Re: Upload folder permissions

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Kristofer Gafvert (kgafvert_at_NEWSilopia.com)
Date: 01/13/05


Date: Thu, 13 Jan 2005 11:12:45 -0800

Hello,

Make sure that "Execute Permissions" are set to None. Then scripts and
executables will not run.

-- 
Regards,
Kristofer Gafvert
www.gafvert.info - My articles and help
www.ilopia.com
Ray wrote:
> Hi
>
> I am running a website with a classifieds section on it that allows 
users to
> post ads and upload an image for the ad.
>
> The problem is that the site was hacked this weekend by Team_Evil through
> this image folder whereby they managed to upload code to it and execute 
it
> resulting in my whole site being defaced.
>
> My script does a check on the file extension to verify that it is of an
> image type before the form posts and allows the upload.
>
> Is there anyway to setup permissions on the image folder whereby people 
can
> still upload images and that the images be deleted when the ad is deleted
> but no asp scripts can be executed from this folder incase they get by 
the
> extension checking again? All the scripts make use of FSO to upload and
> delete the images..
>
> Any guidelines and assistance will be appreciated.
>
> Thanks
> Ray


Relevant Pages

  • Re: File Upload - Security Issues
    ... uploaded and the user could upload any or all of these in theory. ... There is no one product that can give you 100% security, ... > Code doesn't execute in local memory space unless remote user has rights ... > You don't have MS Office installed on the server. ...
    (microsoft.public.scripting.vbscript)
  • Re: Problem with IIS 6.0 serving .NET applications
    ... It's working now because you need to have "scripts and executable" ... > to "None" and I'd get the content of the exe shown in the browser, ... >> Did you set Application & Scripts execute permissions? ... >>> execute permission on that Virutal Directory, ...
    (microsoft.public.inetserver.iis.security)
  • Re: HTTP 403.1 Forbidden: Execute Access Forbidden
    ... This sounds like an Visual InterDev behavior/requirement -- I really have no ... execute ASP script, you MUST have the "Scripts" execute permission [so ... scripts and executables is not necessary to run the default.asp page]). ... IIS is merely doing what you configured. ...
    (microsoft.public.inetserver.iis)
  • Re: PERL WEB PROGRESS BAR
    ... >I am doing little CGI scripts. ... You can setup a javascript indicator for your upload ... which shares the bandwidth with the upload. ...
    (comp.lang.perl.misc)
  • Re: That stupid cant execute error is driving me insane
    ... This error comes up when the vdir does not have "Scripts" or "Scripts and ... Executables" Execute Permission and you try to access a URL that is either ... Here is a simplistic view of how IIS does request processing: ... If the mapping is dynamic, then IIS decide whether the URL should be ...
    (microsoft.public.inetserver.iis)