Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

NT Using ASP And FSO To Read Server Files Vulnerability

Solution:
Joel Maslak <jmaslak@WIND-RIVER.COM> suggests Applying appropriate NTFS permissions to limit the access to given to the IUSR_machinename account. For multiple virtual web servers, run each virtual server under a different user account.

Russ Cooper <Russ.Cooper@RC.ON.CA> recommends disabling the "Allow Parent Paths" option via Internet Services Manager.








 

Privacy Statement
Copyright 2009, SecurityFocus