Groups | Blog | Home
all groups > iis security > december 2004 >

iis security : IIS lockdown - odd log entrys


gavin NO[at]SPAM my-deja.com
12/4/2004 9:36:22 AM
hi all,

Just installed IIS on my XP pro box and decided to run the IIS
lockdown tool, all seemed to go fine but I got the following in the
report at the end:
..
..
..
Warning: Unable to secure content
(C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe): Access is denied.
Warning: Unable to secure content
(C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe): Access is denied.
Warning: Unable to secure content
(C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe): Access is denied.
..
..
..

why was it even trying to access these files!?

Also, I ran windows update after installing IIS and it found no
updates! I found that odd - I do have service pack 2 however, could
that be why I needed no updates for IIS (even tho I did not have it
installed when I installed SP2!)? IISlockdown reports I am all
uptodate with patches for IIS - should I trust it?

cheers guys!

Bernard
12/6/2004 12:59:30 PM
Not sure why you get access is denied, but I believe iislockdown is trying
to configure the ntfs permission so that anonymous access do not have write
access to those paths.

iislockdown do not tell you what patch is missing, you can do this via
windows update or get MBSA from microsoft.com


--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]

gavin NO[at]SPAM my-deja.com
12/7/2004 3:49:04 AM
cheers for the info - sounds like its not too big a deal - any opinions
as to whether I should worry?
I checked the directory security and there is no anonymous access but
when I try to check the actual files mentioned I dont get the security
tab - just lots of options for how it should be run in DOS mode! Other
files in the directories do show the security tab... why would this be?


I have indeed run MBSA and it seems to say all is well in terms of
patches.

gav


[quoted text, click to view]
Ken Schaefer
12/7/2004 12:12:03 PM
Hi,

IISLockdown is probably trying to secure NTFS permissions for those file to
prevent an anonymous user from executing them. However, those files are
already located in protected directories.

There are no post-SP2 patches for IIS on Windows XP. When you installed IIS,
even if you had already installed SP2, it should request SP2 binaries if
required.

To verify, you can use Microsoft Baseline Security Analyser:
www.microsoft.com/technet/security/tools/mbsahome.mspx

Cheers
Ken


[quoted text, click to view]

gavin NO[at]SPAM my-deja.com
12/8/2004 2:29:05 AM
hi again,

Ok yep sorry the tab is there (Doh!) I just did not see it because
there was a whole host of other tabs there too which I dont normally
see. sorry!



[quoted text, click to view]
Bernard
12/8/2004 12:02:07 PM
huh ? it should have a 'security' tab.
anyway, I think you can safely ignore the errors.

--
Regards,
Bernard Cheah
http://www.tryiis.com/
http://support.microsoft.com/
http://www.msmvps.com/bernard/



[quoted text, click to view]

Ken Schaefer
12/8/2004 7:10:23 PM
Did you turn off "Use Simple File Sharing"?

(In Explorer -> Tools -> Folder Options -> View -> uncheck "use Simple File
Sharing (Recommended)") and then you should see a security tab.

Cheers
Ken

[quoted text, click to view]

AddThis Social Bookmark Button