Cannot lock down folder

paul.hester_at_gmail.com
Date: 09/13/05


Date: 13 Sep 2005 05:30:18 -0700

Hi all,

I'm having a problem with what is most likely a rudimentary task. I
want to lock down access to a folder on the webserver so that only a
particular security group has access to it. However, I have created a
user that isn't a member of any groups (I've removed him from Users as
well) and he can still be authenticated and get access to the folder.

I'm using IIS6 on a Windows 2003 Server. I've turned off anonymous
access for this folder and am using Integrated Windows Authentication.
I've turned off inherited permissions for the folder edited the ACL so
that only the following members remain:

Administrators
CREATOR_OWNER
INTERACTIVE
Internet Guest Account
NETWORK
NETWORK SERVICE
SN Admin (the group I created)
SYSTEM

I get the authentication popup as expected when accessing the folder,
but this user is still getting through. I'm writing out the
authenticated user on the web page and it's definitely the same user.

My apologies if this is a bit of a newbie question. Any help would be
much appreciated.

Many thanks,

Paul



Relevant Pages

  • Re: Multi Level Forms Authentication Help DESPERATELY NEEDED!
    ... Forms authentication supports this functionality. ... You can have a web.config in each folder that specifies who's allowed in. ... > to access certain files on the web site to an ASP .NET Forms ... > while still managing access to the aforementioned subdirectories. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Domain Name Forging On Authentication Prompt
    ... Domain Name Forging On Authentication Prompt ... To bypass IE domain restrictions the ip of the protected folder needs ... [End Code Sample] ...
    (Vuln-Dev)
  • RE: Need to restrict remote users to access only specific folder(s
    ... This sounds like an authentication problem -- or a firewall problem. ... go through the IIS logs to look for problems authenticating or on the service ... user via file access permissions when working internally. ... Suggestions for better folder level access via RWW? ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to securely publish a Click Once application
    ... the folder hierarchy in tact. ... Forms authentication, deny all anonymous users and the mime setting to add ... non-asp.net apps to the forms authentication protection looks like the right ... for any updates - but because the update location doesn't allow ...
    (microsoft.public.dotnet.framework)
  • Re: Authentication login screen appears on both frames of the framset
    ... This section sets the authentication policies of the application. ... This section sets the authorization policies of the application. ... Application-level tracing enables trace log output for every page ... folder / file to set ...
    (microsoft.public.dotnet.framework.aspnet)