Re: Windows 2003 remote admin access



Then I would look at the web content, as I try to say before, at
least if the content are is IIS enabled as application (i.e. supports
asp, asp.net) or if any areas are enabled for scripting (i.e. granted
execute, such as for cgi). Consider, if any area is made to allow
non-anonymous browsing, then that area when browsed will have
access done in context of the authenticated browsing account (i.e.
the person's admin account) so any code posted to the content
area couuld be made to run with that account. Similarly, if the
authoring is being done with use of the FrontPage server extensions,
or if FTP is configured with excess dirs, then once authenticated to
author with these as an admin account the authoring would only
be limited to areas defined as vdirs in IIS and/or FTP. If you
are finding changes at other locations, or changes to machine
config settings (new accounts, service properties changes, etc.)
then I would examine the content of web script and/or application
areas (assuming your statements about dcom over http, ports
allowed, rdp not allowed are all correct).

"John Collins" <jc1998@xxxxxxxxx> wrote in message
news:e82m6l$g02$1@xxxxxxxxxxxxxxxxxxxxxx
Hello Roger,

The server sits behind a hardware firewall which is only allowing those
particular ports inbound so access on any other ports shouldn't be
possible. The user does have HTTP and FTP web authoring access but this
should (as I understand it) only be for the areas defined in IIS under the
website and FTP sites? DCOM proxying certainly hasn't been enabled
manually by myself. I'm assuming that this wouldn't be enabled by default?
How can I check to see if it is enabled and if so how can this be used to
gain access?

Many thanks,
John

"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in message
news:Oi%239fQ%23mGHA.3544@xxxxxxxxxxxxxxxxxxxxxxx
Are they allowed to author web content ? particularly if it is in
and IIS defined application area ??
Has DCOM proxying over HTTP been enabled ?
How are you certain that there are no other allowed ports ?


"John Collins" <jc1998@xxxxxxxxx> wrote in message
news:e80ucu$d86$1@xxxxxxxxxxxxxxxxxxxxxx
Hello,

I have a query which is only apparent due to politics in the work place.
On a technical level I can quite easily stop this issue but am intrigued
as to how this can be happening?..

One of our Windows 2003 servers is being accessed by a user who does
have an administrator account, but does not have local access to the
server. From outside the local network the only permitted inbound access
is for HTTP, HTTPS, SMTP and FTP, all using the standard ports. There
is no remote access software installed, e.g. Remote Desktop, NetOp etc.
How can it be possible for files to be added / removed, permissions
changed etc on this server via these protocols? (Obviously the user can
interact with the services that are provided, but things are changing
outside of these locations).

Any ideas at all, anyone?

Thanks,
John







.



Relevant Pages

  • Re: ASP.NET Website Project
    ... same time that i would have enough permission to access my DB. ... This has nothing to do with random ports. ... runs as the account you are logged in with, while IIS runs as the OS ...
    (microsoft.public.dotnet.framework.aspnet)
  • Handling HTTP 500 Account Locked
    ... When a user's account has been locked due to password violations and ... referenced account is currently locked...". ... This is due to the browser option "Show Friendly HTTP error messages" ... We're using Win2k, IIS 5.0, Active Directory with Digest ...
    (microsoft.public.inetserver.iis.security)
  • Re: Host Company web on SBS 2003
    ... HTTPS and RWW requires that the user know an account and password, ... and the typical attack methods of HTTP don't work until the account ... In HTTP your server is processing anything they throw at it before ... Traffic must work its way through IIS to get authenticated. ...
    (microsoft.public.windows.server.sbs)
  • Re: Host Company web on SBS 2003
    ... HTTPS and RWW requires that the user know an account and password, ... In HTTP your server is processing anything they throw at it before ... Traffic must work its way through IIS to get authenticated. ... spam999free@xxxxxxxxxx (remove 999 for proper email address) ...
    (microsoft.public.windows.server.sbs)
  • RE: SOME Users cannot access OWA others do, error HTTP 500
    ... I understand that some account access OWA ... IIS 6.0 compression corruption causes access violations ... compressed copy of the affected files on the SBS server: ...
    (microsoft.public.windows.server.sbs)