Re: IIS Security Question

From: gg (asdfasd)
Date: 10/07/04

  • Next message: David Wang [Msft]: "Re: permanent redirect and ssl"
    Date: Thu, 7 Oct 2004 14:39:35 -0700
    
    

    You might want to consider putting the file systemobject in COM+, and
    running under a different user , who only has write access to that folder,
    this delegates the writing from the IUSR, and has advantages.

    "Sid" <sidskiba@telus.net> wrote in message
    news:320b01c4aa8a$13194b10$a301280a@phx.gbl...
    > I have sort of a general question about file uploading.
    > IIS 5.1
    >
    > I have a web site at c:\inetpub\wwwroot\
    >
    > I also have a directory at c:\images\ (not in the wwwroot
    > nor a virtual folder)
    >
    > I have read/write/modify on c:\images\ for IUSR account.
    >
    > Only Read/Execute on wwwroot
    >
    > I am looking to use a script to allow image uploads on a
    > password secure ASP page to the images directory.
    >
    > I have a question about general security of this though
    > and am not bright enough to test this. Can someone who
    > knows there is a directory c:\images\ use an HTTP command
    > or some other method to put files into that directory
    > without even having access to the upload script? Like a
    > PUT or PUSH of some sort?
    >
    > Or is the directory safe as it is out of the wwwroot and
    > is not a virtual directory?


  • Next message: David Wang [Msft]: "Re: permanent redirect and ssl"

    Relevant Pages

    • Re: Publishing all pages in Publisher 2003
      ... I suspect that you just aren't uploading the index_files ... as the images that you are uploading ... When you insert large image files into your Publisher doc, ... graphics and upload the new index.htm file and the new index_files folder. ...
      (microsoft.public.publisher.webdesign)
    • Re: Help with Publisher 2007 - images
      ... I used Normal, just now, when uploading with Filezilla. ... The index_files folder contains the other .htm files...the ... Microsoft MVP Expression ...
      (microsoft.public.publisher.webdesign)
    • Re: linking to pub files in more languages
      ... The German version of your site is not in a subfolder called "deutsch". ... You do not say how you are uploading your files to your host. ... at the same level as the current index_files folder, ...
      (microsoft.public.publisher.webdesign)
    • Re: Probable security breech - how do I fix it?
      ... What I was wondering is if I should be uploading to the image host or message board from this folder instead of from desktop: useraccountname>Public>Public Pictures ...
      (microsoft.public.windows.vista.security)
    • Re: Publisher 2003 wont republish, says folder is missing or dele
      ... so I am assuming that you did succeed in uploading after ... I did notice that you uploaded the "rich" version of the Publisher html, ... The host is a free host ... index_files folder to your computer where you can find them. ...
      (microsoft.public.publisher.webdesign)