all groups > iis security > november 2004 >
You're in the

iis security

group:

prevent asp.net and IUSR from accessing c:\



Re: prevent asp.net and IUSR from accessing c:\ Tom Kaminski [MVP]
11/24/2004 11:21:05 AM
iis security: [quoted text, click to view]

You certainly did not mention that here.

Re: prevent asp.net and IUSR from accessing c:\ Tom Kaminski [MVP]
11/24/2004 11:21:31 AM
[quoted text, click to view]

Is your IIS server also the domain controller?

prevent asp.net and IUSR from accessing c:\ Mike Schwarz
11/24/2004 2:17:45 PM
hi

i have installed a small script on a virtual web called explore.aspx
this is able to explore my whole c:\ directory, as the user asp.net
is a member of the group "Domain User / User" and this user
does has read permission on the whole drive c:\

how can i prevent this?
is it necessary that asp.net user is member of "Domain User/Users" ?

thankx for any tip/hint how to lock down my system

mike schwarz

Re: prevent asp.net and IUSR from accessing c:\ Leon Mayne [MVP]
11/24/2004 3:08:30 PM
[quoted text, click to view]

The ASPNET and IUSR_MACHINENAME accounts should only be members of the
Guests group. Try that.

Re: prevent asp.net and IUSR from accessing c:\ Mike Schwarz
11/24/2004 4:42:07 PM
i have deactivated guest group... as mentioned in several forums...


"Leon Mayne [MVP]" <l.rmv.mayne@uea.ac.uk> schrieb im Newsbeitrag
news:%23b3p2dj0EHA.3416@TK2MSFTNGP09.phx.gbl...
[quoted text, click to view]

Re: prevent asp.net and IUSR from accessing c:\ Mike Schwarz
11/25/2004 10:43:29 AM
yes, my webserver is setup as domain controller

"Tom Kaminski [MVP]" <tomk (A@T) mvps (D.O.T) org> schrieb im Newsbeitrag
news:ezQE1Gk0EHA.2316@TK2MSFTNGP15.phx.gbl...
[quoted text, click to view]

Re: prevent asp.net and IUSR from accessing c:\ jeff.nospam NO[at]SPAM zina.com
11/27/2004 4:02:59 AM
On Wed, 24 Nov 2004 14:17:45 +0100, "Mike Schwarz" <ctek@ctek.ch>
[quoted text, click to view]

Don't have the asp.net user in the domain users group *and* remove
domain users from the NTFS permissions for the root of C:\.

[quoted text, click to view]

No.

Are you running IIS on a DC? There are idiosyncracies to this since
the IIS accounts become domain accounts and have a different access
potential than if they are local accounts. Basically, remove all
access for accounts that don't need access.

AddThis Social Bookmark Button