RE: Bypass Traverse Checking?

From: Scott (scottcm@usa.net)
Date: 01/21/03

  • Next message: Tony Mason: "RE: Bypass Traverse Checking?"
    From: "Scott" <scottcm@usa.net>
    To: <focus-ms@securityfocus.com>
    Date: Tue, 21 Jan 2003 08:24:33 -0600
    
    

    We've made the change you're looking into without problems. I don't see how
    it could cause a problem with IIS, either. Even if the user were anonymous
    they're still logged into the system with an account. The 3 authentication
    methods I've seen it work successfully is Forms, Anonymous, and Integrated.
    I assume it will also work with Basic and Passport.

    Scott

    -----------------------------------------------
    From: Williamson, Scott
    To: focus-ms@securityfocus.com
    Sent: 1/15/03 12:10 PM
    Subject: Bypass Traverse Checking?

    I'm working on procedures for servers in our organization. I keep
    coming
    across the recommendation to set the following on a Windows 2000 Server.
    My
    problem is I have another administrator who believes this could cause
    problems in IIS. What are the lists opinions? Anyone heard of this
    causing
    problems?

    User Rights Assignment - Set "Bypass Traverse Checking" - Remove
    Everyone
    and Replace with Authenticated Users.

    Thanks in advance for your time,

    Michael Scott Williamson
    Systems Administrator



    Relevant Pages

    • Re: Microsoft Security Advisory MS 03-007
      ... > You say "IIS servers are actively being compromised already, ... -- permissions are checked on httpext.dll to see if Anonymous request using ... CONFIGURATIONS OF THE IIS LOCKDOWN TOOL DO LEAVE WEBDAV ...
      (Focus-Microsoft)
    • RE: Microsoft Security Advisory MS 03-007
      ... announcement covers IIS 5.1 but not IIS 6, ... > You say "IIS servers are actively being compromised already, ... -- permissions are checked on httpext.dll to see if Anonymous request ... CONFIGURATIONS OF THE IIS LOCKDOWN TOOL DO LEAVE WEBDAV ...
      (Bugtraq)
    • Re: Microsoft Security Advisory MS 03-007
      ... announcement covers IIS 5.1 but not IIS 6, ... > You say "IIS servers are actively being compromised already, ... -- permissions are checked on httpext.dll to see if Anonymous request ... CONFIGURATIONS OF THE IIS LOCKDOWN TOOL DO LEAVE WEBDAV ...
      (Bugtraq)
    • RE: Microsoft Security Advisory MS 03-007
      ... announcement covers IIS 5.1 but not IIS 6, ... > You say "IIS servers are actively being compromised already, ... through, and if it carried the exploit, compromise could occur. ... CONFIGURATIONS OF THE IIS LOCKDOWN TOOL DO LEAVE WEBDAV ...
      (Focus-Microsoft)
    • Re: Howto refresh IIS 6 Application pool identity credential info
      ... The Application Servers are load balanced clustered, ... HostHeader names in IIS, it has a CNAME in DNS referencing ... Only account A has access to database DB-A ...
      (microsoft.public.inetserver.iis.security)