limbo Posted October 14, 2007 Posted October 14, 2007 Silly question but how secure is WebDaV, especially on Microsoft IIS. WebDav on IIS is a risk - many security professionals will tell you to avoid it, as we found out when our website was hacked. The worst bit is that it had been enabled by the people that set up our server and we were not even using it! We use all http based stuff - email OWA and our MLE/VLE which gives access to the website content management, the helpdesk, blogs, student username lookups / password resets, class lists, attendance records etc. plus complete access to their personal files in realtime (the actual files, not a sychronised copy). HTTPS has only one real function and that is to stop packets being stolen on route from the user to the server by encrypting them - these will not protect against WebDav attacks.
Dafty Posted April 2, 2008 Posted April 2, 2008 Currently we are about to pilot Citrix access for staff. We also use Exchange 2007 OWA, the staff love the 2007 version and find it much easier to use.
box_l Posted April 3, 2008 Posted April 3, 2008 sonicwall sslvpn-2000 but we are not using the vpn bit, as i cannot trust any machine external to the schools AV setup. and it works really well. BoX
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now