WordPress on IIS7.5 Recommended Permissions [Answered]RSS

1 reply

Last post Jun 06, 2011 10:58 PM by HCamper

  • WordPress on IIS7.5 Recommended Permissions

    Jun 06, 2011 06:46 PM|John Kisha|LINK

    I have searched the forum and Google and really couldn't find anything definitive on the minimum permissions needed for WordPress to do automatic updates and not create a security problem on the server. From my reading, I found someone that suggested granting write permissions to "everyone" account and then denying write access specifically to IIS_IUSERS account. This seems to have worked for the automatic updates, but I'm not so happy with the everyone account having write access. Anybody have any thoughts on this, or know a better solution? Thanks, John

    Permissions wordpress

  • Re: WordPress on IIS7.5 Recommended Permissions

    Jun 06, 2011 10:58 PM|HCamper|LINK

    Hello,

    Yes, A search for security and permissions on the Web for Web Servers and in particular IIS Servers can lead to conflicting suggestions.

    The IIS Net library guides for security for IIS Server contain the recommended configuration of permissions for accounts and users.

    The IIS Net library guides are here http://learn.iis.net/page.aspx/140/understanding-built-in-user-and-group-accounts-in-iis-7/ 

    Users and Accounts http://learn.iis.net/page.aspx/583/secure-content-in-iis-through-file-system-acls/ System Account Contol.

    You may also find a video presentation by

    Scott Forsyth http://weblogs.asp.net/owscott/archive/2011/06/06/securing-iis-thwarting-the-hacker-week-23.aspx .

    Helps to explain the operations of users identify and IIS Server security.

    I agree the idea of using the "Everyone" is not a good choice. I suggest that you not use "Everyone" Group in Word Press Web Sites..

    For general  permissions that are Word Press you can use the IUSR and IIS_IUSRS and use standard permissions

    of read,execute,list for most of the Word Press pages.

    If the Word Press directories that require writing or updating ie Plugins / Download add the write permssions for the IUSR and IIS_IUSRS.

    Hope this helps,

    Martin

     

     

     

    Windows and Linux work Together IT-Pros
    Community Member Award 2011