what you need to know about running IIS and get useful of it .... you'll find it here ...

1- IIS allows universal CrossSiteScripting
2- Remote control of IIS
3- Microsoft IIS local and remote DoS
4- All versions of Microsoft IIS Remote buffer overflow (SYSTEM Level Access)
5- Unchecked Buffer in ISAPI Extension Could Enable Compromise of IIS 5.0 Server

http://www.astalavista.com/library/auditing/webserver/