Re: IIS 6 FTP Security

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 07/10/04


Date: Sat, 10 Jul 2004 04:39:51 GMT

On Thu, 8 Jul 2004 12:55:05 -0700, "Brian Allen"
<anonymous@discussions.microsoft.com> wrote:

>I work for an web hosting company, and I am currently
>converting from NT4 to 2003. I have already set up a good
>handful of websites on the 2003 servers. All these
>websites have FrontPage and FTP access. The folders
>permissions are all set properly to my knowledge. The
>problem is that with the FTP sites, any user in my Active
>Directory has access to any FTP site that I have set up,
>even though they don't have folder permission. I even
>created a new user, who had access to nothing at all, and
>it was able to access the FTP sites. I've been reading
>about user isolation from links on the boards here, but I
>don't think that's what I need... I just want the FTP
>servers to use the folder permissions, or just be able to
>grant access to certain users within the AD domain (Like
>IIS 4 allowed you to specify users). Any help into this
>would be much appreciated.

You want user isolation. Specifically, AD User Isolation mode. The
reason it exists is to do what you want done.

Maybe look at:

HOW TO: Set Up an FTP Server in Windows Server 2003
http://support.microsoft.com/default.aspx?scid=kb;en-us;323384

How To Set Up an FTP Site So That Users Log Onto Their Folders:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;201771

HOW TO: Create a Secure FTP Directory that Uses Password
Authentication:
http://support.microsoft.com/?id=239120

Jeff



Relevant Pages

  • iis6 ftp permissions
    ... I have a problem with permissions. ... I'm trying to set up iis6 ftp on w2k3 so that ftp ... And to do this, following the backdoor folders trick, I have set up ... The root then has two virtual directories: ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: MGET command deletes files
    ... > I then ftp. ... > open the ftp log file, no sent /file.txt 226 was recorded. ... > Can you double check and ensure the user doesn't have any permissions on ... >> There is a file in both folders with the same name. ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: ftp secured access
    ... Refer ... Create an FTP Folder with Read Access but Not List Access ... > allow the folders which a user has permissions to view, ...
    (microsoft.public.inetserver.iis.security)
  • Re: iis6 ftp permissions
    ... of those website folders. ... > I have a problem with permissions. ... > is a many-to-many relationship between the ftp users and web sites. ... > and each of these virtual directories have two sub virtual directories ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: FTP Permissions
    ... I'm not sure on this but make sure your folders have the right permissions ... at the upper levels. ... AD users have NTFS permissions to where the FTP site points to. ...
    (microsoft.public.inetserver.iis.ftp)