Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Programming > ASP .Net > ASP .Net Security > IWAM account and Act as part of the operating system right

Reply
Thread Tools

IWAM account and Act as part of the operating system right

 
 
Frank1213
Guest
Posts: n/a
 
      11-22-2006
I have used the code sample from the KB article
http://support.microsoft.com/default.aspx/kb/248187
to impersonate a user from an ASP page and change the security context. The
impersonation works fine on Windows 2003 and XP but fails on Windows 2000.
The only way I can get impersonation to work is by enabling "Act as part of
the operating system" privileges for the IWAM_<computername> account as
mentioned in the KB article.
My question,
1. How big of a security risk is this when I deploy my application?
2. Is this an accepted security workaround?

Thanks in advance.
 
Reply With Quote
 
 
 
 
Frank1213
Guest
Posts: n/a
 
      11-28-2006
I would appreciate if anyone has any thoughts on this one. Basically, what is
the security risk if I grant the IWAM_<computername> user account the Act as
part of the operating system right?
Thanks.

"Frank1213" wrote:

> I have used the code sample from the KB article
> http://support.microsoft.com/default.aspx/kb/248187
> to impersonate a user from an ASP page and change the security context. The
> impersonation works fine on Windows 2003 and XP but fails on Windows 2000.
> The only way I can get impersonation to work is by enabling "Act as part of
> the operating system" privileges for the IWAM_<computername> account as
> mentioned in the KB article.
> My question,
> 1. How big of a security risk is this when I deploy my application?
> 2. Is this an accepted security workaround?
>
> Thanks in advance.

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IWAM account on Windows 2000 =?Utf-8?B?RnJhbmsxMjEz?= ASP .Net 0 12-01-2006 12:48 PM
Problem Printing using IWebBrowser2 from IWAM Account on Server 2003 ScottLR ASP .Net Web Controls 12 09-23-2005 02:54 AM
How to Import Certificate file into windows certificate store under IWAM account Helena Cai ASP General 0 08-29-2004 05:27 AM
RE: SE_TCB_NAME (Act as part of the operating system) privilege Steven Cheng[MSFT] ASP .Net 4 05-13-2004 07:11 AM
Why is "Act as part of the operating system" dangerous? Arturo ASP .Net Security 2 04-14-2004 11:36 AM



Advertisments