#1: Need to add local machine host name into binding as well
#2: Disable loopback for IIS
References:
http://support2.microsoft.com/default.aspx?scid=kb;en-us;896861
http://stackoverflow.com/questions/5180851/iis-binding-with-windows-authentication
About loopback for Reflection attack
http://en.wikipedia.org/wiki/Reflection_attack
No comments:
Post a Comment