Jump to content

Recommended Posts

Posted
Silly question but how secure is WebDaV, especially on Microsoft IIS.

 

WebDav on IIS is a risk - many security professionals will tell you to avoid it, as we found out when our website was hacked. The worst bit is that it had been enabled by the people that set up our server and we were not even using it!

 

We use all http based stuff - email OWA and our MLE/VLE which gives access to the website content management, the helpdesk, blogs, student username lookups / password resets, class lists, attendance records etc. plus complete access to their personal files in realtime (the actual files, not a sychronised copy).

 

HTTPS has only one real function and that is to stop packets being stolen on route from the user to the server by encrypting them - these will not protect against WebDav attacks.

  • 5 months later...
Posted

Currently we are about to pilot Citrix access for staff.

 

We also use Exchange 2007 OWA, the staff love the 2007 version and find it much easier to use.:)

Posted

sonicwall sslvpn-2000

 

but we are not using the vpn bit, as i cannot trust any machine external to the schools AV setup.

 

and it works really well.

 

BoX

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...