This document provides tips for hacking IIS web servers. It discusses resolving HTTPAPI 2.0 404 errors by adding the correct host header. It also covers techniques like virtual host hopping, local file disclosure through DLLs, ASP.NET viewstate deserialization for remote code execution, analyzing source code using DNSpy, exploiting XXE vulnerabilities even without outbound HTTP, and fuzzing short file names found through enumeration. Resources like tools, blogs, and YouTube channels focused on IIS hacking are also referenced.