Re: Setting IPGrant on a folder from a WebMethod

From: Joe Kaplan \(MVP - ADSI\) (joseph.e.kaplan_at_removethis.accenture.com)
Date: 02/21/05

  • Next message: WJ: "Re: Forms-Based Authentiction and NON ASP.NET Assets"
    Date: Mon, 21 Feb 2005 14:49:37 -0600
    
    

    I'd make sure you don't use that app pool for any other websites or
    applications on the same server. Always use a different app pool with lower
    privileges for other sites. That will help restrict it as well.

    Other than that, it is up to you to consider whether you need to go to COM+
    or not for additional security. As long as you don't have any other entry
    points into this site and you are comfortable with the security you are
    providing, then I think it can be secure. Just be careful and spend some
    time doing some threat modeling to make sure you don't miss anything.

    Joe K.

    "David Salonius" <dsalonius@charter.net> wrote in message
    news:%23MKOlGFGFHA.228@TK2MSFTNGP15.phx.gbl...
    >
    >
    > Setting the user in the Application Pool identity to an administrator
    > account solved the problem. From what I can tell, as long as my web
    > methods folder is locked down to where no one can upload code, this
    > should be safe. Is that a fair assessment?
    >
    > Thanks,
    >
    > David
    >
    > *** Sent via Developersdex http://www.developersdex.com ***
    > Don't just participate in USENET...get rewarded for it!


  • Next message: WJ: "Re: Forms-Based Authentiction and NON ASP.NET Assets"

    Relevant Pages

    • Re: .NET 2.0 Master Pages problem
      ... IIS can only run one version of ASP.NET at a time in each app pool. ... applications will start throwing exceptions. ... When I run it on the server, it looks like crap - no master page ...
      (microsoft.public.dotnet.framework.aspnet)
    • AppPool + secureConversation
      ... The web service works in the default app pool, and in a new app pool with the default identity. ... It failed when the new app poll was given a different identity (I have added identity to local group IIS_WPG and configured security on the certificate's private key). ... However WSE3 is supposed to allow secureConversation to work with web farms so why am I getting this error? ...
      (microsoft.public.dotnet.framework.webservices.enhancements)
    • RE: Thoughts on the book: DEC is dead, long live DEC
      ... site and tried to option out a Win2k3 server. ... to certain applications or functions. ... There have been patches ... Remember that 60% of most security issues are from internal sources. ...
      (comp.os.vms)
    • Re: Application Pols
      ... The reason for having sharepoint in a workgroup first is because we need to ... databases to this new server. ... > installation and choose them instead. ... each site can run in its own app pool. ...
      (microsoft.public.sharepoint.windowsservices)
    • Single Point Software Security in C/S environment?
      ... I am looking for something that will allow me to put security, # logged users, ... I don't want to worry about registering/controlling the applications ... applications interrogate the server for security rights. ...
      (borland.public.delphi.thirdpartytools.general)