Re: IWAM: Writing temp files to \winnt\temp

From: Tyler Durden (fadingreality414_at_yahoo.com)
Date: 08/04/04

  • Next message: Pete Herzog: "Re: nessus exceptions"
    Date: Tue, 3 Aug 2004 22:03:36 -0700 (PDT)
    To: joeyp@voteprivacy.com
    
    

    Theres one crazy idea I have about that. Now remember,
    this is a long shot. Since some program somewhere has
    to delete whats in temp, if the account with write
    permission to the directory crafted a filename (or
    just file possibly) so long that it was just
    disgusting, it might be able to cause the program to
    hang. That could be a DOS in itself. Besides that, it
    could fill up disk space. Lets say the site allows
    users to register. Their information has to be stored
    SOMEWHERE. Now if theres no more disk space, how might
    the registration information be saved?

    This was all abstract, and just a what-if.

    --Oedipus

    --- Joey Peloquin <joeyp@voteprivacy.com> wrote:

    > Greetings,
    > I'm a security analyst with a large retail company.
    >
    > Our web application developers are writing a web
    > service, which is called by
    > COM. It is written in dotnet, and they are
    > impersonating IWAM.
    >
    > Since IWAM is making the call, temporary files are
    > written to \winnt\temp,
    > the value of the system %temp% and %tmp% variables.
    > I've complained that I
    > don't like the idea of granting write to an
    > anonymous account on
    > \winnt\temp, but have been unable to locate any
    > specific information on the
    > risk of doing so.
    >
    > Since the ASPNET account already has write to the
    > directory (this is
    > apparently done when the framework is installed?),
    > and I cannot find any
    > instances of other security practitioners having a
    > problem with it, I am
    > losing this fight. To compound matters, all of the
    > references I've found to
    > \winnt\temp and serialization have lead to posts
    > decreeing the resolution of
    > permission woes by granting 'write' on \winnt\temp
    > for IWAM.
    >
    > From a pen-test perspective, what is the actual
    > level of risk is associated
    > with the developer's request? Do you know of any
    > papers or other
    > information that accurately discusses the risk, if
    > any, of allowing IWAM to
    > write to \winnt\temp?
    >
    > Changing the value of the system %temp% and %tmp%
    > variables is not possible.
    >
    > Thanks for any insight.
    >
    > Joey
    >
    >
    >
    >

                    
    __________________________________
    Do you Yahoo!?
    Yahoo! Mail Address AutoComplete - You start. We finish.
    http://promotions.yahoo.com/new_mail


  • Next message: Pete Herzog: "Re: nessus exceptions"

    Relevant Pages

    • Re: IWAM Out of sync
      ... IWAM password, shouldn´t we run the SYNCIWAM.Vbs script from Adminscripts ... I think I did this the last time: Change Password on account, ... > on my computer or IIS web server, or the account keeps getting locked out. ...
      (microsoft.public.inetserver.iis.security)
    • Re: over writing default IWAM_<machinename> in ii4.0
      ... I'm not sure what you mean by "overwrite the IWAM account." ... If this is a SQL server database with a SQL security account setup within ... > to interative user using steps: ...
      (microsoft.public.inetserver.iis.security)
    • Re: IUSR_<machine_name> Default Group Membership
      ... Stop IIS ... Set the default IIS/IWAM anonymous account password. ... replace the x's with the IWAM user name! ... Microsoft Exchange 2000 between October 1 and November 16. ...
      (NT-Bugtraq)
    • Re: Event Viewer entry
      ... Fascinating - I had spotted the IWAM post and deleted the account, ... Activation Permissions, clicked Edit Default, removed the IWAM account ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: IWAM user
      ... So basically if I put my IUSR_x and IWAM_ x Accounts in the administrators ... database from my ASP/VBScript page right? ... impersonate the browser logged in account). ...
      (microsoft.public.windowsxp.security_admin)

    Loading