Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IUSR & IWAM Accounts

Status
Not open for further replies.

skialta

MIS
Apr 5, 2005
244
US
My company is very security conscious and we are trying to determine if the passwords should be changed for the IUSR & IWAM accounts on all of our IIS boxes. Can you please give your 2 cents and if possible provide links to sites that can support the best practice. Thanks!
 
Thanks Niksen, what about the IUSR account? That is a different account for running the IIS service itself unless I'm mistaken.
 
actually, as anonymous access to the server is not allowed, the IUSR_computername account was made to impersonate the anonymous user (which a public webserver by nature get loads of)
webservice runs on "system" account which is a secure account which can't be used for anything than run stuff locally. noone can connect with system from outside.
You can actually remove ntfs permissions on the homefolders and still run the webserver. You will then get these red marks in IIS manager because it cannot read in the folders, but it will still serve pages as the IUSR can read the files.

overall i would say, if youre running win2k remember to lock IIS down with iislockdown tool, in win2k3 IIS is locked down from out of the box.then control the rest with ntfs settings.

brgds Nicolai
 
Thanks again, for the clarification...do you know of any links, preferably Microsoft's site?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top