RE: Bypass Traverse Checking?

From: Hall, Randy (randy.hall@intel.com)
Date: 01/24/03

  • Next message: Ralph Los: "Securing IIS/5 with ASP"
    Date: Fri, 24 Jan 2003 09:27:45 -0800
    From: "Hall, Randy" <randy.hall@intel.com>
    To: <focus-ms@securityfocus.com>
    
    

    I thought I would weigh in on this discussion, mostly because I see some
    dangerous assertions being made.

    A very good web article that clears the distinction between Everyone,
    Users, and Authenticated Users is at:

    http://www.windowswebsolutions.com/Articles/Index.cfm?ArticleID=23581

    I read it and agree with its findings.

    Cheers,

    --R

    --
    Randy Hall MCSA, MCSE (randy.hall@intel.com)
    Network/Web Manager, Corporate Demos
    Intel Corporation, Santa Clara, CA USA
    All views expressed herein are MINE MINE MINE!!!
    -----Original Message-----
    From: Laura A. Robinson [mailto:larobins@bellatlantic.net] 
    Sent: Friday, January 24, 2003 5:35 AM
    To: 'Shane Brooks'; 'Williamson, Scott'; focus-ms@securityfocus.com
    Subject: RE: Bypass Traverse Checking?
    As an additional item, since I've been challenged on this one via
    e-mail, I
    would encourage reading of this:
    http://www.microsoft.com/windows2000/techinfo/reskit/en-us/default.asp?u
    rl=/
    windows2000/techinfo/reskit/en-us/distrib/dsbc_nar_lmxa.asp
    or
    http://tinyurl.com/4ubt
    Particularly this:
    "Note
    For anonymous access to be available for Internet users, anonymous
    access
    must be enabled on the Internet Information Services (IIS) Web server."
    Again, note that Authenticated users does _not_ include anonymous.
    Laura
    > -----Original Message-----
    > From: Shane Brooks [mailto:shane@floridacomputerservices.com] 
    > Sent: Monday, January 20, 2003 7:11 PM
    > To: Williamson, Scott; focus-ms@securityfocus.com
    > Subject: Re: Bypass Traverse Checking?
    > 
    > 
    > You should definately make this change.  If anything, the 
    > other admin is confusing Anonymous access of web-pages by the 
    > IUSR_[computername] account. However, IIS manages the 
    > password of this account automatically and the account is 
    > therefore a member of "Authenticated Users", since IIS 
    > authenticates every page as IUSR automatically if Anonymous 
    > access is enabled.  The only account that is affected by 
    > Everyone is the guest account which is disabled by default. 
    > Hope this helps, Shane
    > ----- Original Message -----
    > From: "Williamson, Scott" <scott.williamson@htcinc.net>
    > To: <focus-ms@securityfocus.com>
    > Sent: Wednesday, January 15, 2003 1:10 PM
    > Subject: Bypass Traverse Checking?
    > 
    > 
    > > I'm working on procedures for servers in our organization.  I keep 
    > > coming across the recommendation to set the following on a Windows 
    > > 2000 Server.
    > My
    > > problem is I have another administrator who believes this 
    > could cause 
    > > problems in IIS.  What are the lists opinions?  Anyone heard of this
    > causing
    > > problems?
    > >
    > > User Rights Assignment - Set "Bypass Traverse Checking" - Remove 
    > > Everyone and Replace with Authenticated Users.
    > >
    > > Thanks in advance for your time,
    > >
    > > Michael Scott Williamson
    > > Systems Administrator
    > 
    


    Relevant Pages

    • Re: iis 6.0
      ... How IIS Authenticates Browser Clients ... >>An IIS account for anonymous access to IIS. ... >>will be the process identity, ...
      (microsoft.public.inetserver.iis.security)
    • Re: 401.1 Error w/ Anonymous Access
      ... > - I've set up a local account on the machine (Win2000 Professional, ... > - In the local machine's Local Security Policy I've allowed SiteUser to ... I am under the impression that if Anonymous Access is ... IIS will treat the request as if it is coming from the user ...
      (microsoft.public.inetserver.iis.security)
    • Re: HTTP/1.1 401 Access Denied - when trying to access a .jsp page
      ... local system account which has full priviledges. ... If your upgrade was to IIS ... The jsp page fails now because of some tightened security that happened ... Even though it is 'configured for anonymous access' ...
      (microsoft.public.inetserver.iis.security)
    • Re: Cant make a domain user the "anonymous access" user
      ... I do not think this is an IIS issue. ... IIS just uses the username/password you set and call LogonUser with it -- ... domain user account is used for anonymous access, ...
      (microsoft.public.inetserver.iis.security)
    • Re: IIS on 2003 Domain Controller
      ... >anonymous access to a 2003 server configured as a Domain Controller. ... Have you set IIS for anonymous access and not Windows Authenticated? ... >understand the account used for anonymous access cannot be on a remote ...
      (microsoft.public.inetserver.iis.security)