RE: Com+ permissions

security.feeds_at_deepzone.org
Date: 02/24/05

  • Next message: Gustavo Mateus: "Re: Com+ permissions"
    To: <focus-ms@securityfocus.com>
    Date: Thu, 24 Feb 2005 09:34:30 +0100
    
    

    I would suggest to use some kind of automated installation/update procedure
    using a 'sudo'-like process. It is not perfect nor trouble-free, but better
    than giving out Admin credentials. As such there are several 'quick'
    options:

      1. task scheduler + script/s + file-based semaphores that trigger the
    action
      2. suexec cgi over a proceted web page.
      3. cygwin sudo package (not tested) over a rconsole/ssh session.
      ...

    In any case, you will have to pay attention to properly secure/harden the
    environemt you deploy. A 'Threat Model' analysis for each scenario would
    help on it.

    Hope this helps.

              
    Carlos Veira Lorenzo
    -------------------------------------------
    www.deepzone.org - cveira [at] deepzone.org
    www.dotpi.com - cveira [at] dotpi.com
    -------------------------------------------

    -----Original Message-----
    From: Gustavo Mateus [mailto:gustavo@gustavo.eti.br]
    Sent: miércoles, 23 de febrero de 2005 21:53
    To: focus-ms@securityfocus.com
    Subject: Com+ permissions

    I have a big problem when I have to give access on windows servers for user
    who need to publish com+ dll because they all need to be in "Administrators"
    group.

    Has anyone found any solution for that?
    Is there someway to publish com+ dll without been the server administrator?

    Thanks

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Gustavo Mateus: "Re: Com+ permissions"

    Relevant Pages

    • RE: Com+ permissions
      ... Subject: Com+ permissions ... I have a big problem when I have to give access on windows servers for ... Is there someway to publish com+ dll without been the server administrator? ...
      (Focus-Microsoft)
    • Com+ permissions
      ... I have a big problem when I have to give access on windows servers for ... Is there someway to publish com+ dll without been the server administrator? ...
      (Focus-Microsoft)
    • RE: Com+ permissions
      ... >I have a big problem when I have to give access on windows servers for ... >Is there someway to publish com+ dll without been the server ... this sort of job and deny them all other file system and other privs ... Delivered using the Free Personal Edition of Mailtraq ...
      (Focus-Microsoft)