Re: HOW TO IIS -Security



phil wrote on 24 May 2006 21:44:15 -0700:

Hi!! & Hello!!!

Well I have a server where I have hosted many sites on IIS 6.0. When
the users I mean the public users (anyone from anywhere) if they go to
their Start->Run-> from windows and type the IP address(for eg
\\83.485.574.22) like this it opens up the default site with full
directory view and ...with all the files and folders. write permission
.how can i stop this ??? i mean their is no security at all how can i
stop this???

regards
Phil

A connection to \\w.x.y.z isn't going through IIS - that's a UNC path.
Actually, it shouldn't show the default site at all - it should just show a
list of the available shares on the machine on that IP address. If this is
the case, you've got Windows file sharing exposed to everyone, and the guest
account enabled with full permissions - this is nothing to do with IIS, and
it means you've changed the default NTFS permissions in Windows and
connected your machine to the internet with no firewall.

Dan


.



Relevant Pages

  • Re: Run IIS as admin to write to Active Directory - security risk?
    ... Please reconsider using ADAM with IIS (better yet on R2 also w/. ... This can be done on standalone or member of domain, ... app that will allow public users to create their own user accounts, ...
    (microsoft.public.inetserver.iis.security)
  • HOW TO IIS -Security
    ... Well I have a server where I have hosted many sites on IIS 6.0. ... the users I mean the public users if they go to ...
    (microsoft.public.inetserver.iis.security)
  • RE: no OWA
    ... have the correct permissions was the "inetpub" folder. ... Correct the settings in IIS: ... click to check the "Hide All Microsoft Services" ...
    (microsoft.public.windows.server.sbs)
  • Re: Minimum NTFS Permissions - Theres such a thing???
    ... ?2001 Microsoft Corporation. ... HOW TO: Set Minimum NTFS Permissions Required for IIS 5.0 to Work WGID:198 ... " List Folder Contents" ...
    (microsoft.public.inetserver.iis.security)
  • Re: FTP control
    ... > I would like to use NTFS security settings to control who ... I would suggest getting a third party FTP server, ... if you set quota and these permissions for that group you can ... Information Server (IIS) Web site, ...
    (microsoft.public.win2000.security)