Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Secure Your Website in IIS

IIS is the web server that comes with Windows Server. This guide gives simple ways to make a site on IIS safer. It needs admin access to the Windows server, such as on a VPS or dedicated server.

Web Hosting2 min read11 steps8 screenshots

What is IIS?

A web server is a program that sends web pages to visitors. IIS stands for Internet Information Services. You manage it with a tool called IIS Manager.

Screenshot: A web server is a program that sends web pages to visitors. IIS stands for Internet Inform

Warning: Some changes can stop your site from loading. Take a backup of your site and its settings first.

Steps

  1. Keep Windows updated. Open Settings, then Windows Update. Install updates often. Updates close known security holes.
  2. Install an SSL certificate. SSL is a digital lock that hides data between visitor and site. In IIS Manager, click your site, then Bindings, then add an https binding with your certificate.
  3. Redirect http to https. Install the URL Rewrite add-on, then add a rule that sends all plain http visitors to https.
  4. Remove what you do not use. In Server Manager, open Manage, then Remove Roles and Features. Fewer features mean fewer ways in.
  5. Turn off directory browsing. In IIS Manager, open Directory Browsing for your site and click Disable. This stops visitors from seeing a list of your files.
    Screenshot: Turn off directory browsing. In IIS Manager, open Directory Browsing for your site and cli
  6. Use separate application pools. An application pool is a private workspace for a site. Give each site its own pool, so one hacked site cannot easily touch another.
    Screenshot: Use separate application pools. An application pool is a private workspace for a site. Giv
  7. Limit file permissions. Give the pool identity only the rights it needs. Allow write access only to folders that must save files, such as uploads.
    Screenshot: Limit file permissions. Give the pool identity only the rights it needs. Allow write acces
  8. Hide server details. Remove the X-Powered-By header in HTTP Response Headers. Less information helps attackers less.
    Screenshot: Hide server details. Remove the X-Powered-By header in HTTP Response Headers . Less inform
    Screenshot: Hide server details. Remove the X-Powered-By header in HTTP Response Headers . Less inform
  9. Use request filtering. Open Request Filtering. Block file types you never serve, and set a sensible upload size limit.
  10. Turn on logging. Open Logging for your site and keep it enabled. Read the logs to spot strange visits.
  11. Use strong passwords for admin accounts. Turn on the Windows firewall and open only the ports you need.
Tip: Menu names differ a little between Windows Server versions, but the ideas are the same. Not sure about a step? Ask Hostvento support.

Quick recap

  • Update Windows and IIS regularly.
    Screenshot: Update Windows and IIS regularly.
    Screenshot: Update Windows and IIS regularly.
  • Use SSL and redirect to https.
  • Turn off directory browsing and remove unused features.
  • Give each site its own application pool and minimal permissions.
  • Keep logs on and use strong passwords.
  • Back up before changing settings.