all groups > iis security > january 2007 >
You're in the

iis security

group:

IUSR_ and IWAM_ with admin privileges


IUSR_ and IWAM_ with admin privileges Nicee
1/26/2007 9:12:00 AM
iis security:
An application has been purchased that requires the IUSR_ and IWAM_ accounts
be placed in the local administrators group in order for the application to
work.

Re: IUSR_ and IWAM_ with admin privileges Ken Schaefer
1/28/2007 7:32:29 PM
It means that if someone can get your web application to something
unintended (e.g. there is a bug in the application), then the attacker can
take control of your entire server.

Alternatively, if an attacker can get your IWAM or IUSR users to run some
code (e.g. by uploading a webpage, and then requesting it) then they have
full control over your server as well.

Cheers
Ken

[quoted text, click to view]
Re: IUSR_ and IWAM_ with admin privileges Roger Abell [MVP]
1/28/2007 8:00:17 PM

[quoted text, click to view]

Absurd. The risks are total for that machine, or
worse if installed on a DC (ex. SBS server).

I hope they did not ask for money in exchange !!

AddThis Social Bookmark Button