Securing IIS/5 with ASP

From: Ralph Los (RLos@enteredge.com)
Date: 01/24/03

  • Next message: Laura A. Robinson: "RE: AD replication over WAN"
    From: "Ralph Los" <RLos@enteredge.com>
    To: "'focus-ms@securityfocus.com'" <focus-ms@securityfocus.com>
    Date: Fri, 24 Jan 2003 12:55:54 -0500
    
    

    Hello,
            I have a document I've built over the years about securing IIS/5,
    with regards to permissions, etc right down to the file level. This often
    works, except when I get that pesky ASP engine involved. I'm sick of
    HTTP/500 errors! I know for a fact the error is with file permissions, but
    I can't pin-point which file(s) are causing it. I've had the dllhost.exe
    keep getting "ACCESS DENIED" (Using NTFileMon from sysinternals.com) on
    C:\winnt\system32\<some_file> but...the permissions on that
    file/folder/whatever are IUSR/IWAM/SYSTEM (RWX).

            Bottom line, does anyone have a definitive "baseline IIS/5 w/ASP"
    security document done I could look over? Just curious - dying to know what
    I'm missing.

    ?Ralph



    Relevant Pages

    • RE: Securing IIS/5 with ASP
      ... Is the account active? ... with regards to permissions, etc right down to the file level. ... except when I get that pesky ASP engine involved. ...
      (Focus-Microsoft)
    • RE: Any way to remove ADMIN$ only?
      ... permissions, most restrictive permissions apply. ... you must use file level permissions. ... and NTFS permission the heck out of things. ... Any way to remove ADMIN$ only? ...
      (Focus-Microsoft)
    • RE: Need to share "Program Files" folder
      ... also check the permissions on directory / file level. ... Bernhard Wolf ... and it says that this is a system folder so it can not be shared. ...
      (microsoft.public.windowsxp.embedded)
    • Re: Change Share and File Permissions (Take Ownership) when necessary. (env. NT4)
      ... > mess) so the only thing i want is to reset the permissions to be the above ... > (as i will maintain security on the file level only instead). ... Local or remote directories ...
      (microsoft.public.scripting.wsh)
    • RE: Share permissions question
      ... getting off easy with only about fifty groups and fifty or so shares - so far. ... Welcome to the wunderful world of permissions. ... >> the Shares for all the sub-folders of the main folder. ... >>> absolute, at the file level, and will be enforced either way. ...
      (microsoft.public.windows.server.general)