IUSR_ and IWAM_ with admin privileges

IUSR_ and IWAM_ with admin privileges

am 26.01.2007 18:12:00 von Nicee

An application has been purchased that requires the IUSR_ and IWAM_ accounts
be placed in the local administrators group in order for the application to
work.

Could you please detail the security risks?

Re: IUSR_ and IWAM_ with admin privileges

am 28.01.2007 09:32:29 von Ken Schaefer

It means that if someone can get your web application to something
unintended (e.g. there is a bug in the application), then the attacker can
take control of your entire server.

Alternatively, if an attacker can get your IWAM or IUSR users to run some
code (e.g. by uploading a webpage, and then requesting it) then they have
full control over your server as well.

Cheers
Ken

"Nicee" wrote in message
news:B15C5AC5-F71D-4124-8C15-767C8840A2D3@microsoft.com...
> An application has been purchased that requires the IUSR_ and IWAM_
> accounts
> be placed in the local administrators group in order for the application
> to
> work.
>
> Could you please detail the security risks?

Re: IUSR_ and IWAM_ with admin privileges

am 29.01.2007 04:00:17 von Roger Abell

"Nicee" wrote in message
news:B15C5AC5-F71D-4124-8C15-767C8840A2D3@microsoft.com...
> An application has been purchased that requires the IUSR_ and IWAM_
> accounts
> be placed in the local administrators group in order for the application
> to
> work.
>
> Could you please detail the security risks?

Absurd. The risks are total for that machine, or
worse if installed on a DC (ex. SBS server).

I hope they did not ask for money in exchange !!