Home All Groups Group Topic Archive Search About

Looking for suggestions on how to clean up ACL - W2k+IIS

Author
14 Apr 2005 5:12 PM
M. Simioni
Hi, i'm new to Windows 2000 server administration.

I just got a Windows 2000 server machine that acts as a webserver.
I saw that the ACL is very dirty: the ASPNET, FTP and IUSR_ accounts have
full control in too much directory.

Well, i was looking for a good tutorial on how to clean the acl and give
only the file/directory permissions that are strictly needed by IIS and
ASPNET.

The server has Windows 2000 Server SP4, MS SQL Server 2000 and IIS 5.0 with
ASP.NET sites installed on it.

I was wandering if deleting all the account accesses to directories, and
leaving only Administrator access + those accesses needed by IIS&ASPNET is a
good idea.
No one uses that computer, it's only a webserver with few sites on it but i
would like to harden it.

Thanks a lot i.a.
best regards

Marco

Author
14 Apr 2005 8:08 PM
Tom Kaminski [MVP]
Show quote Hide quote
"M. Simioni" <m.simioniREMOVET***@REMOVETHISwooow.it> wrote in message
news:Mvx7e.1675$TR5.450@news.edisontel.com...
> Hi, i'm new to Windows 2000 server administration.
>
> I just got a Windows 2000 server machine that acts as a webserver.
> I saw that the ACL is very dirty: the ASPNET, FTP and IUSR_ accounts have
> full control in too much directory.
>
> Well, i was looking for a good tutorial on how to clean the acl and give
> only the file/directory permissions that are strictly needed by IIS and
> ASPNET.
>
> The server has Windows 2000 Server SP4, MS SQL Server 2000 and IIS 5.0
with
> ASP.NET sites installed on it.
>
> I was wandering if deleting all the account accesses to directories, and
> leaving only Administrator access + those accesses needed by IIS&ASPNET is
a
> good idea.
> No one uses that computer, it's only a webserver with few sites on it but
i
> would like to harden it.

Follow these:
http://support.microsoft.com/default.aspx?scid=kb;en-us;Q271071
http://support.microsoft.com/default.aspx?scid=kb;en-us;313075
http://support.microsoft.com/kb/815153/