Re: User with blank password cannot login

From: Alun Jones [MSFT] (alunj_at_online.microsoft.com)
Date: 10/01/04


Date: Fri, 1 Oct 2004 16:01:01 -0700


"Alan Hellier" <Alan.Hellier@uhi.ac.uk> wrote in message
news:eLvHef8pEHA.596@TK2MSFTNGP11.phx.gbl...
> I've set up a Windows 2003 box with IIS 6 and i need to have a user with a
blank password to access the FTP site. For some reason which i can't figure
out, IIS 6 won't allow the user with the blank password to connect, but when
a password is added is does. This is really weird as the user with th blank
password logged in OK on my original W2K with IIS 5 box. Can anyone tell me
how to get this working?

This is by design - read the document at
http://www.microsoft.com/windowsserver2003/techinfo/overview/secinnovation.mspx
for a list of some of the security innovations that we have made in Windows
Server 2003 - one is that local users with blank passwords may not log on
remotely.

This can be changed by opening up the Local Security Policy, and under Local
Policies -> Security Options, you will find "Accounts: Limit local account
use of blank passwords to console logon only."

Needless to say, it's recommended that you keep the default setting, so that
non-anonymous access to your system is protected either by physical security
or a good password policy. If you have a need for public access to your
system, the "anonymous" FTP pseudo-user is a good method for doing this.

Alun.
~~~~



Relevant Pages

  • Re: very basic questions
    ... how does a firewall work with IIS? ... Multiple users upload to the FTP site. ... > My main security concerns are: ...
    (microsoft.public.inetserver.iis.security)
  • Trying to setup a FTP site in IIS 5
    ... I'm trying to create an FTP site in IIS 5 and I'm having some ... I've changed the FTP Site ... security. ... I changed the password multiple times so I know it's not the ...
    (microsoft.public.inetserver.iis.security)
  • Military Files Left Unprotected Online
    ... military and the wars in Iraq and Afghanistan, ... directly, citing troop security. ... agency's own server. ... a new secure ftp site ...
    (comp.dcom.telecom)
  • Military Files Left Unprotected Online
    ... facility in southern Iraq. ... citing troop security. ... agency's own server. ... unclassified file was on an FTP site that's not indexed by Internet search ...
    (misc.survivalism)
  • Re: Mac Server Hacked In Less Than 6 Hours
    ... Windows has RAS, and for it is built in since NT 3.1 ... | A typical IIS box and this Mac are not the same thing so the comparison ... IIS has been subject to quite a few bugs and so have ... Security isn't a proprietary attribute. ...
    (sci.crypt)