Re: SharePoint Security

Tech-Archive recommends: Speed Up your PC by fixing your registry



Remove Site Settings in the site definition. That should accomplish what
you're after.

Bill English


"Herbert" <Herbert@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DB1033F1-DC51-4100-A500-DB420BC38ACB@xxxxxxxxxxxxxxxx
>I don't know if this has been covered here before, I've tried to search but
> no luck.
>
> I notice that a non-admin user can access
> http://Sitename/_layouts/1033/settings.aspx page. Normal user cannot
> access the links on that page, and will get prompted for
> username/password,
> however, they can try as many times as possible. easy target for just a
> brutal force attack. Why did MS implement this? Is there a way to block
> non-admin users from seeing settings.aspx at all (ie. they won't even get
> prompt for password and just display a 401)
>
> I'm planning on putting WSS as an internet site, it's not a very good
> idea
> to let others see your site setting page.
>
> Thanks a lot.


.



Relevant Pages

  • RE: Password prompt & Internal Web site
    ... On the screen with the error, yo will find directions to edit the ... web.config file associated with the website that you are trying to access. ... | name and password" prompt when I click on links "Create", "Site Settings", ...
    (microsoft.public.windows.server.sbs)
  • Password prompt & Internal Web site
    ... I'm at my wits end on this one, I've googled it to death, to no avail. ... name and password" prompt when I click on links "Create", "Site Settings", ... Web Site", when I click on "Manage Access" I get the same prompt, and It ...
    (microsoft.public.windows.server.sbs)
  • Re: Default Portal Access
    ... Additional Settings under Site Settings. ... Set Anon access there. ... > At the portal level I can't find an option to let ... >>Bill English ...
    (microsoft.public.sharepoint.portalserver)
  • RE: password protect "site settings"
    ... how do you get the "site settings" nav bar to prompt for a password before ... "tedteng" wrote: ... >> dave. ...
    (microsoft.public.sharepoint.portalserver)
  • Re: challenge for id/password issue - urgent
    ... Remove the link to Site Settings (or hide it behind an icon) so users won't ... > How can I set the prompt when the reader click the "Site ...
    (microsoft.public.sharepoint.windowsservices)