The scope of Everyone, Auth Users and IUSR_Machine accounts
Web Server forum
Back To The Forum Home!Search!Private Messaging System

Web Server Talk Web Server Talk > Web Servers reviews > IIS server support > IIS Server Security > The scope of Everyone, Auth Users and IUSR_Machine accounts




  Last Thread   Next Thread Next
  Show Printable Version Email this Page Subscribe to this Thread      Post New Thread    Post A Reply      

    The scope of Everyone, Auth Users and IUSR_Machine accounts  
FB


View Ip Address Report This Message To A Moderator Edit/Delete Message


 
08-23-05 10:56 PM

I´m testing a web site hosted on a Win2003 machine with diverse content (as
p,
htm, pdf, etc) and i´m confused about certain concepts on authenticationa a
nd
authorization access.

i have a folder with ZIPs and ASP pages and ONLY Anonymous access enabled.
i have made several tests, changing NTFS permissions (IIS permissions is
always as Read) and the results were strange.

IUSR_ and Users group have Logon Locally Right and Let Everyone Permissions
Apply to Anonymous is on default (Disabled)

If IUSR_MAchine is anonymous user, access have to be denied when ONLY
Everyone or Users is permitted on ACLs. Is it right?

The tests i´ve made with RX permissions on NTFS Folder´s ACL

 ========================================
=====
ACL on folder         ACTION
RESULT
 ========================================
=====
Everyone               Get zip file and process ASP page             OK and 
OK
Auth Users            Get zip file and process ASP page             OK and O
K
IUSR_Machine       Get zip file and process ASP page             OK and OK
Users                   Get zip file and process ASP page             OK and
OK
ASPNET               Get zip file and process ASP page             401.3 and
401.5
SYSTEM only        Get zip file and process ASP page             401.3 and
401.5
 ========================================
=====

If IUSR_Machine user is a nonymous user, why NTFS´s ACLs with Auth USers or
Everyone we have normal access? If IUSR_Machine user is accessing the web
page, why it can access even without proper NTFS permissions?













[ Post a follow-up to this message ]



    Sponsored Links  




 





   All times are GMT. The time now is 12:42 AM.      Post New Thread    Post A Reply      
  Last Thread   Next Thread Next


Most Popular forums 

Forum Jump:
Rate This Thread:

Forum Rules:
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is OFF
vB code is ON
Smilies are ON
[IMG] code is OFF
 
Medical and Health forum | Computer Games Reviews | Graphics design forum

Back To The Top
Home | Usercp | Faq | Register