[Dshield] Short story/Code Red question

Jay Wren JRWren at advnetworks.com
Wed Aug 8 21:06:50 GMT 2001


> -----Original Message-----
> From: Steve Simek [mailto:ssimek at captivasoftware.com]
> Sent: Wednesday, August 08, 2001 2:54 PM
> To: 'dshield at dshield.org'
> Subject: [Dshield] Short story/Code Red question
> 

clip

> Now the question. I called the user to advise he was 
> infected. He had a
> vanilla W2k machine and didn't bother to patch it since he 
> didn't think IIS
> was on. I've read it's on by default. But, not the whole IIS 
> package, I
> can't believe that.... Haven't tried it myself.... What's the 
> real answer?


The real answer is:
Win2k server, by default installs IIS.  Win2k Professional, by default, does
not install IIS.

That said, it is very trivial, to click a custom install of either one, and
disable that specific function at install time.

I hope this answers your question.

-Jay




More information about the list mailing list