Microsoft IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsSystem AdministrationMicrosoft IIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old June 28th, 2006, 05:25 AM
Padwah Padwah is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2005
Posts: 46 Padwah User rank is Private First Class (20 - 50 Reputation Level)Padwah User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 1 Day 19 h 35 m 3 sec
Reputation Power: 3
IIS/ASP Permissions

I have written an ASP based blog/cms application but I need a bit of a hand with the security permissions between IIS and the ASP scripts themselves. The application allows administrators (application administrators NOT system administrators) to add, edit and delete physical pages from within the application itself using scripting.filesystemobject. Unfortunately this means that read,write and modify permissions must be set on the website that it is running on to allow these files to be created or modified which is obviously not a very secure way of doing things as I recently found out when someone uploaded a new index page for me :/

So anyway, I've two questions now:

1) I'm currently going through my IIS log files to try and see how or what they did but I've only got notepad, anyone got any tips on what I should be looking for?

2) The scripts that require permission to add, edit and delete files all reside in a sub-folder within the application. Is there anyway that I can grant the required permissions to the specific files or the folder they reside in?

Reply With Quote
  #2  
Old June 28th, 2006, 08:18 AM
degsy degsy is offline
Contributing User
ASP Free God 2nd Plane (6000 - 6499 posts)
 
Join Date: Aug 2005
Location: North East, UK
Posts: 6,191 degsy User rank is First Lieutenant (10000 - 20000 Reputation Level)degsy User rank is First Lieutenant (10000 - 20000 Reputation Level)degsy User rank is First Lieutenant (10000 - 20000 Reputation Level)degsy User rank is First Lieutenant (10000 - 20000 Reputation Level)degsy User rank is First Lieutenant (10000 - 20000 Reputation Level)degsy User rank is First Lieutenant (10000 - 20000 Reputation Level)degsy User rank is First Lieutenant (10000 - 20000 Reputation Level)degsy User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 4 Days 19 h 41 m 52 sec
Reputation Power: 121
Do you have a login script?
If not you should have. If you have change the password and make it more secure.
If the password is in an Access database within the webroot then make sure you don't have read permissions on the folder because if you do then anyone can download it.
__________________
CyberTechHelp

Reply With Quote
  #3  
Old June 28th, 2006, 08:22 AM
Padwah Padwah is offline
Contributing User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Dec 2005
Posts: 46 Padwah User rank is Private First Class (20 - 50 Reputation Level)Padwah User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 1 Day 19 h 35 m 3 sec
Reputation Power: 3
Cheers for the reply degsy, I do have a log in script which uses a MySQL DB. after going through the logs though it looks like the scrotes used an exploit in either the Frontpage extensions or webdav to put their files in my website root rather than their being a serious problem with my IIS permission settings.

Reply With Quote
  #4  
Old July 1st, 2006, 05:59 PM
Doug G Doug G is offline
Grumpier Old Moderator
ASP Free God 11th Plane (10000 - 10499 posts)
 
Join Date: Sep 2003
Posts: 10,143 Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level)Doug G User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 3 Weeks 4 Days 23 h 19 m 36 sec
Reputation Power: 181
You can set read/write permissions on a specific subfolder, in fact that's the usual way to restrict users uploads to a specified location only. I generally use windows itself to set file permissions, not IIS.
__________________
======
Doug G
======
I didn't attend the funeral, but I sent a nice letter saying I approved of it. --Mark Twain

Reply With Quote
Reply

Viewing: ASP Free ForumsSystem AdministrationMicrosoft IIS > IIS/ASP Permissions


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway
Stay green...Green IT