PC Review


Reply
Thread Tools Rate Thread

Default Permissions

 
 
Tom
Guest
Posts: n/a
 
      21st Jan 2004
On Windows 2000 / 2003 Server the default permissions on my C & D drives
include

Administrators
Domain User
Everyone

And a few others...

On a test server I have changed this to just Administrators & Domain Users
and allowed this to go through to all other folders.

Is this safe to do ??

With the default setting, IIS installed and running ASP, I can browse all
files on my hard disks, via the browser, using just a couple of simple asp
files... This is a big security risk..

With the changed settings, everything is fine !

Any Advice / comments ?

Thanks
 
Reply With Quote
 
 
 
 
Dave Patrick
Guest
Posts: n/a
 
      21st Jan 2004
Make sure that the System account (NT Authority) has full control of the
%systemdrive% and or the drive the pagefile is located on.

--
Regards,

Dave Patrick ....Please no email replies - reply in newsgroup.
Microsoft MVP [Windows NT/2000 Operating Systems]
http://www.microsoft.com/protect.

"Tom" wrote:
| On Windows 2000 / 2003 Server the default permissions on my C & D drives
| include
|
| Administrators
| Domain User
| Everyone
|
| And a few others...
|
| On a test server I have changed this to just Administrators & Domain Users
| and allowed this to go through to all other folders.
|
| Is this safe to do ??
|
| With the default setting, IIS installed and running ASP, I can browse all
| files on my hard disks, via the browser, using just a couple of simple
asp
| files... This is a big security risk..
|
| With the changed settings, everything is fine !
|
| Any Advice / comments ?
|
| Thanks


 
Reply With Quote
 
Tom
Guest
Posts: n/a
 
      21st Jan 2004
Thanks



On Wed, 21 Jan 2004 07:33:17 -0700, "Dave Patrick"
<(E-Mail Removed)> wrote:

>Make sure that the System account (NT Authority) has full control of the
>%systemdrive% and or the drive the pagefile is located on.


 
Reply With Quote
 
Steven L Umbach
Guest
Posts: n/a
 
      22nd Jan 2004
Yes, you may be able to get by with removing everyone. I would leave system
access as it is and be careful about modifying the \winnt folder which
already is fairly restricted. Running the IIS lockdown tool will also harden
a lot of folder/file permissions including setiing explicit deny permisions
to many sensitive files in the \winnt folder that could be used by an
attacker to compromise your server. --- Steve

http://support.microsoft.com/default...b;en-us;325864


"Tom" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> On Windows 2000 / 2003 Server the default permissions on my C & D drives
> include
>
> Administrators
> Domain User
> Everyone
>
> And a few others...
>
> On a test server I have changed this to just Administrators & Domain Users
> and allowed this to go through to all other folders.
>
> Is this safe to do ??
>
> With the default setting, IIS installed and running ASP, I can browse all
> files on my hard disks, via the browser, using just a couple of simple

asp
> files... This is a big security risk..
>
> With the changed settings, everything is fine !
>
> Any Advice / comments ?
>
> Thanks



 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
default permissions John Windows XP General 4 28th Aug 2007 12:25 PM
Set default permissions =?Utf-8?B?R2FyeQ==?= Microsoft Outlook Calendar 3 28th Sep 2006 02:55 PM
default permissions Sebastian Microsoft Outlook 2 4th Oct 2004 01:33 PM
default permissions on GPO Glenn M Microsoft Windows 2000 Group Policy 5 23rd Apr 2004 02:22 AM
Default Permissions Tom Microsoft Windows 2000 Security 3 22nd Jan 2004 03:17 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 01:22 PM.