Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Execute scripts permissions

Status
Not open for further replies.

madanthrax

IS-IT--Management
Sep 15, 2001
123
0
0
AT
Dear all,

I have a website running asp classic on a Win 2003 RE server. The server is centrally managed and I am not allowed to play with the IIS settings. I have a pure asp upload commercial component on my site and recently we were successfully attacked with an aspx file being placed on the server and executed. This was caught quickly but as ever the entry method has not been established yet. Of course fingers are being pointed at my module.

I have tried unsuccessfully to exploit the component may times in the past 4 or 5 years by avoiding the file type check and while no expert hacker I have come to trust it (fool). However during my visit to central I agreed to suspend file upload for a period and we sat down together to change the upload folder to read only. I then noticed in the IIS folder permissions that the execute (scripts?) box was ticked. I've been using web servers for a long time locally on my development notebooks but they were always using blanket admin rights setups to make anything possible. I said nothing at the time, but now I am asking you guys please to tell me if the aspx file could have run if the folder execute box was unticked?

regards,

Thanks for your help in advance.

[sub]"Nothing is impossible until proven otherwise"[/sub]​
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top