ASPX form Uploads a file even without IIS Write permission

From: FB (FB_at_discussions.microsoft.com)
Date: 08/20/05

  • Next message: Christian Paparelli: "Re: ASPX form Uploads a file even without IIS Write permission"
    Date: Fri, 19 Aug 2005 17:31:19 -0700
    
    

    A customer have a IIS 6 web server and even with IIS Write property DISABLED,
    an ASPX form can upload files to the server.

    The authentication is Anon (via IUSR_ user) and the IUSR_User have RWXD
    rights on the folder where the upload is stored.

    In the properties of the IIS folder where upload is done, the Read
    permission is set, but Write, SourceAccerss and Browse are disabled.

    Why the upload works???


  • Next message: Christian Paparelli: "Re: ASPX form Uploads a file even without IIS Write permission"

    Relevant Pages

    • Re: ASPX form Uploads a file even without IIS Write permission
      ... > solely responsible for making your custom configuration secure. ... > authentication/authorization does not lock down everything and leaves the ... IIS simply has no idea whether a given POST request is ... > ASP Upload, what the purpose of the Write IIS property? ...
      (microsoft.public.inetserver.iis.security)
    • RE: User name and password dialog refresh after 3 mins
      ... you are encountering some strange IIS authentication ... Submit the CSV file to server and parsing the file to store data objects ... | 1 User chooses a CSV file to upload ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: IIS 6 ASP: Which Process Identity Is It Using? App Pool or Anon?
      ... It is actually not an upload application. ... would need the write privileges or that both the IUSR and the TestService ... If everything works, the memory mapped files ... > I doubt if the behavior you met is caused by IIS caches IUSR ...
      (microsoft.public.inetserver.iis)
    • Re: Upload best practice help !
      ... Make sure no IIS directory has script/executables permission, ... this assumes that you do not have HTTP-accessible script ... if you upload the binary outside of HTTP namespace if you have an HTTP- ... particular environment like inetpub. ...
      (microsoft.public.inetserver.iis.security)
    • Re: ASPX form Uploads a file even without IIS Write permission
      ... you have to understand that the "Write" Property in IIS does not ... NTFS/IIS/ASP.Net based authentication/authorization schemes. ... ASP Upload, what the purpose of the Write IIS property? ... Anyone can upload files to the server? ...
      (microsoft.public.inetserver.iis.security)