Re: Programmatically Altered IIS Security?

From: Painless (Painlesspole_at_yahoo.com)
Date: 05/09/04

  • Next message: Issac Goldstand: "403 Error on CGI Pages in IIS 6.0"
    Date: Sun, 9 May 2004 08:01:25 -0700
    
    

    Same problem for me also. Monday morning I get an angry call from a
    customer claiming he cannot edit his web pages. For some reason, windows
    authentication has stopped working, and my SMTP server has forgotten which
    IP addresses it can relay mail for. I now have the web server running with
    clear text authentication.
     The angry calls have stopped, and I have re-configured the mail server, but
    understand, these servers have been running perfectly since 2001. (And we
    never EVER touch ANYTHING that is working.)

    The only server I have which is still running is one which we had
    accidentally turned off the automatic updates. (and I am afraid to apply
    updates now.)

    "Rick Skinner" <rskinner@research.usf.edu> wrote in message
    news:f88a871.0405050905.5072ab7d@posting.google.com...
    > Programmatically Altered IIS Security?
    >
    > My server is running IIS5 on Windows 2000. On Monday morning one of
    > my techs installed two updates from Windows Update:
    >
    > 1) Root Certificates Update
    > 2) Update for Windows Media Player 9 Series (KB837272)
    >
    > Let's leave aside the point that there is probably no good reason to
    > install these updates on a production Web server for now.
    >
    > We also had a corresponding Sasser virus outbreak on several
    > workstations Monday morning.
    >
    > Immediately after these updates were applied about half of my ASP
    > based pages started hanging. After an hour of troubleshooting we were
    > inclined to suspect directory/file level permissions problems. I
    > noticed particularly that three strange local groups with no members
    > had been assigned read only permission to the wwwroot file system.
    > Also permissions throughout the file system were insufficient to allow
    > much of our ASP stuff to run. I don't know how these permissions got
    > altered and none of my techs claim responsibility.
    >
    > Is it possible that one of these two updates altered the permissions
    > on the wwwroot file system? Or do I blame it on the Sasser worm? Can
    > anyone help explain how my Web server's file system permissions got
    > altered by Windows Update or by any other means?
    >
    > I first restored system state from the previous Friday and those three
    > strange local groups went away substantiating that they did not exist
    > as of the last good backup. I next restored Friday's file system with
    > permissions from inetpub on down and everything was fine after that.
    >
    > I'm just left wondering what altered the permissions on my file
    > system. Any experience you can offer would be appreciated. Thanks.
    > Rick Skinner
    > rskinner@research.usf.edu


  • Next message: Issac Goldstand: "403 Error on CGI Pages in IIS 6.0"

    Relevant Pages

    • AW: ASP Dot Net Security Guidelines
      ... i have set up 2 dotnet server and did a pen-test of a dotnet server for ... i wouldn't focus so much on the file system permissions. ... ASP Dot Net Security Guidelines ...
      (Focus-Microsoft)
    • Re: Give yourself SQL Administrator rights
      ... Even if you change the default settings to allow updates to ... permissions to this user on sysxlogins. ... Only members of the server roles sysadmin and serveradmin ... SQL Server DBAs may wish to disable 'allow ...
      (microsoft.public.sqlserver.security)
    • Programmatically Altered IIS Security?
      ... my techs installed two updates from Windows Update: ... install these updates on a production Web server for now. ... Also permissions throughout the file system were insufficient to allow ...
      (microsoft.public.inetserver.iis.security)
    • Re: Folder security by GPO
      ... If file system does not work then you could use a Group ... Policy computer startup script using cacls to assign permissions for the ... > file system security through Group Policy in the Computer Config - Windows ... I want to set a policy such that Server A gets the policy ...
      (microsoft.public.win2000.security)
    • Re: Remove shutdown in remote desktop
      ... kj> I'd NEVER give regular users logon permissions to a Domain ... this kiosk-like solution on two workstations or on another server. ... kj> 2) Locally logged on users have file system access to shares ... Domain Controller, IIS, Sharepoint Server, Exchange Server, ISA, SQL, etc? ...
      (microsoft.public.windows.server.sbs)