IIS Server Security - iusr permissions inhertited from where in IIS6?

This is Interesting: Free IT Magazines  
Home > Archive > IIS Server Security > March 2007 > iusr permissions inhertited from where in IIS6?





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author iusr permissions inhertited from where in IIS6?
mike.varley1@ntlworld.com

2007-03-15, 7:23 am

Hi

Win2k3 Server Std with sp1\IIS6.

We have just done an IIS install and are getting 401.3 Unauthorized
errors on the default website. On inspection the iusr account has no
effective permissions on the wwwroot folder. Looking at other IIS
installations that work ok iusr has:

Traverse Folder\Execute File
List Folder\Read Data
Read Attributes
Read Extended Attributes
Read Permissions

on wwwroot. The problem is that I cannot see where it gets these
permissions from. I have looked up through inetpub to c:\ and the only
explicit assignment I can see for iusr is deny write on wwwroot. The
other explicit assignments appear to be the same between the working
and non-working systems. Additionally iusr is only a memeber of
'Guests' which has no explicit assignments.

I can see a 'read and execute' assignment for Everyone to c:\ but
this is set to 'This folder only'.

Can anyone shed any llight on this...where does iusr inherit its
permissions from? Also why might this installation have failed in this
way. The install was done using a domain account that is a member of
the local admins group.

Thanks for you help

Mike

Ken Schaefer

2007-03-16, 1:26 am

Hi,

You can look in iis6 setup log to see if there are any indications of
failures to set ACLs properly.

In terms of default permissions both the IIS_WPG group, and the
IUSR_<machinename> account should have Read/Execute permissions specified at
the c:\inetpub\wwwroot level

Cheers
Ken

<mike.varley1@ntlworld.com> wrote in message
news:1173957457.279274.27100@y66g2000hsf.googlegroups.com...
> Hi
>
> Win2k3 Server Std with sp1\IIS6.
>
> We have just done an IIS install and are getting 401.3 Unauthorized
> errors on the default website. On inspection the iusr account has no
> effective permissions on the wwwroot folder. Looking at other IIS
> installations that work ok iusr has:
>
> Traverse Folder\Execute File
> List Folder\Read Data
> Read Attributes
> Read Extended Attributes
> Read Permissions
>
> on wwwroot. The problem is that I cannot see where it gets these
> permissions from. I have looked up through inetpub to c:\ and the only
> explicit assignment I can see for iusr is deny write on wwwroot. The
> other explicit assignments appear to be the same between the working
> and non-working systems. Additionally iusr is only a memeber of
> 'Guests' which has no explicit assignments.
>
> I can see a 'read and execute' assignment for Everyone to c:\ but
> this is set to 'This folder only'.
>
> Can anyone shed any llight on this...where does iusr inherit its
> permissions from? Also why might this installation have failed in this
> way. The install was done using a domain account that is a member of
> the local admins group.
>
> Thanks for you help
>
> Mike
>


Sponsored Links






Free braindumps | Software forum | Database administration forum

Copyright 2003 - 2008 webservertalk.com