RE: IIS still vulnerable

From: Christopher Haun (a-chaun_at_NOSPAMmicrosoft.com)
Date: 12/29/03


Date: Mon, 29 Dec 2003 18:55:07 GMT


Yes, definitely lock permissions down on the ntfs level for the iusr
account if using anonymous access on any ftp sites. These kb articles
should help show the minimum levels.

187506 INFO: Basic NTFS Permissions for IIS 4.0
http://support.microsoft.com/?id=187506

271071 HOW TO: Set Basic NTFS Permissions for IIS 5.0
http://support.microsoft.com/?id=271071

812614 INFO: Default Permissions and User Rights for IIS 6.0
http://support.microsoft.com/?id=812614

Also consider looking at the ftp properties to lock down the site(s) with
certain ip address exclusions. The IIS logs (start > run > logfiles) may
show his IP address. Then you can lock him out that way.

Keep in mind that the intruder may have installed some more backdoors on
the system.
On the surface it doesn't sound like the intruder is very malevolent.
However, it may not be worth giving him the benefit of the doubt.
There is some good general advice at:
http://www.cert.org/tech_tips/win-UNIX-system_compromise.html

Hope that helps,

Chris - IIS Team



Relevant Pages

  • Re: IIS 5 Anonymous NTFS Permissions
    ... Where did you apply the permissions at the wwwroot or the web site? ... Default Permissions and User Rights for IIS 6.0: ... How To Set Basic NTFS Permissions for IIS 5.0: ... And even if you don't type a username or password and just click ...
    (microsoft.public.inetserver.iis)
  • RE: no OWA
    ... have the correct permissions was the "inetpub" folder. ... Correct the settings in IIS: ... click to check the "Hide All Microsoft Services" ...
    (microsoft.public.windows.server.sbs)
  • Re: Minimum NTFS Permissions - Theres such a thing???
    ... ?2001 Microsoft Corporation. ... HOW TO: Set Minimum NTFS Permissions Required for IIS 5.0 to Work WGID:198 ... " List Folder Contents" ...
    (microsoft.public.inetserver.iis.security)
  • Re: FTP control
    ... > I would like to use NTFS security settings to control who ... I would suggest getting a third party FTP server, ... if you set quota and these permissions for that group you can ... Information Server (IIS) Web site, ...
    (microsoft.public.win2000.security)
  • Re: Minimum NTFS Permissions - Theres such a thing???
    ... ?2001 Microsoft Corporation. ... > permissions that you must have to run Internet Information Services ... > third-party applications in an IIS 5.0 environment. ... Open the properties for the %systemroot%\Winnt folder, ...
    (microsoft.public.inetserver.iis.security)