Re: Limited account has access to everything with FTP



If you are connecting via FTP protocol, don't think you will see all hard
drivers. So, I'm guess your IE is acting like windows explorer. Now, try to
connect remotely or using command prompt ftp.exe

c:\> ftp yourserverip

you should see ftp banner msgs, login prompt, after login, try do a dir
listing...... does it works ?

--
Regards,
Bernard Cheah
http://www.microsoft.com/iis/
http://www.iiswebcastseries.com/
http://www.msmvps.com/bernard/


"Dave Neve" <NoAddressForSpammers@xxxxxxx> wrote in message
news:uG77zXIZFHA.2884@xxxxxxxxxxxxxxxxxxxxxxx
> Hi
>
> I hadn't done this but I was definately logged on with a special name (x)
> that had nothing to do with my administrators account.
>
> There is one folder (y) to which (x) has authorisation.
>
> (y) is the default opening folder and everything goes ok but when I click
> on 'files' in IE, explorer shows all my drives etc on the left of IE.
>
> Needless to say, I can then access them.
>
> I've now disabled 'anonymous' access and the problem still remains.
>
> Is this cos I am running the test on my own computer?
>
> I am logged on as administrator but accessing FTP with account name 'x'?
>
> Thanks in advance
>
> Dave Neve
>
>
> "Cari (MS-MVP)" <Newsgroups1@xxxxxxxxxxxxxx> a écrit dans le message de
> news: u58bZwHZFHA.3220@xxxxxxxxxxxxxxxxxxxxxxx
>> Did you disable Anonymous User Access?
>> --
>> Cari
>> (MS-MVP Printing & Imaging)
>>
>> "Dave Neve" <NoAddressForSpammers@xxxxxxx> wrote in message
>> news:utNgjgBZFHA.3364@xxxxxxxxxxxxxxxxxxxxxxx
>>> Hi
>>>
>>> I'm still trying to set up my FTP server.
>>>
>>> I was accessing it using my administrators account and I noticed that I
>>> could go open up any file on my computer which I felt was risky.
>>>
>>> So I created a new limited account and 'attributed' it to the root
>>> default folder (the one that is first opened up when I use FTP)
>>>
>>> But with 'explorer', this limited account has as much access as the
>>> administrators account before.
>>>
>>> How can I limit the account to one folder and its subfolders only?
>>>
>>> Thanks in advance
>>>
>>> Dave Neve
>>>
>>>
>>>
>>
>>
>>
>
>


.



Relevant Pages

  • RE: FTP Accounts
    ... Create the new account, give them NTFS access to the ftproot folder and any ... when they first logon to the FTP server. ... | Content-Class: urn:content-classes:message ...
    (microsoft.public.inetserver.iis.security)
  • Separate Anonymous Access User to prevent FTP browsing?
    ... I have several virtual webs running in the same FTP root folder. ... With this setup, a user can authenticate with their FTP account, browse from ... - Point the WWW virtual web at that same folder. ...
    (microsoft.public.inetserver.iis)
  • Re: Windows 2003 Error need help
    ... A 3rd party FTP may be more secure. ... First you would want to rename your AD administrator account to something else, then create an administrator account in the domain, but only leave it in the Guest group, then disable the account. ... Thn create a user account on ServU called "administrator" on ServU, leave the password blank, create ab empty folder, then configure the administrator user account you created to use this emtpy folder as its home folder, then configure permissions to only Read. ...
    (microsoft.public.windows.server.networking)
  • Re: My FTP access is very unsecure - advice requested
    ... Do you have security set at the folder level for each user's folder? ... >> search random IP addresses for FTP servers that are open to abuse. ... >> because that account exists to allow anonymous logons to proceed. ... >> There are secure FTP servers available for even less than that - I'm ...
    (microsoft.public.inetserver.iis.ftp)
  • RE: Confused about FTP for IIS7 authorization
    ... ACL list includes your test account and that's why you can login without ... them are with allowed rules in FTP authorization. ... Microsoft Online Community Support ...
    (microsoft.public.inetserver.iis.ftp)

Loading