? File level secutiry without setting ACL

From: David Rich (david.rich@cibasc.com)
Date: 05/20/02


From: "David Rich" <david.rich@cibasc.com>
Date: Mon, 20 May 2002 11:24:03 -0700


I have a lot of files like Word, Excel and PDF files on my
web site. I also have a database that has the user Domain
and user ID and what Files they can see.

>From that a ASP web page is building a page and only shows
that users the specific files they are suppose to see.

Currently I have to add the user id to the file's ACL to
restrict access to the file.

How can I handle this security without having to set the
ACL for each individual file.

I looked at ISAPI filters but I am not efficient enough in
C to write one. Is there another way to handle access
security to files on IIS?

I also tried to use the on session in the global.asa page
and have it timeout but it looked liked it would only run
if you hit a asp page.

If anyone knows how to handle this ACL issue please let me
know?

  



Relevant Pages

  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)
  • [NT] Microsoft JScript Remote Code Execution (MS06-023)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... There is a remote code execution vulnerability in JScript. ... Configure Internet Explorer to prompt before running Active Scripting ...
    (Securiteam)
  • [NT] Cumulative Security Update for Internet Explorer (MS05-052)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... A remote code execution vulnerability exists in the way Internet Explorer ...
    (Securiteam)
  • [NT] Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (MS07-042)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Vulnerability in Microsoft XML Core Services Could Allow Remote Code ... mode sets the security level for the Internet zone to High. ...
    (Securiteam)
  • [NT] Microsoft Data Access Components (MDAC) Function Code Execution (MS06-014)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Microsoft Data Access Components Function Code Execution ... for the Internet security zone to prompt before running ActiveX controls. ...
    (Securiteam)

Quantcast