Previous Next

Thread: IUSR account - Administrator rights?

Last post 04-19-2007 3:06 AM by qbernard. 2 replies.

Average Rating Rate It (5)

RSS

Page 1 of 1 (3 items)

Sort Posts:

  • 04-18-2007, 6:05 PM

    • subterfuge
    • Not Ranked
    • Joined on 04-18-2007, 10:02 PM
    • Posts 1
    • subterfuge

    IUSR account - Administrator rights?

    We had a .NET (1.1) application installed on a webserver by a third party on a Windows Server 2003 SP2 server.  What I've discovered is that in order to get their application to work properly, instead of tracking down all the permissions errors for their application, they made the ASPNET and IUSR account part of the local administrators group on the webserver.

    Is this ok?  Everything about this screams security risk, but I need some hard evidence that this is completely and totally wrong..

     

    Thanks

  • 04-19-2007, 2:12 AM In reply to

    • thomad
    • Top 25 Contributor
    • Joined on 08-20-2002, 3:28 PM
    • Redmond
    • Posts 387
    • thomad

    Re: IUSR account - Administrator rights?

    Subterfuge,

     You are absolutely right. This is a big security risk. They should try to figure out what permissions they need instead of making IUSR and ASPNET an administrator.

    Hope this helps

    Thomas Deml
    Senior Program Manager
    Internet Information Services
    Microsoft Corp.
  • 04-19-2007, 3:06 AM In reply to

    • qbernard
    • Top 10 Contributor
    • Joined on 03-25-2003, 10:12 PM
    • Malaysia
    • Posts 2,218
    • IIS MVPs
    • qbernard

    Re: IUSR account - Administrator rights?

    Get filemon/procmon to trace the access related issue.
    Cheers,
    Bernard Cheah
Page 1 of 1 (3 items)
Page view counter