fix It

Check out our list of Free Email Newsletters!

IIS and Web Administration eBooks Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Related IIS and Web Administration Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing