RE: Outlook Web Access view include files vulnerability

From: danmiller@carolina.rr.com
Date: 02/20/02


To: vuln-dev@securityfocus.com
From: danmiller@carolina.rr.com
Date: Wed, 20 Feb 2002 17:27:02 GMT

Do not let web users access asp include files. They should
only be accessed by the user running the asp scripts
(usually IWAM_MACHINENAME). I used to associate .inc files
with the asp dll so that the source wouldn't be returned to
the user (if you have patched all the MS view source bugs),
but I don't know if you can pass parameters to them or if
there would be any other ill
effects.



Relevant Pages

  • Execute Permissions being reset to "none".
    ... On a random basis, sometimes in 30 minutes, sometimes every ... I reset it to "scripts and execs" and eventually, ... Once it get's reset to "none", the ASP scripts stop working, of course. ...
    (microsoft.public.inetserver.iis)
  • Execute Permissions being reset to "none"
    ... Management System and has some ASP content for database lookup and such. ... the execute permissions get reset to "none" from "scripts and executables". ... get's reset to "none", the CMS and ASP scripts stop working, of course. ...
    (microsoft.public.win2000.general)
  • How to set up access to IIS server for class students ?
    ... we are planning to set up a class on ASP w/VBScript. ... The problem is that while we can setup a dedicated machine with ... IIS server running, it may not be possible to run IIS on every ... ASP scripts (the scripts should be able to access databases on ...
    (microsoft.public.inetserver.iis.security)
  • Re: URL Scan - allowing asp scripts
    ... You also have to redirect the .asp extension from 404.dll back to asp.dll. ... Network Systems Security, LLC ... URL Scan - allowing asp scripts ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
    (Security-Basics)
  • IIS & databse
    ... When we write asp scripts without database ... make a database connection, the IIS server does not serve any more ... t get any errors at all neither HTTP errors nor asp errors. ... Its as if the server has just went in to sleep ...
    (microsoft.public.inetserver.iis)