Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Hack iis6 contest underway..
http://www.hackiis6.com/ ^ | 2005-05-05 | http://www.hackiis6.com/

Posted on 05/05/2005 12:52:05 PM PDT by N3WBI3

1) Most security breaches are caused by not following basic security guidelines and best practices. We want to put IIS 6.0 to the test to see if it is highly secure when you implement it correctly.

2) Because it's a fun way to engage with you, our audience!

3) It's a chance to share knowledge and demonstrate how to protect your system against hack attempts. Coming in our July issue, we'll publish an article "How to Set Up a Hackproof IIS" featuring Roger Grimes' recap of the contest, and sharing the secrets of how he created an impenetrable IIS environment.


TOPICS: Computers/Internet
KEYWORDS: hack; iis; microsoft
An iis6 guy putting his money where his mouth is. I dont advocate hacking other peoples boxes but as a hardening test it should be interesting
1 posted on 05/05/2005 12:52:07 PM PDT by N3WBI3
[ Post Reply | Private Reply | View Replies]

To: Swordmaker


2 posted on 05/05/2005 12:52:21 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 1 | View Replies]

To: N3WBI3
We want to put IIS 6.0 to the test to see if it is highly secure when you implement it correctly.

And your reasoning for this is ...?

3 posted on 05/05/2005 12:54:19 PM PDT by softwarecreator (Facts are to liberals as holy water is to vampires)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Ping


4 posted on 05/05/2005 12:55:20 PM PDT by stylin_geek (Liberalism: comparable to a chicken with its head cut off, but with more spastic motions)
[ Post Reply | Private Reply | To 2 | View Replies]

To: N3WBI3

These kinds of things typically don't amount to much - even if it stays up, that's hardly proof of invulnerability. Frankly, if I had a reliable, repeatable way of cracking into IIS, I'd want a heck of a lot more than an XBox in exchange for that information.


5 posted on 05/05/2005 12:55:48 PM PDT by general_re ("Frantic orthodoxy is never rooted in faith, but in doubt." - Reinhold Niebuhr)
[ Post Reply | Private Reply | To 1 | View Replies]

To: N3WBI3

I know I'm going to look at this, simply because we do multi million dollar secure bank transactions where I work. And the sites require IE.


6 posted on 05/05/2005 12:56:41 PM PDT by stylin_geek (Liberalism: comparable to a chicken with its head cut off, but with more spastic motions)
[ Post Reply | Private Reply | To 1 | View Replies]

To: softwarecreator
And your reasoning for this is ...?

I would bet it is to test to see if it is highly secure when you implement it correctly.

7 posted on 05/05/2005 12:57:01 PM PDT by Flyer (If I were 8 pixels tall I could fit in my tag line)
[ Post Reply | Private Reply | To 3 | View Replies]

To: general_re

You get to say that you're the guy who hacked IIS. Nobody really cares about the XBox and most contestants aren't interested in that anyway.


8 posted on 05/05/2005 12:58:56 PM PDT by t_skoz ("let me be who I am - let me kick out the jams!")
[ Post Reply | Private Reply | To 5 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

9 posted on 05/05/2005 1:05:50 PM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: N3WBI3

huh...? oh.
10 posted on 05/05/2005 1:09:51 PM PDT by struggle ((The struggle continues))
[ Post Reply | Private Reply | To 1 | View Replies]

To: t_skoz

If I'm the guy who can hack IIS, I can probably parlay that skill into more tangible rewards than nerd-kudos ;)


11 posted on 05/05/2005 1:10:16 PM PDT by general_re ("Frantic orthodoxy is never rooted in faith, but in doubt." - Reinhold Niebuhr)
[ Post Reply | Private Reply | To 8 | View Replies]

To: softwarecreator
And your reasoning for this is ...?

Because the guy doing this makes his living pushing Microsoft products.

12 posted on 05/05/2005 1:10:19 PM PDT by antiRepublicrat
[ Post Reply | Private Reply | To 3 | View Replies]

To: softwarecreator
Hey dont jump on me, this guy is a MS users and tech writer...

Roger A. Grimes
Contributing editor, Windows IT Pro Magazine

13 posted on 05/05/2005 1:38:54 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 3 | View Replies]

To: general_re

Umm not really hacking iis is not a one in a million type of deal. There is a reason you secure in layers and thats because a naked iis6 box on the net is just waiting to be hacked..


14 posted on 05/05/2005 1:41:08 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 11 | View Replies]

To: general_re
even if it stays up, that's hardly proof of invulnerability.

True. But if it doesn't stay up, that's certainly proof of vulnerability. ;-p
15 posted on 05/05/2005 2:18:11 PM PDT by Bush2000
[ Post Reply | Private Reply | To 5 | View Replies]

To: N3WBI3

I wasn't. I was in the middle of writing it and had to go. Accidently pushed the "reply" button.


