Re: Setting IPGrant on a folder from a WebMethod

From: IPGrunt (me_at_privacy.net)
Date: 02/21/05


Date: 21 Feb 2005 20:00:59 GMT

On 21 Feb 2005, David Salonius <dsalonius@charter.net> postulated in
news:OnizSDEGFHA.560@TK2MSFTNGP15.phx.gbl:

>
> My web service is running under NT AUTHORITY\NETWORK SERVICE. I've
then
> given full control under folder security to that user. Under
Advanced
> Security Settings, I've verified that NETWORK SERVICE has full
control
> to all permissions. The error still persists. Is this what you're
> referring to?
>
> Thanks,
>
> David
>
> *** Sent via Developersdex http://www.developersdex.com ***
> Don't just participate in USENET...get rewarded for it!

Use IIS to manage this for you, buy assigning a new application pool
for this site that impersonates administrator (using LocalSystem as
Identity). (I use one called AdmininstrationPool that I keep reserved
for roles where I need this level access).

Remember, This IS a security hole, so be careful who has access.

-- ipgrunt



Relevant Pages

  • [NEWS] HelixPlayer Based Players Format String
    ... Get your security news from a reliable source. ... media player for Linux, Solaris (versions for other operating systems are ... between 0x0822** - 0x082f** and with control of one pointer at a time ... $ An open security advisory #13 - RealPlayer and Helix Player Remote ...
    (Securiteam)
  • Re: why microsoft choose mfc rather than wtl?
    ... to lower security settings, etc. ... For a client to get ... the particular AX control is never accessed, shown, or downloaded. ... unethical to deliver an automobile to customers because it is possible ...
    (microsoft.public.vc.mfc)
  • Re: Linux security
    ... that is in Windows NT-based systems out of the box. ... Why do you want that fine level of control? ... level of control over security?" ... a file system is a different beast altogether. ...
    (Ubuntu)
  • Re: Homeland security suggests Real ID (and now it gets worse!)
    ... Torture Bracelet To Control Dissenting Americans? ... Homeland Security, weapons company express desire to use "Security Bracelet" in law enforcement, crowd control ... Why the terrorists wouldn't just remove the bracelet as soon as they boarded the plane isn't explained, but the perceived fallibility of the device isn't the issue - the heart of the matter is the fact that the Department of Homeland Security has publicly expressed an interest and is seeking funding to utilize the device against the "criminal element". ...
    (alt.support.chronic-pain)
  • RE: [Full-disclosure] RE: [ISN] How To Save The Internet
    ... The point might be better made here that we have many security models ... a box owner may assign so that their access permissions are granted ... the current legal morass over intellectual property is of social value ... Nor is there much up-front discussion for consumers of what they can control, ...
    (Full-Disclosure)