Re: HOW TO IIS -Security



Hi,

a) How do you know there is no security? Are you allowing anonymous access?
Have you configured NTFS permissions to restrict which users can access the
files?

b) Do you have WebDAV enabled in the Web Service Extensions list? They are
accessing the site via WebDAV by the looks of it - if you have it enabled,
you need to take additional steps to restrict who can view what. Otherwise
disable WebDAV if you don't need that functionality.

Cheers
Ken


"phil" <philip.prabhakar@xxxxxxxxx> wrote in message
news:1148532255.803316.252990@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi!! & Hello!!!

Well I have a server where I have hosted many sites on IIS 6.0. When
the users I mean the public users (anyone from anywhere) if they go to
their Start->Run-> from windows and type the IP address(for eg
\\83.485.574.22) like this it opens up the default site with full
directory view and ...with all the files and folders. write permission
.how can i stop this ??? i mean their is no security at all how can i
stop this???

regards
Phil



.



Relevant Pages

  • Re: HOW TO IIS -Security
    ... How do you know there is no security? ... c)Do you have WebDAV enabled in the Web Service Extensions list? ... Have you configured NTFS permissions to restrict which users can access the ...
    (microsoft.public.inetserver.iis.security)
  • Re: User ASPNET in SQL Server 2000
    ... and turn off anonymous access. ... a logon box will pop up if the user cannot ... >While I love integrated security in SQL Server, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: OU Security - best setup?
    ... Ideally for best security for each company and to restrict what users can ... only what is in their OU if you have disabled netbios over tcp/ip in the ... computer from the network to only include authorized groups such as users ...
    (microsoft.public.win2000.security)
  • Re: WCF and Integrated Windows Authentication
    ... anonymous access in IIS. ... should be used as the security identity when your ASP.NET web app calling ... you can try explicitly specify a client credentials (when calling the WCF ... You can send feedback directly to my manager at: ...
    (microsoft.public.dotnet.framework.aspnet.webservices)
  • Re: restrict read access
    ... Check to see if the objects are inheriting the parent ou's security. ... What ou did you deny? ... >>> account) and stores in an interna database. ... >>> we would like to restrict that to an special OU. ...
    (microsoft.public.win2000.active_directory)