Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register iSpy Downloads New Posts Donate Unanswered Posts Member List Search

Computer Juice raffle - Win PC hardware of your choice worth £500 / €680 / $1000 - Enter HERE!


Computer Juice - Forums - web server security...unbreakable?


Reply
 
Thread Tools
  #1  
Old 12-05-2008, 12:41 PM
Nikronius's Avatar
CJ Member
 
Nikronius is offline
Send a message via MSN to Nikronius Send a message via Yahoo to Nikronius Send a message via Skype™ to Nikronius
 
Join Date: Dec 2007
Last Online: 14-06-2008 11:33 PM
Posts: 53
iTrader: (0)
Nikronius is on a distinguished road
Default

web server security...unbreakable?


Hi there guys.

well I have been with too much free time lately and I have been learning in the meantime about web server security.

I just arrived to a Question:

lets say you have a MS IIS 5.0 based on Windows 2000, very well patched and secured with a very nice cisco 12.x that only allows port 80.

Still you have problems with XSS in the page and have some services active like IPP (very well known for its vulnerability back in time ;)

Is it possible for a hacker compromise your webserver just with XSS?? as far as I've heard that can only inject html and js in to the page but cant do more than that...

And then i ask the other question is it any kind of security that is "unbreakable"?? wich means that no matter how hard an attacker tries he will never be able to compromise your webserver??

if you were an attaker what would you try to do? keeping in mind that there is only 1 port open and only 1 vulnerability at sight (XSS, cause IPP is already patched)

is it possible to exploit the cisco router or a firewall??, I have read a little bit about that but i dont think is that easy no?

I would like to know cause it is my duty to harden the security of my webserver and I can only do that by knowing little bit more right?? :)

thanks in advance.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 12-05-2008, 07:17 PM
Mike0001's Avatar
CJ Donator
Intel Nvidia
Mike0001 is offline
 
Join Date: Aug 2007
Last Online: 04-07-2008 05:19 PM
Posts: 1,149
iTrader: (0)
Mike0001 is on a distinguished roadMike0001 is on a distinguished road
Default

web server security...unbreakable?


Personally, I would convert to the industry standard Apache server and not touch IIS with a bargepole.

I guess we may never be secure against DDOS attacks.
__________________
I think I am a signature, therefore I exist!
I believe a higher being has me as a signature...
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
SSL Security sdghosh Web Design & Programming 1 27-11-2007 08:20 PM
News - Another Step Towards Unbreakable Quantum Encryption NewsBot Industry News & Reports 0 13-06-2007 12:09 PM
News - Another Step to Unbreakable Quantum Encryption NewsBot Industry News & Reports 0 13-06-2007 10:09 AM
News - Oracle partners put weight behind Unbreakable Linux NewsBot Industry News & Reports 0 27-04-2007 06:00 PM
what is WEP security on my psp? kelly m PC & Console Gaming 4 31-03-2007 03:54 AM



Copyright ©2006 - 2008 Computer Juice - Forums - Free PC Help, Support and Repairs.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.