16 posted on 05/05/2005 2:28:42 PM PDT by softwarecreator (Facts are to liberals as holy water is to vampires)
[ Post Reply | Private Reply | To 13 | View Replies]

To: N3WBI3; Bush2000
...a naked iis6 box on the net is just waiting to be hacked..

Oh, no - IIS 6/Windows Server 2003 is actually quite tight, even in the default configuration. I predict it won't be cracked, because the people most likely to be able to do it are the least likely to want to reveal that ability.

17 posted on 05/05/2005 2:29:40 PM PDT by general_re ("Frantic orthodoxy is never rooted in faith, but in doubt." - Reinhold Niebuhr)
[ Post Reply | Private Reply | To 14 | View Replies]

To: N3WBI3
I know a guy that worked as a consultant to Microsoft when they did this for Windows 2000, and that box never got hacked. He said all they did was lock every port but 80 down with IPSec, and shut down every unneccesary service.

Despite what some people will tell you, a fully patched box with proper usernames/passwords implemented is practically impossible to hack, the only way is if you have access to a "zero day" exploit that no one knows about or has had time to develop a defense for. Anybody that has one of those probably isn't going to waste it for an XBOX, unless they really want to try to humiliate Microsoft. But give MS some credit, not only have they already tried this before, and succeeded, they're willing to risk it again.

18 posted on 05/05/2005 4:03:58 PM PDT by Golden Eagle (Team America)
[ Post Reply | Private Reply | To 1 | View Replies]

To: N3WBI3
Umm not really hacking iis is not a one in a million type of deal. There is a reason you secure in layers and thats because a naked iis6 box on the net is just waiting to be hacked..

Then go for it. If it's so easy, it should be a piece of cake for you. Or, are you just blowing smoke?
19 posted on 05/05/2005 5:54:32 PM PDT by Bush2000
[ Post Reply | Private Reply | To 14 | View Replies]

To: general_re
because the people most likely to be able to do it are the least likely to want to reveal that ability

This was the point I wanted to make in #3, but got called away and accidently posted it.

If you are a 'expert' hacker, what reason would you have to expose yourself and your 'methods'?  An X-Box?  Makes no sense to me, but then I never understood the thrill of hacking anyway, so what do I know?

20 posted on 05/05/2005 7:13:44 PM PDT by softwarecreator (Facts are to liberals as holy water is to vampires)
[ Post Reply | Private Reply | To 17 | View Replies]

To: Bush2000
Then go for it. If it's so easy, it should be a piece of cake for you. Or, are you just blowing smoke?

Well, N3WBI3, sounds like a dare ... you, and others like you, come here and say how easy it is ... go for it.

If no one here does it, then I guess you'll all have to stop the "see-how-vulnerable-MS-is" type of claims.

21 posted on 05/05/2005 7:16:52 PM PDT by softwarecreator (Facts are to liberals as holy water is to vampires)
[ Post Reply | Private Reply | To 19 | View Replies]

To: Bush2000
Anything is hackable; apache, iis, sunOne, .... THats why I said security in layers. Whay the hell did you jump on me for that?

Can I hack it? maybe, if I really put my time into it. Im not a gifted hacker but I do have a good deal of experience on iis as an admin. Personally the amount of time I would have to put into it (if I could do it) is not worth an x-box to me..

22 posted on 05/05/2005 8:15:10 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 19 | View Replies]

To: softwarecreator

or it might be im too busy with a wife who is now two days past her due date, moving into a new house, finishing a class at school, and rebuilding our weblogic platform... A naked *anything out there* can be hacked..


23 posted on 05/05/2005 8:19:11 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 21 | View Replies]

To: N3WBI3
or it might be im too busy with a wife who is now two days past her due date, moving into a new house

Well, yeah, sure, it could be that too!  =)

Congrats on the upcoming baby!

My wife and I are also closing on a new house next week, so I know how you feel.

24 posted on 05/05/2005 8:31:30 PM PDT by softwarecreator (Facts are to liberals as holy water is to vampires)
[ Post Reply | Private Reply | To 23 | View Replies]

To: softwarecreator

new construction or an existing one?


25 posted on 05/05/2005 9:14:56 PM PDT by N3WBI3
[ Post Reply | Private Reply | To 24 | View Replies]

To: Golden Eagle
unless they really want to try to humiliate Microsoft.

That's about the only reason one of them would go for it. Unless they need a new computer and want the XBox to put Linux on.

26 posted on 05/06/2005 6:46:55 AM PDT by antiRepublicrat
[ Post Reply | Private Reply | To 18 | View Replies]

To: antiRepublicrat
That's about the only reason one of them would go for it. Unless they need a new computer and want the XBox to put Linux on.

Yep, being a hacker, probably would.

27 posted on 05/06/2005 12:19:19 PM PDT by Golden Eagle (Team America)
[ Post Reply | Private Reply | To 26 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson