Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!
all groups > iis security > february 2007 >

iis security : Allow http, but deny ftp


Thomas Kofler
2/13/2007 7:31:01 AM
Hello,

we have the following scenario:

IIS 6.0 on Windows 2003

Web-Directory and ftp-Directory use the same physical ntfs folder.

For one user (Active Directory) we have a a secure web appliation (SSL) to
upload/download documents (the NTFS permission for the AD user must be set
probably on this directory).

The problem: The same user could use ftp to download the file unsecure.

Ken Schaefer
2/15/2007 12:41:07 AM
Hi,

Make the folder a virtual directory that is not located under the physical
web root. Do not add it as a virtual directory under your FTP server.

Cheers
Ken


[quoted text, click to view]
AddThis Social Bookmark Button