RE: Priviledge escalation attack

From: Laura A. Robinson (larobins@bellatlantic.net)
Date: 10/31/02


From: "Laura A. Robinson" <larobins@bellatlantic.net>
To: "'Henry Sieff'" <hsieff@orthodon.com>, "'Eric Howard'" <dlydl7502@sneakemail.com>, <focus-ms@securityfocus.com>
Date: Thu, 31 Oct 2002 14:37:47 -0500


You are correct in everything you say, though: the default permissions
are completely insufficient to lock down a server which will have
interactive logins (like a terminal server). They are even to loose for
a web server.

--
Henry Sieff

I disagree a bit- he's only correct in saying that the default permissions are weak. His scenario for an exploit was not correct.

Additionally, .Net is bringing significant changes as far as default security settings, but that's another topic. ;-)

Laura



Relevant Pages

  • Re: write with cURL
    ... execute permissions. ... This is assuming that the PHP script runs ... of potential security risks from other users on the same server. ... web server itself is part of the group. ...
    (alt.php)
  • Re: web service architecture question
    ... To assume that we have all the security we will ever need is a bad one. ... ways to breach a server, and the separatin of the web and app server is one ... You can use remoting or web services. ... The web server will be exposed outside the ...
    (microsoft.public.dotnet.framework.webservices)
  • RE: System.Data.SqlClient "Timeout expired" causing ASP.net web applic
    ... There are many values here that can shutdown the aspnet_wp. ... > update tables on a Web Server running SQL Server 2000. ... > formation(DataSet currentBalances): Timeout expired. ...
    (microsoft.public.dotnet.languages.vb)
  • RE: System.Data.SqlClient "Timeout expired" causing ASP.net web applic
    ... There are many values here that can shutdown the aspnet_wp. ... > update tables on a Web Server running SQL Server 2000. ... > formation(DataSet currentBalances): Timeout expired. ...
    (microsoft.public.dotnet.framework.aspnet)
  • RE: System.Data.SqlClient "Timeout expired" causing ASP.net web applic
    ... There are many values here that can shutdown the aspnet_wp. ... > update tables on a Web Server running SQL Server 2000. ... > formation(DataSet currentBalances): Timeout expired. ...
    (microsoft.public.dotnet.framework.adonet)