RE: Securing IIS/5 with ASP

From: Holmes, Tyran (tholmes@ascendone.com)
Date: 01/24/03

  • Next message: Kelly Fuller: "RE: Win2k log management"
    Date: Fri, 24 Jan 2003 16:32:23 -0500
    From: "Holmes, Tyran" <tholmes@ascendone.com>
    To: "Ralph Los" <RLos@enteredge.com>, <focus-ms@securityfocus.com>
    

    Is the account (IUSR...) active? I know I remember getting some errors
    for the IUSR accts in the Event Log on an IIS server and found that my
    cohort had disabled the accounts. Just a thought...

    -----Original Message-----
    From: Ralph Los [mailto:RLos@enteredge.com]
    Sent: Friday, January 24, 2003 12:56 PM
    To: 'focus-ms@securityfocus.com'
    Subject: Securing IIS/5 with ASP
    Sensitivity: Confidential

    Hello,
            I have a document I've built over the years about securing
    IIS/5,
    with regards to permissions, etc right down to the file level. This
    often
    works, except when I get that pesky ASP engine involved. I'm sick of
    HTTP/500 errors! I know for a fact the error is with file permissions,
    but
    I can't pin-point which file(s) are causing it. I've had the
    dllhost.exe
    keep getting "ACCESS DENIED" (Using NTFileMon from sysinternals.com) on
    C:\winnt\system32\<some_file> but...the permissions on that
    file/folder/whatever are IUSR/IWAM/SYSTEM (RWX).

            Bottom line, does anyone have a definitive "baseline IIS/5
    w/ASP"
    security document done I could look over? Just curious - dying to know
    what
    I'm missing.

    ?Ralph



    Relevant Pages

    • Securing IIS/5 with ASP
      ... with regards to permissions, etc right down to the file level. ... except when I get that pesky ASP engine involved. ... I'm sick of ...
      (Focus-Microsoft)
    • Re: Incoming E-Mail - cant create contact in OU
      ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: Incoming E-Mail - cant create contact in OU
      ... account out of local administrator to attempt to find any denied ... I then added full permissions to my user account on both of these keys, ... that's for every app pool you create for every new web app on the ... local admin rights to the server hosting incoming email. ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: Win2k - Account Operator not working properly
      ... You very likely have other ACL issues other than what was mentioned and I can point them out here for you for free or you can pay someone $200-500 an hour to come check it out. ... In order for that to result in inheritence protection it means the schema had to be modified. ... set the account in the GUI to inherit from its parents. ... Used the delegation wizard, on the top level OU, to assign the desired permissions. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Incoming E-Mail - cant create contact in OU
      ... account out of local administrator to attempt to find any denied access. ... I then added full permissions to my user account on both of these keys, ... local admin rights to the server hosting incoming email. ... what permission I need to give the app pool locally to avoid this issue. ...
      (microsoft.public.sharepoint.windowsservices)