Re: URLScan and an EXE File

From: Herb Martin (news_at_LearnQuick.com)
Date: 07/11/03


Date: Thu, 10 Jul 2003 20:58:25 -0500


User permissions for the other EXEs that should not
run.

Something like:

cacls *.exe /e /t /d Machine_Domain\IUSR_machinename

(An appropriate group can be used also -- do NOT use
everyone, network users, authenticated users etc with DENY)

Not a bad idea to do this to ALL *.exe *.dll on your system -
The lockdown tool does something like this to all the programs
OUTSIDE your webs, like in System32, on the theory if a hacker
does RUN code they cannot bootstrap through the existing and
powerful system utilies.

[What follows is just personal venting, feel free to ignore....]

Caveat: Having just screwed up my Frontpage extensions for the
5th time, maybe I am not the best person to trust on the subject. <GRIN>

Seriously, I didn't mess them up by myself, the lockdown tool or UrlScan
is did this too me.

The reason I am GOOD with permissions (besides teaching) is from YEARS
of FIGHTING Frontpage and the various Server Extensions or lockdown tool
crappy handling of this.

I LOVE FrontPage, I hate their idea of permissions -- and the stupid
lockdown
tool has hoed me again.

Even auditing is not finding the "file access" problem this time -- ok,
re-think
assumptions....



Relevant Pages

  • FPSE2002 Shared Hosting Flaw Workaround
    ... I have begun a workaround for the FrontPage 2002 Extensions use of the ... Interactive and Network permissions for those attempting Secure Shared ... When creating FrontPage users this configuration assumes they only belong to ... Add the Group 'Users' and give them 'Traverse Folder' on 'This folder only' ...
    (microsoft.public.inetserver.iis.security)
  • Re: Interactive USER
    ... by connecting with frontpage and disabling anonymous browsing from there. ... Interactive and Network permissions for those attempting Secure Shared ... SharePoint Admin Web Instance and App Pool. ... Add the Group 'Users' and give them 'Traverse Folder' on 'This folder only' ...
    (microsoft.public.inetserver.iis.security)
  • re: Need info on IIS manager and autoriting / permisions for FP ( MVP please rea
    ... You should always manage FrontPage permissions through ... FrontPage, and not through IIS Manager or Windows ... installed on the virtual server you're trying to use. ...
    (microsoft.public.frontpage.client)
  • BUG: XP SP2/FrontPage XP
    ... A fresh install of XP SP2 and associated updates, ... install of IIS 5.1 on XP Pro. ... Using FrontPage to access a website locally set up ... Use unique permissions for this web. ...
    (microsoft.public.frontpage.programming)
  • BUG: XP SP2/FrontPage XP
    ... A fresh install of XP SP2 and associated updates, ... install of IIS 5.1 on XP Pro. ... Using FrontPage to access a website locally set up ... Use unique permissions for this web. ...
    (microsoft.public.inetserver.iis)