IIS4 - IUSR accout security

From: Jeff Tate (jtate@scientific-evidence.nonspam.com)
Date: 06/13/02


From: "Jeff Tate" <jtate@scientific-evidence.nonspam.com>
Date: Thu, 13 Jun 2002 10:17:59 -0700


Are there any good recommendations/best practices
regarding the IUSR and IWAM accounts for IIS4? Allowing
these accounts the "Logon locally" and network access
privledges doesn't sit totally well with me. If it must
be, the so be it. But, I'd like to know how best to secure
these accounts.

Some questions:
What groups MUST they be in?
Any settings that could be used to reduce the hazards
these two accounts seem to present?
Is renaming the accounts a good Idea?

Thanks
Jeff Tate



Relevant Pages

  • Re: "Identical" accounts on networked computers
    ... Computer Browser service was not starting from ... I>>deleted/removed the accounts back to a single user, ... > When people complain of problems with network access, that is one of the easiest> diagnoses. ... > You have posted here so many articles, it's hard to keep track of your problems. ...
    (microsoft.public.windowsxp.network_web)
  • Re: How to stop share to prompt for credentials
    ... Not a good solution but enable the guest account and assign share permissions to the guest account. ... The other possible solution is to make the workgroup name match the domain name and then create accounts with identical usernames and passwords on both the server and workstation. ... allowed ANONYMOUYS LOGON and Everyone full control ... --Disabled Network Access: Do not allow anonymous enumeration of SAM accounts ...
    (microsoft.public.win2000.general)
  • Re: xp pro permissions for file sharing with xp home
    ... > I have checked the network access and they are set to the following: ... Do not allow anonymous enumeration of SAM accounts - ... > network security: Force logoff when logon hours expire - Disabled ... Minimum session security for NTLM SSP based (including ...
    (microsoft.public.windowsxp.general)
  • How to stop share to prompt for credentials
    ... allowed ANONYMOUYS LOGON and Everyone full control ... -under the AD controllers of the domain where MYBOX sits, created an OU, ... --Disabled Network Access: Do not allow anonymous enumeration of SAM accounts ...
    (microsoft.public.win2000.general)
  • Re: xp pro permissions for file sharing with xp home
    ... I have checked the network access and they are set to the following: ... Do not allow anonymous enumeration of SAM accounts - Enabled ... network security: Force logoff when logon hours expire - Disabled ... > rechecking your share settings on the XP Pro machine, ...
    (microsoft.public.windowsxp.general)

Quantcast