RE: Restrict FileSystemObject to it's virtual dir

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: FKeller (FKeller_at_discussions.microsoft.com)
Date: 10/26/04


Date: Mon, 25 Oct 2004 17:59:04 -0700

Hello Dallo

I wonder if you got it to work with the desired security?

I did see that there is a very ingenious ASP-script going around. Even on
big providers you can go with it to all drives, even C:\WINNT and \SYSTEM32
and read, change, delete or upload whatever you want. So as I did see even
big providers have not the needed security and are in danger. How did you
implement the security that users cannot go out of there root? Hackers event
use file upload possibilities in websites to upload the tool and use it then.

Thanks for help,

Fritz Keller

"Dallo" wrote:

> Hi everybody,
> i've to configure on a single win2003 machine a lot dinamic web site.
> I'd like to protect each site from interference of other sites scripts that
> uses, for example, filesystemobject method.
> In other words, i dont want asp script using FSO of a site can access,
> modify or delete files on other sites.
> Is there a way to restrict FSO to it's virtual directory?
>
>
> tnx to everyone
> :)
>
>
>



Relevant Pages

  • Re: File Upload - Security Issues
    ... You want to upload a file for what reason and ... these viruses have less chance of being able to execute (even if succeeded ... :> file and what pitfalls you see re: security might be helpful on this ... :>: files to an IIS server that doesn't have MS Office actually installed? ...
    (microsoft.public.scripting.vbscript)
  • Re: File Upload - Security Issues
    ... uploaded and the user could upload any or all of these in theory. ... There is no one product that can give you 100% security, ... > Code doesn't execute in local memory space unless remote user has rights ... > You don't have MS Office installed on the server. ...
    (microsoft.public.scripting.vbscript)
  • Re: File Upload - Security Issues
    ... You want to upload a file for what reason and you do ... file and what pitfalls you see re: security might be helpful on this end?! ... files to an IIS server that doesn't have MS Office actually installed? ... 2* Upon submit this is submitted to an ASP page that then (using the XML ...
    (microsoft.public.scripting.vbscript)
  • [NT] Why Pressing CTRL in IE is Dangerous
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... hidden file upload form. ... The upload form is submitted automatically (legal JavaScript ... side script to take care of the upload process. ...
    (Securiteam)
  • RE: Restrict FileSystemObject to its virtual dir
    ... big providers have not the needed security and are in danger. ... use file upload possibilities in websites to upload the tool and use it then. ... > I'd like to protect each site from interference of other sites scripts that ... > Is there a way to restrict FSO to it's virtual directory? ...
    (microsoft.public.inetserver.iis)