Re: Limit some users?

From: David Wang [Msft] (someone_at_online.microsoft.com)
Date: 10/04/05

  • Next message: Steven L Umbach: "Re: Is the Certficate I "see" from my IE Broswer the "actual " server certificate ?"
    Date: Tue, 4 Oct 2005 14:05:19 -0700
    
    

    Then the simple way would be to find a Web Hoster and have them host your
    website. No complexities of hosting and securing a server, friends/family
    can still visit the website, and you have control of its content.

    Reality is, as soon as you put a server up, the entire world will visit it,
    including your family. Most of the non-family members will likely visit with
    malicious intent, and if you do not become a whiz they will walk all over
    you.

    When you talk about Computers and Security, it is like talking about Cars
    and Safety. It is constantly changing and improving. And when you say:

    > I only run my server for fun and a couple of friends and family visit
    > it.So how should I go about making it more secure?

    It is analogous to saying:
    "I only drive my car for fun for a couple of friends and family, so how
    should I go about making it more safe?"

    In the case of the car, you would buy the car with the safety features and
    use them. You wouldn't try to assemble it together. In the case of the
    server, where you have all the pieces, you either need to know how to
    assemble it properly, or you buy the end product of someone else who has it
    together.

    And since you say you are a simple man with simple goals and not a computer
    whiz nor understand all the tech talk, I suggest you go with professional
    Web Hosters like 1and1.com

    -- 
    //David
    IIS
    http://blogs.msdn.com/David.Wang
    This posting is provided "AS IS" with no warranties, and confers no rights.
    //
    "Joker7" <sat_ring@hotmail.com> wrote in message
    news:1128423222.b2735f3f7a22d24258519430516cbc1a@teranews...
    "David Wang [Msft]" <someone@online.microsoft.com> wrote in message
    news:%23356aH8xFHA.3124@TK2MSFTNGP12.phx.gbl...
    : Do NOT run IIS on a FAT32 partition. You are just asking for trouble
    because
    : you have no security in that configuration. Running custom authentication
    : will eventually cause you more problems than it is worth - suppose you
    want
    : a Web hoster to host your website; they probably won't run your custom
    : authentication (they do not like running arbitrary binaries on their
    servers
    : because they have to protect themselves against both you and this binary),
    : so you probably have to rewrite it all.
    :
    : I suggest you only allow IIS to serve content from a NTFS partition.
    :
    : I also suggest you stick with a web hoster to host your site and only do
    : website development on your machine.
    :
    : -- 
    : //David
    : IIS
    : http://blogs.msdn.com/David.Wang
    : This posting is provided "AS IS" with no warranties, and confers no
    rights.
    : //
    : "Joker7" <sat_ring@hotmail.com> wrote in message
    : news:1128270378.787c436c75f1d6f71254e174463cd4f6@teranews...
    :
    : "Miha Pihler [MVP]" <mihap-news@atlantis.si> wrote in message
    : news:e7YHIP2xFHA.1148@TK2MSFTNGP11.phx.gbl...
    :: Hi,
    ::
    :: One way to do this would be to apply NTFS permissions on the web content.
    : Of
    :: course you would have to remove permissions such as Authenticated Users
    :: Group, IUSR_<Computer Name>, etc. Then place the users (or your own
    : groups)
    :: and allow these users only read permissions.
    ::
    :: Users who will not have read permissions will be denied access.
    ::
    :: IIS will always honor NTFS permissions...
    ::
    :: I hope this helps,
    ::
    :: -- 
    :: Mike
    :: Microsoft MVP - Windows Security
    ::
    :: "Joker7" <sat_ring@hotmail.com> wrote in message
    :: news:1128253607.2aec507a71ec49dbce63317a5ba900a9@teranews...
    :
    : I forgot to say that the drive is fat32 and not NTFS
    :
    : Cheers
    : Chris:
    :
    :
    Hi,
    I'm a simple man with simple goals in life,so could you explain yourself in
    simple terms.I'm not a computer whiz that would understand all the tech
    talk.
    Quote
    You are just asking for trouble because
    : you have no security in that configuration. Running custom authentication
    : will eventually cause you more problems than it is worth
    I only run my server for fun and a couple of friends and family visit it.So
    how should I go about making it more secure?
    Chris
    

  • Next message: Steven L Umbach: "Re: Is the Certficate I "see" from my IE Broswer the "actual " server certificate ?"

    Relevant Pages

    • RE: [Owasp-dotnet] Re: (Asp.Net Full Trust Vulnerabilities) RE: Apache VS IIS Security model questio
      ... > b) Each client of the server (say, each department of a company, or each ... > c) Each website is placed into its own custom application pool ... password attack to all accounts. ... download the ANBS (Asp.Net Baseline Security) Open Source tool (that I ...
      (Pen-Test)
    • Re: Cant open websites from Front Page
      ... For the files found which are in your website folder structure, ... Restart the server if possible to ensure files are unlocked. ... But they gave me no option to 'delete' the lock file. ... how FP security and NTFS security combine to give the effective rights. ...
      (microsoft.public.frontpage.extensions.windowsnt)
    • [Full-Disclosure] RE: [Owasp-dotnet] Re: (Asp.Net Full Trust Vulnerabilities) RE: Apache VS IIS Secu
      ... > b) Each client of the server (say, each department of a company, or each ... > c) Each website is placed into its own custom application pool ... ALL website's Metabase entries, then the malicious script could (after ... download the ANBS (Asp.Net Baseline Security) Open Source tool (that I ...
      (Full-Disclosure)
    • RE: Using ISA for 1 IP Address on net with hardware firewall on ot
      ... If anyone else uses the MS interface to this newsgroup watch out. ... When it tells you a post hasn't been made due to some server error, it probably has gone through as you can see from the multiple posts I made.... ... >> Security can be a bit tricky, ... deploy OWA on its own virtual website. ...
      (microsoft.public.isa)
    • security-basics Digest of: get.123_145
      ... VPN to ASP a security risk? ... Re: Multiple IPSec tunnels? ... Subject: Security NT Server ... VPN to ASP a security risk? ...
      (Security-Basics)