You are here: Re: PHP/IIS rights problem « PHP Language « IT news, forums, messages
Re: PHP/IIS rights problem

Posted by Hilarion on 11/14/05 19:26

>>> Am I right that this is a "rights" problem?
>>
>>Yes, this is probably a rights problem. Make sure that you granted
>>write access on this file to the IIS service account
>
> OK. Is there any security danger to doing this?


Yes and no. If you'll have some other app (also web-app) working
on the same account which is prone to user abuse*, then
this app will be able to overwrite the file in which case
you'll loose all the data and/or get your disc filled with some
crap.

* - If the app has some security holes (simple example is:
web-app allows user to point a server path to which their
uploaded file should go to).

If you check what uses same account and are sure that all those
apps are safe, and if you check all the web-apps working
on this IIS and are sure they are well-written and do not
allow access to this file, then there's no security risk
from allowing IIS account writing to this file.

You may try minimising the risks by creating dedicated account
for IIS with same privileges as the oryginal account and grant
write privileges on the file only to this dedicated account.
This way only IIS and it's web-apps are potential risk source.



Hilarion

 

Navigation:

[Reply to this message]


Удаленная работа для программистов  •  Как заработать на Google AdSense  •  England, UK  •  статьи на английском  •  PHP MySQL CMS Apache Oscommerce  •  Online Business Knowledge Base  •  DVD MP3 AVI MP4 players codecs conversion help
Home  •  Search  •  Site Map  •  Set as Homepage  •  Add to Favourites

Copyright © 2005-2006 Powered by Custom PHP Programming

Сайт изготовлен в Студии Валентина Петручека
изготовление и поддержка веб-сайтов, разработка программного обеспечения, поисковая оптимизация