Click here to get back home

ASPNET Account autiding alert

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
ASPNET Account autiding alert M. Simioni 07-12-2005
Get Chitika Premium
Posted by Roger Abell on July 12, 2005, 11:49 pm
Please log in for more thread options
Well, they should not be able to write to c:\winnt at all !!
When you look at one of these in c:\winnt are the NTFS permissions
on it all inherited or are some or all explicit ? i.e. gray or white boxes?

That dir name makes it sound like this was upgrade to W2k from NT4,
which would leave c:\winnt permissioned loose.
I would be the villan and first notify my web authors that use
crystal that c:\winnt will be altered and there apps will fail
if they do not use the temp environment var to locate their
file usage correctly, and I would set an implementation date
and hold to it. When that date comes you will find out who
is responsible. The alternative, of trying to loosening c:\winnt
permissions, if it is not an explicitly set permissions issue, so
that inherited permissions are sufficient is not an attractive
way to go.

--
Roger Abell
Microsoft MVP (Windows Security)
MCSE (W2k3,W2k,Nt4) MCDBA
> The ASPNET account has R/W access to
> "C:\WINNT\Microsoft.NET\Framework\v1.0.3705\Temporary ASP.NET Files" and
> "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files" ( no
> FULL CONTROL, only Modify+Read+Write, it's ok? ).
>
> The aspnet_wp process is running under the ASPNET account.
>
> The aspnet_wp process i using 195MB of memory, with a peak of 312MB.
> With a process viewer i can see it has abount 22 threads (nearly all of
them
> regarding mscorsvr.dll).
>
> Marco.
>
> > This sounds a lot like an attempt to get at the Temporary ASP.NET Pages
> > cache directory. Are you running the ASP.NET worker process as a
different
> > account that perhaps doesn't have access to the proper directories?
> >
> > -- Sean M, who admittedly is not fond of changing the identity of the
> > worker
> > process
> >
> >> i forgot to say, the name KOSW047BFJNQUY26 changes every time.
> >>
> >> i still don't know who try to create that directory/file and when.
> >> i didn't write the applications by myself, i only know that thy use
> > Crystal
> >> Reports, they're written in .NET 2002 and they use a component to draw
> >> charts, dunno if it is that particular component that tryes to write
the
> >> directory/file. at least, the programmer said me that he doesn't
> > explicitly
> >> create it.
> >>
> >> how can i see if it is being created with explicit permission or other
> > grant
> >> ? i can't even find that directory.
> >>
> >> thank you,
> >> Marco
> >>
> >>
> >>
> >> > Marco,
> >> >
> >> > C:\WINNT\KOSW047BFJNQUY26 appears to be some temporary
> >> > directory ?? Is it being created with explicit permissions that will
> >> > exclude Users or other grant that includes Dir List for AspNet ?
> >> >
> >>
> >
> >
>
>




Posted by M. Simioni on July 13, 2005, 5:39 pm
Please log in for more thread options
I can't see that items.
That directory (or files?) with the random name doesn't even seem to exists,
or at least i'm not able to see them, so i can't see the protection
settings.

The "Users" group has read only access to WINNT directory.

Why is the protection event talks about READ/SYNCRONIZE deny, if the Users
( and then the ASPNET account too) has read grants on the WINNT directory?

I don't think the programmers are creating a file in it, i talked with them
and nobody has written code to create a file/directory in C:\WINNT, or at
least we don't know if Crystal Report tryes to.

thanks for the help,
Marco


> Well, they should not be able to write to c:\winnt at all !!
> When you look at one of these in c:\winnt are the NTFS permissions
> on it all inherited or are some or all explicit ? i.e. gray or white
> boxes?
>
> That dir name makes it sound like this was upgrade to W2k from NT4,
> which would leave c:\winnt permissioned loose.
> I would be the villan and first notify my web authors that use
> crystal that c:\winnt will be altered and there apps will fail
> if they do not use the temp environment var to locate their
> file usage correctly, and I would set an implementation date
> and hold to it. When that date comes you will find out who
> is responsible. The alternative, of trying to loosening c:\winnt
> permissions, if it is not an explicitly set permissions issue, so
> that inherited permissions are sufficient is not an attractive
> way to go.
>
> --
> Roger Abell
> Microsoft MVP (Windows Security)
> MCSE (W2k3,W2k,Nt4) MCDBA
>> The ASPNET account has R/W access to
>> "C:\WINNT\Microsoft.NET\Framework\v1.0.3705\Temporary ASP.NET Files" and
>> "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files" ( no
>> FULL CONTROL, only Modify+Read+Write, it's ok? ).
>>
>> The aspnet_wp process is running under the ASPNET account.
>>
>> The aspnet_wp process i using 195MB of memory, with a peak of 312MB.
>> With a process viewer i can see it has abount 22 threads (nearly all of
> them
>> regarding mscorsvr.dll).
>>
>> Marco.
>>
>> > This sounds a lot like an attempt to get at the Temporary ASP.NET Pages
>> > cache directory. Are you running the ASP.NET worker process as a
> different
>> > account that perhaps doesn't have access to the proper directories?
>> >
>> > -- Sean M, who admittedly is not fond of changing the identity of the
>> > worker
>> > process
>> >
>> > message
>> >> i forgot to say, the name KOSW047BFJNQUY26 changes every time.
>> >>
>> >> i still don't know who try to create that directory/file and when.
>> >> i didn't write the applications by myself, i only know that thy use
>> > Crystal
>> >> Reports, they're written in .NET 2002 and they use a component to draw
>> >> charts, dunno if it is that particular component that tryes to write
> the
>> >> directory/file. at least, the programmer said me that he doesn't
>> > explicitly
>> >> create it.
>> >>
>> >> how can i see if it is being created with explicit permission or other
>> > grant
>> >> ? i can't even find that directory.
>> >>
>> >> thank you,
>> >> Marco
>> >>
>> >>
>> >>
>> >> > Marco,
>> >> >
>> >> > C:\WINNT\KOSW047BFJNQUY26 appears to be some temporary
>> >> > directory ?? Is it being created with explicit permissions that
>> >> > will
>> >> > exclude Users or other grant that includes Dir List for AspNet ?
>> >> >
>> >>
>> >
>> >
>>
>>
>
>




