RE: POST method causes security bug?

From: Jason J. Joyce [MS] (jasonjoyonline@microsoft.com)
Date: 06/18/02


From: jasonjoyonline@microsoft.com ("Jason J. Joyce [MS]")
Date: Tue, 18 Jun 2002 16:06:54 GMT


This is likely just permissions (ACL) on NTFS objects. Check Q187506
(http://support.microsoft.com/default.aspx?scid=kb;EN-US;q187506). A good
way to check would be to look at the responses recorded in the IIS log, 401
is a client issues and usually permissions.

Thanks,
- Jason Joyce
- Microsoft

This posting is provided "AS IS" with no warranties, and confers no rights.
You assume all risk for your use. © 2001 Microsoft Corporation. All rights
reserved.



Relevant Pages

  • Re: norton anti-virus unable to scan file(s) due to NTFS acls/permissions
    ... It is true that these rights will skip ACL checking. ... Backup programs explicitly enable these rights. ... >>> fix that does *not* involve changing file permissions or ACLs. ...
    (microsoft.public.win2000.security)
  • Re: Prevent changes to Administrator password
    ... What I am trying to do is give Taz1972 some options to minimize the risk or make it harder for a lower-level DA to reset the password for the EA account. ... Restricted Admins group to mitigate against what you propose Deji. ... also need to make sure the DAs in question cannot elevate their rights to EA, ... > By adding the Deny Write Permissions ACE, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Prevent changes to Administrator password
    ... What I am trying to do is give Taz1972 some options to minimize the risk or make it harder for a lower-level DA to reset the password for the EA account. ... * This posting is provided "AS IS" with no warranties and confers no rights! ... > By adding the Deny Write Permissions ACE, ... > permission to modify the ACL on AdminSDHolder. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Why is Fedora not a Free GNU/Linux distributions?
    ... Taking away legitimate rights, yes, that would be immoral. ... specifically to be incompatible with the GPL, ... Software license) doesn't take away any right you had. ... There are other permissions that enable you to copy and distribute the ...
    (Fedora)
  • Re: Prevent changes to Administrator password
    ... Have you thought about delegating the exact permissions needed instead of using DA or restructing your forest? ... * This posting is provided "AS IS" with no warranties and confers no rights! ... > Restricted Admins group to mitigate against what you propose Deji. ...
    (microsoft.public.windows.server.active_directory)