|
security
newsgroups
|
|||||||||||||||||||||||
|
|||||||||||||||||||||||
Looking for suggestions on how to clean up ACL - W2k+IISI just got a Windows 2000 server machine that acts as a webserver. I saw that the ACL is very dirty: the ASPNET, FTP and IUSR_ accounts have full control in too much directory. Well, i was looking for a good tutorial on how to clean the acl and give only the file/directory permissions that are strictly needed by IIS and ASPNET. The server has Windows 2000 Server SP4, MS SQL Server 2000 and IIS 5.0 with ASP.NET sites installed on it. I was wandering if deleting all the account accesses to directories, and leaving only Administrator access + those accesses needed by IIS&ASPNET is a good idea. No one uses that computer, it's only a webserver with few sites on it but i would like to harden it. Thanks a lot i.a. best regards Marco
Show quote
Hide quote
"M. Simioni" <m.simioniREMOVET***@REMOVETHISwooow.it> wrote in message Follow these:news:Mvx7e.1675$TR5.450@news.edisontel.com... > Hi, i'm new to Windows 2000 server administration. > > I just got a Windows 2000 server machine that acts as a webserver. > I saw that the ACL is very dirty: the ASPNET, FTP and IUSR_ accounts have > full control in too much directory. > > Well, i was looking for a good tutorial on how to clean the acl and give > only the file/directory permissions that are strictly needed by IIS and > ASPNET. > > The server has Windows 2000 Server SP4, MS SQL Server 2000 and IIS 5.0 with > ASP.NET sites installed on it. > > I was wandering if deleting all the account accesses to directories, and > leaving only Administrator access + those accesses needed by IIS&ASPNET is a > good idea. > No one uses that computer, it's only a webserver with few sites on it but i > would like to harden it. http://support.microsoft.com/default.aspx?scid=kb;en-us;Q271071 http://support.microsoft.com/default.aspx?scid=kb;en-us;313075 http://support.microsoft.com/kb/815153/ -- Tom Kaminski IIS MVP http://www.microsoft.com/windowsserver2003/community/centers/iis/ http://mvp.support.microsoft.com/ http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS
IIS 6 conflict using port 443 for NON-SSL traffic
Intranet problem - 404 and 405 errors How to tell if IIS lockdown Tool is installed? Failure posting files to iis6.0 using ssl client authentication IIS6, WIN2k3SP1 and integrated authentication URLScan as an attack vector? Anonymous access request certificate immediately update databse encrypting and signing |
|||||||||||||||||||||||