IIS Server Security - IIS Virtual Directory Hacks

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > May 2006 > IIS Virtual Directory Hacks





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author IIS Virtual Directory Hacks
jonathan haughey

2006-05-22, 7:15 am

I am publishing a web application in asp that will allow my users to access
a sql database, each user will have a virtual directory that will give them
an interface to access their respective database.

My worry is that they will be able to access each others virtual directories
and hence modify the respective database.

I want to test the application and ensure that users cannot access each
others virtual directories and databases.

I have already tested that they cannot insert the name of another users
virtual directory followed by a file name, that they can find out from their
own virtual directory.

The users have no access to the IIS server apart from via their Virtual
directory. I need to secure this application and make it water tight.

I am looking for some suggestions for how to possibly hack another users
virtual directory.

Any help here would be greatly appreciated.

Many thanks in advance.


Jeff Cochran

2006-05-22, 7:15 am

On Mon, 22 May 2006 12:02:38 +0100, "jonathan haughey"
<jonathan.haughey@shesoftware.com> wrote:

>I am publishing a web application in asp that will allow my users to access
>a sql database, each user will have a virtual directory that will give them
>an interface to access their respective database.
>
>My worry is that they will be able to access each others virtual directories
>and hence modify the respective database.
>
>I want to test the application and ensure that users cannot access each
>others virtual directories and databases.
>
>I have already tested that they cannot insert the name of another users
>virtual directory followed by a file name, that they can find out from their
>own virtual directory.
>
>The users have no access to the IIS server apart from via their Virtual
>directory. I need to secure this application and make it water tight.
>
>I am looking for some suggestions for how to possibly hack another users
>virtual directory.
>
>Any help here would be greatly appreciated.
>
>Many thanks in advance.


Lock them down with NTFS permissions.

Jeff
Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com