RE: IUSR_computername, IWAM_computername rights
From: Jean-Pierre Harvey (jean-pierre.harvey@edivision.com.au)Date: 07/25/01
- Previous message: Windex King: "Re: Trace of 139 attack?"
- Maybe in reply to: Art Norman: "IUSR_computername, IWAM_computername rights"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Message-ID: <81200F7AD624D4118A9000508B8BBD2C487CBC@edivex001.edivision.com.au> From: Jean-Pierre Harvey <jean-pierre.harvey@edivision.com.au> To: 'Art Norman' <art_norman@altavista.com>, focus-ms@securityfocus.com Subject: RE: IUSR_computername, IWAM_computername rights Date: Wed, 25 Jul 2001 11:27:38 +1000
The easiest way to find out which files the IUSR_computername account needs
is to turn on full filesystem auditing for that user, and look in the
security log. It will be different depending on how many features of IIS you
are using.
From memory the account only needs read access to the web directories and a
couple of dlls in the \system32\inetsrv directory if you are only doing .asp
serving.
JP
-----Original Message-----
From: Art Norman [mailto:art_norman@altavista.com]
Sent: Tuesday, July 24, 2001 6:47 AM
To: focus-ms@securityfocus.com
Subject: IUSR_computername, IWAM_computername rights
Hi,
I'm fighting bastion host with IIS 5.
What exactly NTFS rights should have IUSR_computername, IWAM_computername?
What rights should be asigned to COM+ Web application user (Administrative
Tools>Component Services>My Computer>Com+ Applications>My
Application>Properties>Identity) on IIS 5 server?
I've started by disabling users rights to Winnt directory. Only System and
Administrator are left.
Then I've started to asign rights to IUSR_computername, IWAM_computername
according to Microsoft and other recommendations. Microsoft has quite brief
paper about that. Are there around any papers regarding these users
permisions? I could add permissions to winnt, system32, Program Files for
IUSR_computername, IWAM_computername, my user. Then I should allow these
users to logon from network ......
But the question is how to know exactly what rights for every user should be
asigned? How to keep these users at minimum level of permisions?
Art
Find the best deals on the web at AltaVista Shopping!
http://www.shopping.altavista.com
- Previous message: Windex King: "Re: Trace of 139 attack?"
- Maybe in reply to: Art Norman: "IUSR_computername, IWAM_computername rights"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|