Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
The Code Red/Nimba worm was an attack that exploited a security vulnerability in IIS 5. What made it devastating was that every Windows 2000 computer automatically enabled IIS 5 as part of the normal installation. Microsoft learned an important lesson from this and now enables only the exact and specific services that are required for the server’s role in Windows Server 2008.
One of the reasons that the MS Blaster worm was so devastating was that even on a Windows XP computer with the firewall enabled, the computer could become infected in the time between booting up and the automatic enabling of the Windows Firewall stack. In Windows Server 2008, external network connections are disabled until after the firewall is up and running.