Welcome to MobyThreads.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in
All support for the MobyThreads Threaded phpBB MOD can now be found on welsolutions at this forum

Login allows everyone

 
   Web Hosting and Web Master Forums (Home) -> IIS RSS
Next:  FP 2002 Extensions vs Shared Point  
Author Message
newsgroup11

External


Since: Jun 19, 2004
Posts: 2



(Msg. 1) Posted: Sat Jun 19, 2004 11:36 pm
Post subject: Login allows everyone
Archived from groups: microsoft>public>inetserver>iis (more info?)

Eventually I'd like to be able to authenticate a list of users/passwords,
but I'll start with a single person.

I'm tried basic authentication and IWA, and the login window pops up with
both options. However, regardless of which authentication I try the user
can type anything in the login box and they are given access.

Any suggestions here please?
Thanks in advance.
Cliff

 >> Stay informed about: Login allows everyone 
Back to top
Login to vote
kenremove

External


Since: Aug 23, 2003
Posts: 2901



(Msg. 2) Posted: Sun Jun 20, 2004 11:39 pm
Post subject: Re: Login allows everyone [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi,

There are two "things" you need to be aware of:
a) authentication <- user needs to type in a valid Windows username/password
(anyone who types in something else does not get access)
-and-
b) authorisation <- user credentials supplied in (a) need to have permission
to perform the requested action (eg read a webpage).

So, if you just disable "Allow Anonymous Authentication", and enable Basic
or IWA, then anyone with a valid Windows account can still view the pages by
entering a valid windows username/password (on IIS 4 and IIS 5) because the
Everyone Windows group has Read (RX) NTFS permissions to all files in the
website (by default).

To prevent this, you need to adjust the NTFS permissions on the files in
question so that only users that you wish to allow access can read the
files.

For more info, grab the same chapter of my IIS 6.0 security book - there's a
link on my homepage: www.adopenstatic.com

Cheers
Ken


"Cliff" <newsgroup1.RemoveThis@NOSPAM.wiebe.ws> wrote in message
news:Xns950DE5FDACCFEnewsgroup1wiebews@207.46.248.16...
: Eventually I'd like to be able to authenticate a list of users/passwords,
: but I'll start with a single person.
:
: I'm tried basic authentication and IWA, and the login window pops up with
: both options. However, regardless of which authentication I try the user
: can type anything in the login box and they are given access.
:
: Any suggestions here please?
: Thanks in advance.
: Cliff

 >> Stay informed about: Login allows everyone 
Back to top
Login to vote
newsgroup11

External


Since: Jun 19, 2004
Posts: 2



(Msg. 3) Posted: Sun Jun 20, 2004 11:39 pm
Post subject: Re: Login allows everyone [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Ken Schaefer" <kenREMOVE.RemoveThis@THISadOpenStatic.com> wrote in
news:ekXhHLrVEHA.3596@tk2msftngp13.phx.gbl:

 > Hi,
 >
 > There are two "things" you need to be aware of:
 > a) authentication <- user needs to type in a valid Windows
 > username/password (anyone who types in something else does not get
 > access)
 > -and-
 > b) authorisation <- user credentials supplied in (a) need to have
 > permission to perform the requested action (eg read a webpage).
 >
 > So, if you just disable "Allow Anonymous Authentication", and enable
 > Basic or IWA, then anyone with a valid Windows account can still view
 > the pages by entering a valid windows username/password (on IIS 4 and
 > IIS 5) because the Everyone Windows group has Read (RX) NTFS
 > permissions to all files in the website (by default).
 >
 > To prevent this, you need to adjust the NTFS permissions on the files
 > in question so that only users that you wish to allow access can read
 > the files.
 >
 > For more info, grab the same chapter of my IIS 6.0 security book -
<font color=purple> > there's a link on my homepage: <a style='text-decoration: underline;' href="http://www.adopenstatic.com</font" target="_blank">www.adopenstatic.com</font</a>>
 >
 > Cheers
 > Ken
 >
 >
Well, when you put it like that Ken, it all makes sense! Thanks Ken!
I'll definitely take you up on the offer of the chapter of your book.<!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Login allows everyone 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
ASP.NET Login - Hi, I am using a basic asp.net login script that uses cookies. It is from a tutorial on the www.asp.net site and I am also trying the community starter kit from the same site. I have it on my windows 2000 server running IIS both these systems login fine....

IIS Login box - I hope someone can help me in this site. I have been searching for this answer all over the net. I have used Interegated windows security in one of my websites. It is working just fine. But in the login box it is showing the server IP number as a site..

FTP Login - On NT4-Server, IIS, FTP service... I setup an access dir, User ID, PW, but I cannot login. Upon login, I get an error message indicating... "Could not receive the directory listing". I am using "EditPlus", a text editor that I u...

Login Problem - Setup: Pentium4/2.4/512MB RAM Win2003 Web Server/IIS6 ISA Server 2000 Enterprise Edition Part of my site is private and uses are challenged for a login. Most IE users receive the challenge and are able to access the private areas of the site. However...

Anoymous login - Hi guys, Im running Windows 2003 Standard version at home. Im trying setup the IIS 6. What I dont understand is, when I enable Anoymous login, I still prompt for user name and password. I know in IIS5, it doesnt do that. I know this probably is a....
   Web Hosting and Web Master Forums (Home) -> IIS All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]