    What are the security rammifications of having an IIS 5.0 box, where the
    anonymous user is a domain user as opposed to the normail IUSR_Machine

    How would this be amplified, if at all, by having the default Everyone group
    with full control on the file system? The box is behind a good firewall.

    Thanks for your time,

    Henry Splatt, Sep 4, 2003
    I will take a quick stab at this but by running your website as a domain
    user it is basically giving permission to your web server to access anything
    that the Everyone group on your entire DOMAIN can access. That means that
    if someone manages to take advantage of one of the many IIS vulnerabilities
    they very well may have access to information all over your network instead
    of just the one machine.

    Mike, Sep 5, 2003
    That's why you learn how to lock your IIS server down - there are many
    easy ways to secure IIS so that if someone does compromise it that they
    won't be able to run CMD.COM and other things necessary to do damage.

    Leythos, Sep 5, 2003
