Aug 9, 2011
tom

iis vulnerability

Question

If IIS has a vulnerability and a administrator shuts down port 80 so IIS cannot listen on it. Will that same vulnerability be present on port 443(https)? Thank you for taking the time to look consider this.

Answer

It depends on the exact vulnerability, but in general yes. If the vulnerability is with an application on the IIS server, then it is extremely likely to be still vulnerable.

Related posts:

  1. Sencha Ext JS 4 framework examples on IIS 7 configured NOT on port 80 doesn’t work
  2. How to expose just part of a Website to the WWW in IIS 7?
  3. Enabling Details HTTP Errors for a certain network in IIS 7
  4. MS Analysis Services + IIS – configuration/connection issue
  5. IIS Virtual directory/application name in upper case

Leave a comment