Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Security > IIS anonymous user is a domain user

Reply
Thread Tools

IIS anonymous user is a domain user

 
 
Henry Splatt
Guest
Posts: n/a
 
      09-04-2003
What are the security rammifications of having an IIS 5.0 box, where the
anonymous user is a domain user as opposed to the normail IUSR_Machine
account?

How would this be amplified, if at all, by having the default Everyone group
with full control on the file system? The box is behind a good firewall.

Thanks for your time,

Henry


 
Reply With Quote
 
 
 
 
Mike
Guest
Posts: n/a
 
      09-05-2003
I will take a quick stab at this but by running your website as a domain
user it is basically giving permission to your web server to access anything
that the Everyone group on your entire DOMAIN can access. That means that
if someone manages to take advantage of one of the many IIS vulnerabilities
they very well may have access to information all over your network instead
of just the one machine.

Mike

"Henry Splatt" <> wrote in message
news:AsG5b.3628780$...
> What are the security rammifications of having an IIS 5.0 box, where the
> anonymous user is a domain user as opposed to the normail IUSR_Machine
> account?
>
> How would this be amplified, if at all, by having the default Everyone

group
> with full control on the file system? The box is behind a good firewall.
>
> Thanks for your time,
>
> Henry
>
>



 
Reply With Quote
 
 
 
 
Leythos
Guest
Posts: n/a
 
      09-05-2003
In article <YnS5b.163374$_V.118026
@news04.bloor.is.net.cable.rogers.com>, says...
> I will take a quick stab at this but by running your website as a domain
> user it is basically giving permission to your web server to access anything
> that the Everyone group on your entire DOMAIN can access. That means that
> if someone manages to take advantage of one of the many IIS vulnerabilities
> they very well may have access to information all over your network instead
> of just the one machine.


That's why you learn how to lock your IIS server down - there are many
easy ways to secure IIS so that if someone does compromise it that they
won't be able to run CMD.COM and other things necessary to do damage.

Please follow NORMAL/STANDARD usenet etiquette and BOTTOM post.

Mark


--
--

(Remove 999 to reply to me)
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Making a server on one domain the domain controller of a new domain Limited Wisdom MCSA 7 09-13-2006 02:18 AM
IIS 5 - GetObject fails with "Restrict Anonymous" enabled on Domain Controllers Gerry ASP General 2 07-31-2003 02:34 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57