OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Holmes, Tyran (tholmes_at_ascendone.com)
Date: Fri Jan 24 2003 - 15:32:23 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Is the account (IUSR...) active? I know I remember getting some errors
    for the IUSR accts in the Event Log on an IIS server and found that my
    cohort had disabled the accounts. Just a thought...

    -----Original Message-----
    From: Ralph Los [mailto:RLosenteredge.com]
    Sent: Friday, January 24, 2003 12:56 PM
    To: 'focus-mssecurityfocus.com'
    Subject: Securing IIS/5 with ASP
    Sensitivity: Confidential

    Hello,
            I have a document I've built over the years about securing
    IIS/5,
    with regards to permissions, etc right down to the file level. This
    often
    works, except when I get that pesky ASP engine involved. I'm sick of
    HTTP/500 errors! I know for a fact the error is with file permissions,
    but
    I can't pin-point which file(s) are causing it. I've had the
    dllhost.exe
    keep getting "ACCESS DENIED" (Using NTFileMon from sysinternals.com) on
    C:\winnt\system32\<some_file> but...the permissions on that
    file/folder/whatever are IUSR/IWAM/SYSTEM (RWX).

            Bottom line, does anyone have a definitive "baseline IIS/5
    w/ASP"
    security document done I could look over? Just curious - dying to know
    what
    I'm missing.

    ?Ralph