ASP.NET Process Identity???

From: Roberto López (rlopez_at_eurosistemas.net)
Date: 07/31/03


Date: Thu, 31 Jul 2003 13:30:31 +0200


Hi all,
I have an ASP.NET app that connects to SQL server to
store and retrieve data, and users may upload and download
files from the server using System.IO namespace's functions.

In my machine.config file i have writed "SYSTEM" as user for
ASP.NET (into the process model section). For security reasons
the directories where users upload and download files are protected
whit NTFS permssions that allows access only for Administrators.

I planned to use a function to impersonate an administrator user when
I upload and download files, buy I encountered that it is not neccesary
and I don´t know why.
If I have set that only Administrators can access to this directories in
NTFS permissions, and i have checked that the SYSTEM user of my
server is not a member of Administrators group. Is this a BUG into
NET security??.
I have checked that the user who is running ASP.NET process
is NT_AUTHORITY/SYSTEM
(using system.security.principal.windowsidentity.getcurrent().name
function).

If someone knows something about this please tell me.

Thanks a lot.

--
Roberto López
Dpto. Soporte Software
Eurosistemas Informáticos y Comunicaciones, S.L.
--
Roberto López
Dpto. Soporte Software
Eurosistemas Informáticos y Comunicaciones, S.L.


Relevant Pages

  • Re: edit asp site?
    ... I can download the ... change and upload if that will work but do not ... Definately use a text editor ... Set your system up as a web server, ...
    (alt.html)
  • Re: Edit document via web
    ... You would need some sort of third party software installed on the client to ... download the file, save it somewhere to make changes and then upload it back ... the software would have to know how to upload ... the document back to the server. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Problems uploading newsgroup posts to Tera News
    ... I'm having problems uploading any newsgroups posts to Tera News. ... used this to restore the ability to download since Windows Mail ... I have not been able to upload any posts there again. ... Server: 'free.teranews.com', Protocol: NNTP, Server Response: '403 Remote ...
    (microsoft.public.windows.vista.mail)
  • Re: Corrupted uploads
    ... Just click on the graphic to download it. ... UPLOAD implies the user sending something to the server. ... > Do you have SSL or Compression enabled? ...
    (microsoft.public.inetserver.iis)
  • Re: File Upload - Security Issues
    ... You want to upload a file for what reason and ... these viruses have less chance of being able to execute (even if succeeded ... :> file and what pitfalls you see re: security might be helpful on this ... :>: files to an IIS server that doesn't have MS Office actually installed? ...
    (microsoft.public.scripting.vbscript)