IUSR_ and IWAM_ with admin privileges

An application has been purchased that requires the IUSR_ and IWAM_ accounts
be placed in the local administrators group in order for the application to
work.

Could you please detail the security risks?
Nicee [ Fr, 26 Januar 2007 18:12 ] [ ID #1609339 ]

Re: IUSR_ and IWAM_ with admin privileges

It means that if someone can get your web application to something
unintended (e.g. there is a bug in the application), then the attacker can
take control of your entire server.

Alternatively, if an attacker can get your IWAM or IUSR users to run some
code (e.g. by uploading a webpage, and then requesting it) then they have
full control over your server as well.

Cheers
Ken

"Nicee" <Nicee [at] discussions.microsoft.com> wrote in message
news:B15C5AC5-F71D-4124-8C15-767C8840A2D3 [at] microsoft.com...
> An application has been purchased that requires the IUSR_ and IWAM_
> accounts
> be placed in the local administrators group in order for the application
> to
> work.
>
> Could you please detail the security risks?
Ken Schaefer [ So, 28 Januar 2007 09:32 ] [ ID #1610899 ]

Re: IUSR_ and IWAM_ with admin privileges

"Nicee" <Nicee [at] discussions.microsoft.com> wrote in message
news:B15C5AC5-F71D-4124-8C15-767C8840A2D3 [at] microsoft.com...
> An application has been purchased that requires the IUSR_ and IWAM_
> accounts
> be placed in the local administrators group in order for the application
> to
> work.
>
> Could you please detail the security risks?

Absurd. The risks are total for that machine, or
worse if installed on a DC (ex. SBS server).

I hope they did not ask for money in exchange !!
Roger Abell [ Mo, 29 Januar 2007 04:00 ] [ ID #1610906 ]
Webserver » microsoft.public.inetserver.iis.security » IUSR_ and IWAM_ with admin privileges

Vorheriges Thema: access from internet/intranet
Nächstes Thema: Windows 2003 server and web sharing