OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Showcode.asp
From: Steve (steveSECURESOLUTIONS.ORG)
Date: Thu May 18 2000 - 22:58:33 CDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I would agree. In general, you are much more secure by keeping your
web on a separate partition that contains NOTHING but files related
to the web site. Of course, in a lot of cases this isn't entirely
possible.

This should be one of the first steps taken when implementing web
with IIS.

Steve Manzuik
Secure Solutions
www.securesolutions.org

>
>
> The article points out several files of interest that a person
> could look at; but really, any file on the same partition and/or
> the C: drive (if the C: drive partition is different from the
> webroot partition), many of which pose an immediate and direct
> security risk.
>

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.3 for non-commercial use <http://www.pgp.com>

iQA/AwUBOSS75TV9eGvIXwM6EQJJ4QCfRh6QuSbUuhXpNGSLSV55tR45uMsAn3n0
UuzpM0Se9ej7qRPGiuQ94Lvd
=KPdQ
-----END PGP SIGNATURE-----