Posted by Roger Abell on July 13, 2005, 6:23 pm
Please log in for more thread options
> I can't see that items.
> That directory (or files?) with the random name doesn't even seem to
exists,
> or at least i'm not able to see them, so i can't see the protection
> settings.
>

It could be that the failure message is because of "file not found" ??

> The "Users" group has read only access to WINNT directory.
>
> Why is the protection event talks about READ/SYNCRONIZE deny, if the Users
> ( and then the ASPNET account too) has read grants on the WINNT directory?
>

That is why I first asked about explicit as compared to inherited grants.
Users Read allows just these. That it is a minimal request being made
and one within the inherited grants, makes it sound like something is
looking for a file in the wrong place (?)

> I don't think the programmers are creating a file in it, i talked with
them
> and nobody has written code to create a file/directory in C:\WINNT, or at
> least we don't know if Crystal Report tryes to.

I can't help you there, but it is good you have that info from the devs.

>
> thanks for the help,
> Marco
>
>
> > Well, they should not be able to write to c:\winnt at all !!
> > When you look at one of these in c:\winnt are the NTFS permissions
> > on it all inherited or are some or all explicit ? i.e. gray or white
> > boxes?
> >
> > That dir name makes it sound like this was upgrade to W2k from NT4,
> > which would leave c:\winnt permissioned loose.
> > I would be the villan and first notify my web authors that use
> > crystal that c:\winnt will be altered and there apps will fail
> > if they do not use the temp environment var to locate their
> > file usage correctly, and I would set an implementation date
> > and hold to it. When that date comes you will find out who
> > is responsible. The alternative, of trying to loosening c:\winnt
> > permissions, if it is not an explicitly set permissions issue, so
> > that inherited permissions are sufficient is not an attractive
> > way to go.
> >
> > --
> > Roger Abell
> > Microsoft MVP (Windows Security)
> > MCSE (W2k3,W2k,Nt4) MCDBA
> >> The ASPNET account has R/W access to
> >> "C:\WINNT\Microsoft.NET\Framework\v1.0.3705\Temporary ASP.NET Files"
and
> >> "C:\WINNT\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files"
( no
> >> FULL CONTROL, only Modify+Read+Write, it's ok? ).
> >>
> >> The aspnet_wp process is running under the ASPNET account.
> >>
> >> The aspnet_wp process i using 195MB of memory, with a peak of 312MB.
> >> With a process viewer i can see it has abount 22 threads (nearly all of
> > them
> >> regarding mscorsvr.dll).
> >>
> >> Marco.
> >>
> >> > This sounds a lot like an attempt to get at the Temporary ASP.NET
Pages
> >> > cache directory. Are you running the ASP.NET worker process as a
> > different
> >> > account that perhaps doesn't have access to the proper directories?
> >> >
> >> > -- Sean M, who admittedly is not fond of changing the identity of the
> >> > worker
> >> > process
> >> >
> >> > message
> >> >> i forgot to say, the name KOSW047BFJNQUY26 changes every time.
> >> >>
> >> >> i still don't know who try to create that directory/file and when.
> >> >> i didn't write the applications by myself, i only know that thy use
> >> > Crystal
> >> >> Reports, they're written in .NET 2002 and they use a component to
draw
> >> >> charts, dunno if it is that particular component that tryes to write
> > the
> >> >> directory/file. at least, the programmer said me that he doesn't
> >> > explicitly
> >> >> create it.
> >> >>
> >> >> how can i see if it is being created with explicit permission or
other
> >> > grant
> >> >> ? i can't even find that directory.
> >> >>
> >> >> thank you,
> >> >> Marco
> >> >>
> >> >>
> >> >>
> >> >> > Marco,
> >> >> >
> >> >> > C:\WINNT\KOSW047BFJNQUY26 appears to be some temporary
> >> >> > directory ?? Is it being created with explicit permissions that
> >> >> > will
> >> >> > exclude Users or other grant that includes Dir List for AspNet ?
> >> >> >
> >> >>
> >> >
> >> >
> >>
> >>
> >
> >
>
>




Similar ThreadsPosted
UNC mapping alert March 9, 2008, 5:18 am
User Rights for IUSR_xxxx and ASPNET? December 26, 2006, 1:05 am
how to use the user account and the computers account to ... March 9, 2007, 10:38 am
User Account Created - 624 And User Account Enabled - 626 for Hel October 13, 2005, 1:56 pm
Account Policies - NT January 19, 2006, 3:14 pm
Account Being Locked Somewhere August 18, 2006, 6:50 am
Administrator account July 6, 2007, 12:43 pm
OS account report March 17, 2008, 12:42 am
NT4 user account recovery June 3, 2005, 6:29 am
services running under a certain account August 15, 2005, 9:19 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap