Protect IIS log files by moving them to a secure location
Takeaway: Internet Information Services (IIS) continues to be a favorite target for hackers. Make their job harder by moving IIS' log files to a secure remote location. Mike Mullins tells you how in this edition of Security Solutions.
Microsoft's Internet Information Services (IIS) remains one of the most compelling targets for hackers and script kiddies. By default, these Web servers must allow public access to their resources. If I had to guess, I'd say these servers spend more of their time fending off attacks than actually serving up Web pages.
Unless your organization's Web site has been the victim of defacement or injection of some hostile code, a hacker's attempt to break into your Web server can often go unnoticed, thanks to the sheer volume of traffic that the server's likely to receive. But you can make things a little more difficult for hackers to hide their mischief—and easier for yourself to uncover their deeds. All it takes is adding a little security to your Web server's log files.
If a hacker attacks your Web server—or even if you just want to check its security status—Web logs are the first place you should go for information. By default, you can find these logs in %SYSTEMROOT%/System32/logfiles.
However, this is a well-known location, so you should move the log files to a non-system drive that doesn't house your Web site. To change the location of your log files, log on to the Web server with an account that has administrative rights.
Follow these steps:
- Go to Start, right-click My Computer, and select Explore.
- Navigate to the drive and folder location where you want to relocate the IIS log files.
- Right-click inside the right-hand window pane, and select New | Folder.
- Enter a name for the folder (e.g., MyIISLogs), and press [Enter].
- Go to Start | Control Panel, double-click the Administrative Tools applet, and double-click Internet Information Services (IIS) Manager.
- Right-click the Web site, and select Properties.
- On the Web Site tab, select Properties in the Enable Logging frame.
- On the General Properties tab, click Browse, and then navigate to the folder you just created to store the IIS log files.
- Click OK three times.
Repeat these steps for each Web site. Don't forget that you'll need to manually move any previous files from the old log directory to the new one.
Now that your log files have a new home, you need to assign the directory the proper permissions. Follow these steps:
- Right-click the folder you just created, and select Properties.
- On the Security tab, deselect the Allow Inheritable Permissions From Parent To Propagate To This Object check box.
- A warning box will appear that says you're preventing inheritable permissions from propagating; select Remove, and select Add.
- Add the System and Local Administrator accounts, and select OK.
- Click Administrators, and set to Full Control.
- Click System, set to Full Control, and click OK.
You've now tucked away your Web logs in a secure remote location.
Final thoughts
Log files are the only way you'll ever reconstruct events that aspire to bring down your Web server. Move them, monitor them, and consider transferring them daily (or backing them up) to an off-Web location.
Miss a column?
Check out the Security Solutions Archive, and catch up on the most recent editions of Mike Mullins' column.
Worried about security issues? Who isn't? Automatically sign up for our free Security Solutions newsletter, delivered each Friday, and get hands-on advice for locking down your systems.
Mike Mullins has served as an assistant network administrator and a network security administrator for the U.S. Secret Service and the Defense Information Systems Agency. He is currently the director of operations for the Southern Theater Network Operations and Security Center.
White Papers, Webcasts, and Downloads
- Tom Davenport Study: Linking decisions and information for organizational performance IBM Tom Davenport's new client study looks at approaches to linking ... Download Now
- Five Steps to Determine When to Virtualize YourServers VMware Thinking of virtualizing the servers at your company? Use this step-by-step guide to determine when's the best time to make your big move. Download Now
- Building the Virtualized Enterprise with VMware Iinfrastructure VMware VMware virtualization software has been adopted by over 120,000 enterprise ... Download Now
- The Scalable Enterprise: VMware ESX Server on the Dell PowerEdge 6650 Dell This paper introduces the server virtualization software, VMware ESX ... Download Now
- Why Isn't Server Virtualization Saving Us More? A Few Small Changes May Dramatically Increase Your Efficiency VMware Ever wonder why your company isn't saving more from its server virtualization? Making a few small changes could dramatically increase your efficiency. Download Now
Article Categories
- Security
- Security Solutions, IT Locksmith
- Networking and Communications
- E-mail Administration NetNote, Cisco Routers and Switches
- CIO and IT Management
- Project Management, CIO Issues, Strategies that Scale
- Desktops, Laptops & OS
- Windows 2000 Professional, Microsoft Word, Microsoft Excel, Microsoft Access, Windows XP,
- Data Management
- Oracle, SQL Server
- Servers
- Windows NT, Linux NetNote, Windows Server 2003
- Career Development
- Geek Trivia
- Software/Web Development
- Web Development Zone, Visual Basic, .NET
Designing the next killer product
Developing new ways to collaborate
Overseeing IT operations across a global organization
The biggest security threats facing companies in 2009
