Re: SharePoint Security



Sorry, I should've mention that I'm testing with WSS and using Firefox to
access the page.

"Steven Collier [MVP]" wrote:

> I think windows would still lock out the password after the given number of
> attempts ?
>
> The other option in to turn on Request Approval, after 3 goes they get
> directed to a page to request approval, sending a mail to the site owner.
>
> Steven
>
>
> On 12/4/05 20:32, in article
> DB1033F1-DC51-4100-A500-DB420BC38ACB@xxxxxxxxxxxxx, "Herbert"
> <Herbert@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
>
> > I don't know if this has been covered here before, I've tried to search but
> > no luck.
> >
> > I notice that a non-admin user can access
> > http://Sitename/_layouts/1033/settings.aspx page. Normal user cannot
> > access the links on that page, and will get prompted for username/password,
> > however, they can try as many times as possible. easy target for just a
> > brutal force attack. Why did MS implement this? Is there a way to block
> > non-admin users from seeing settings.aspx at all (ie. they won't even get
> > prompt for password and just display a 401)
> >
> > I'm planning on putting WSS as an internet site, it's not a very good idea
> > to let others see your site setting page.
> >
> > Thanks a lot.
>

.



Relevant Pages

  • Re: SharePoint Security
    ... I think windows would still lock out the password after the given number of ... > I notice that a non-admin user can access ... > prompt for password and just display a 401) ...
    (microsoft.public.sharepoint.portalserver)
  • Re: User Gets Login Prompt Even When Not Actively Using Sharepoint
    ... >login prompt comes up with the username already filled in. ... that 30 minute WSS timeout maybe why the prompt goes away after 30 ... > network connection is not in My Network Places it makes one. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: User Gets Login Prompt Even When Not Actively Using Sharepoint
    ... that 30 minute WSS timeout maybe why the prompt goes away after 30 ... The user does use WSS. ... network connection is not in My Network Places it makes one. ... > hasn't even tried to open a WSS site - if so how could it be a WSS problem? ...
    (microsoft.public.sharepoint.windowsservices)
  • User Gets Login Prompt Even When Not Actively Using Sharepoint
    ... The user is on Windows XP, Office 2003 and we use WSS. ... his LAN password he still gets the prompt continuosly for about 30 minutes. ... I'm thinking this prompt is caused by the network place link. ...
    (microsoft.public.sharepoint.windowsservices)
  • Re: Move Entire Windows Sharepoint Services to another server
    ... If WSS 2.0 you can use smigrate to move sites. ... Mike Walsh ... No matter what I typed in (Even using the Administrator username) it would prompt me again for it until I received the "Access Denied" message 401.1 Unauthorized: Access is denied due to invalid credentials. ...
    (microsoft.public.sharepoint.windowsservices)