Deny Account FTP Access



W2003 Web Edition / IIS6 / Default FTP site / Guest account disabled

I have had to add another user account to the server to secure access for
certain web pages. The new user is not a member of any group and only has
read pemissions on a single directory well under the ftproot.

Suprisingly, although the new user has no effective permissions at the
ftproot level, they are still able to login and browse the full FTP
directory stucture using their username and password. Anonyomous access is
turned off. I can explicitly deny the new user access to the FTP root which
then prevents FTP logon, but surely this isn't the correct way to do this?
With no permissions at the ftproot level users shouldn't be able to logon.

Which account privileges are they assuming when they logon?

Peter


.



Relevant Pages

  • FTP: User must change password at next logon?
    ... I created a user account for FTP access--leaving 'User ... Must Change Password at next Logon" box checked. ...
    (microsoft.public.win2000.security)
  • Re: Limited Access
    ... For users that you want to logon to a computer via Remote Desktop you need ... Remote Desktop Users group. ... sharing to the computer not impeded by a firewall and the user account also ... On my desktop and wired laptop the hard drives are ...
    (microsoft.public.windowsxp.security_admin)
  • Re: GC Question
    ... The Domain and Forest Level are in 2003 ... Then i started up only the Dc for Child domain ... logon on that domain including in the Domain Controller for that Domain, ... When I try to create the user account "User01" I received the following ...
    (microsoft.public.win2000.active_directory)
  • Re: SBS re-connection
    ... I understand that you can not logon domain again ... Do you mean the issue disappeared if you delete the user account on ... >This newsgroup only focuses on SBS technical issues. ... you may want to contact Microsoft CSS directly. ...
    (microsoft.public.windows.server.sbs)
  • FTP User Account Access failure after Promotion to PDC ??
    ... FTP User Account Access failure after Promotion to PDC ?? ... Is there a bug in FTPSVC authentication after a promotion to PDC? ... If under Internet Authentication Service we set up in Remote Access ...
    (NT-Bugtraq)

Quantcast