Fw: Bypass Traverse Checking?

From: Shane Brooks (shane@floridacomputerservices.com)
Date: 01/24/03

  • Next message: Laura A. Robinson: "RE: Bypass Traverse Checking?"
    From: "Shane Brooks" <shane@floridacomputerservices.com>
    To: <focus-ms@securityfocus.com>
    Date: Fri, 24 Jan 2003 08:22:03 -0500
    
    

    Everyone includes everyone, from guest to Administrator. The point was that
    Authenticated Users don't include Guest and Everyone does. So you should
    replace Everyone with Authenticated Users. AFAIK, there is no 'Anonymous'
    account, but anonymous access authenticated as IUSR.

    Shane
    > ----- Original Message -----
    > From: "Laura A. Robinson" <larobins@bellatlantic.net>
    > To: "'Shane Brooks'" <shane@floridacomputerservices.com>; "'Williamson,
    > Scott'" <scott.williamson@htcinc.net>; <focus-ms@securityfocus.com>
    > Sent: Friday, January 24, 2003 2:35 AM
    > Subject: RE: Bypass Traverse Checking?
    >
    >
    > Everyone also affects Anonymous- In Windows 2000 and earlier, Everyone
    > includes the Anonymous account. In Windows Server 2003, there is a
    > separation of the Anonymous account from the Everyone group. Where there
    > would be an effect from this is in establishment of null connections to
    > servers- null connection settings relate to what can be done with
    > "unidentified" connections.
    >
    > As a side note, RestrictAnonymous=2 is no longer supported in Windows
    Server
    > 2003.
    >
    > Laura
    >
    > > -----Original Message-----
    > > From: Shane Brooks [mailto:shane@floridacomputerservices.com]
    > > Sent: Monday, January 20, 2003 7:11 PM
    > > To: Williamson, Scott; focus-ms@securityfocus.com
    > > Subject: Re: Bypass Traverse Checking?
    > >
    > >
    > > You should definately make this change. If anything, the
    > > other admin is confusing Anonymous access of web-pages by the
    > > IUSR_[computername] account. However, IIS manages the
    > > password of this account automatically and the account is
    > > therefore a member of "Authenticated Users", since IIS
    > > authenticates every page as IUSR automatically if Anonymous
    > > access is enabled. The only account that is affected by
    > > Everyone is the guest account which is disabled by default.
    > > Hope this helps, Shane
    > > ----- Original Message -----
    > > From: "Williamson, Scott" <scott.williamson@htcinc.net>
    > > To: <focus-ms@securityfocus.com>
    > > Sent: Wednesday, January 15, 2003 1:10 PM
    > > Subject: Bypass Traverse Checking?
    > >
    > >
    > > > I'm working on procedures for servers in our organization. I keep
    > > > coming across the recommendation to set the following on a Windows
    > > > 2000 Server.
    > > My
    > > > problem is I have another administrator who believes this
    > > could cause
    > > > problems in IIS. What are the lists opinions? Anyone heard of this
    > > causing
    > > > problems?
    > > >
    > > > User Rights Assignment - Set "Bypass Traverse Checking" - Remove
    > > > Everyone and Replace with Authenticated Users.
    > > >
    > > > Thanks in advance for your time,
    > > >
    > > > Michael Scott Williamson
    > > > Systems Administrator
    > >
    >
    >



    Relevant Pages

    • RE: Bypass Traverse Checking?
      ... Authenticated Users, because they are significantly different (different ... account without that SID in its token would not be able to access the ... you are affecting Anonymous Logon and the _builtin_ Guest ... account. ...
      (Focus-Microsoft)
    • RE: Bypass Traverse Checking?
      ... This article discusses the inclusion of Authenticated Users in the access ... token for an account that connects as a guest; ... won't have that token in the guest context is the built-in Guest account ... > looking at the SID of the account. ...
      (Focus-Microsoft)
    • Re: Grayed out password box.
      ... >Laptop I get a grayed out Guest sign in box and the guest password does not ... Are your computers running XP Home, XP Pro, or a combination? ... common non-Guest account on all computers. ... Any user can be an Administrator, ...
      (microsoft.public.windowsxp.network_web)
    • Re: Help with Guest account
      ... Account and created a new User Account. ... Same thing in the Guest ... problem accessing the internet with it as it uses that same network ... enable the Guest Account is "an" administrator account. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Autoplay doesnt work for Guest account
      ... > Administrator is handy. ... > Administrator account. ... AutoPlay tab exists in the CD properties. ... > Guest account does not work and there is no AutoPlay tab ...
      (microsoft.public.windowsxp.general)