Microsoft's Internet Information Services (IIS) remains one of the most compelling targets for hackers and script kiddies. By default, these Web servers must allow public access to their resources. If I had to guess, I'd say these servers spend more of their time fending off attacks than actually serving up Web pages.

Unless your organization's Web site has been the victim of defacement or injection of some hostile code, a hacker's attempt to break into your Web server can often go unnoticed, thanks to the sheer volume of traffic that the server's likely to receive. But you can make things a little more difficult for hackers to hide their mischief—and easier for yourself to uncover their deeds. All it takes is adding a little security to your Web server's log files.

If a hacker attacks your Web server—or even if you just want to check its security status—Web logs are the first place you should go for information. By default, you can find these logs in %SYSTEMROOT%/System32/logfiles.

However, this is a well-known location, so you should move the log files to a non-system drive that doesn't house your Web site. To change the location of your log files, log on to the Web server with an account that has administrative rights.

Follow these steps:

  1. Go to Start, right-click My Computer, and select Explore.
  2. Navigate to the drive and folder location where you want to relocate the IIS log files.
  3. Right-click inside the right-hand window pane, and select New | Folder.
  4. Enter a name for the folder (e.g., MyIISLogs), and press [Enter].
  5. Go to Start | Control Panel, double-click the Administrative Tools applet, and double-click Internet Information Services (IIS) Manager.
  6. Right-click the Web site, and select Properties.
  7. On the Web Site tab, select Properties in the Enable Logging frame.
  8. On the General Properties tab, click Browse, and then navigate to the folder you just created to store the IIS log files.
  9. Click OK three times.

Repeat these steps for each Web site. Don't forget that you'll need to manually move any previous files from the old log directory to the new one.

Now that your log files have a new home, you need to assign the directory the proper permissions. Follow these steps:

  1. Right-click the folder you just created, and select Properties.
  2. On the Security tab, deselect the Allow Inheritable Permissions From Parent To Propagate To This Object check box.
  3. A warning box will appear that says you're preventing inheritable permissions from propagating; select Remove, and select Add.
  4. Add the System and Local Administrator accounts, and select OK.
  5. Click Administrators, and set to Full Control.
  6. Click System, set to Full Control, and click OK.

You've now tucked away your Web logs in a secure remote location.

Log files are the only way you'll ever reconstruct events that aspire to bring down your Web server. Move them, monitor them, and consider transferring them daily (or backing them up) to an off-Web location.

Do you need help with IIS? Gain advice from Builder AU forums

Comments

1

sami - 30/09/09

i fear these many steps are not understood by all users

for me i saw in these hard attacks only a way to impeach independant people and protect some zealots

» Report offensive content

Leave a comment

You must read and type the 6 chars within 0..9 and A..F

* indicates mandatory fields.

1

sami - 30/09/09

i fear these many steps are not understood by all users for me i saw in these hard attacks only a way ... more

Log in


Sign up | Forgot your password?

  • Staff Microsoft shows off IE9 preview

    This week, highlights from Microsoft's MIX10 conference and more in the Roundup. Read more »

    -- posted by Staff

  • Chris Duckett IE9's H.264 vote killed Ogg

    In a split decision by the judges, the winner of the W3C/WHATWG video codec consensus is H.264, taking home the future of video playback on the internet while loser Ogg goes home with nothing but thoughts of what might have been. Read more »

    -- posted by Chris Duckett

  • Staff Google launches Apps Marketplace

    Google launches and app store, while Mozilla plans to re-write its open-source license. More of this week's news in the Roundup. Read more »

    -- posted by Staff

What's on?

  • Optus Deal

    Broadband + home phone + PlayStation®3 in a single package price!