With Internet Information Services (IIS) so widely used, several vendors have created commercial products you can use to test, improve or otherwise manage its security. But, if you're like most people and have a limited budget, you need alternatives. Well, don't fret. There are indeed some viable alternatives for finding some of the big issues and locking down IIS. And it won't cost you a dime.
Some security tools are completely free – that is, no marketing strings are attached. Others are offered up as, "try this and we think you'll like it so much that you'll buy our commercial version." Either way, who cares? You still have a set of free security tools that'll improve the security of your IIS Web environment. Here they are:
Figure 1
[IMAGE]
Figure 1 -- N-Stalker Free Edition web vulnerability scanner
Figure 2
[IMAGE]
Figure 2 -- Acunetix WVS Free Edition Web vulnerability scanner
Figure 3
[IMAGE]
Figure 3 -- Microsoft's wfetch HTTP analysis tool
Don't forget about
To continue reading for free, register below or login
To read more you must become a member of SearchEnterpriseDesktop.com
');
// -->

the other valuable tools in the IIS Resource Kit as well.
So there you have it -- IIS security tools for the budget-conscious admin. You may not be able to find and fix every single security issue in your IIS environment with these tools, but they are all excellent options if your resources are limited. Whether you want to lock down your Web systems or just tinker with some neat security tools, have at it. What have you got to lose?
About the author: Kevin Beaver is an independent information security consultant, keynote speaker, and expert witness with Atlanta-based Principle Logic, LLC where he specializes in providing independent security assessments revolving around risk management and compliance. Kevin has authored/co-authored seven books on information security including Hacking For Dummies and Hacking Wireless Networks For Dummies (Wiley). He's also the creator of the Security On Wheels information security audio books and blog providing security learning for IT professionals on the go. Kevin can be reached at kbeaver [at] principlelogic.com.