CodeVerge.Net Beta


   Explore    Item Entry    Members      Register  Login  
NEWSGROUP
.NET
Algorithms-Data Structures
Asp.Net
C Plus Plus
CSharp
Database
HTML
Javascript
Linq
Other
Regular Expressions
VB.Net
XML

Free Download:




Zone: > NEWSGROUP > Asp.Net Forum > general_asp.net.security Tags:
Item Type: NewsGroup Date Entered: 9/29/2007 12:33:06 PM Date Modified: Subscribers: 0 Subscribe Alert
Rate It:
(NR, 0)
XPoints: N/A Replies: 1 Views: 7 Favorited: 0 Favorite
Can Reply:  No Members Can Edit: No Online: Yes
2 Items, 1 Pages 1 |< << Go >> >|
adaquino
Asp.Net User
security problem9/29/2007 12:33:06 PM

0/0

HI,

I am administering a win 2000 server (iis 5) with several web applications running asp.net 1.1 and 2.0.

The server has been recently attacked by an hacker. I was able to identify the attacker and close the door. After that I discovered that the aspnet_wp processes were running under Administrator account (they were running in ASPNET account before as no changes to default was done)

I checked the aspnet account and its policies and everything is ok. I also tried several options with aspnet_regiis, but no way: the aspnet_wp processes are still running under the administrator account.

I tried also setting the processModel user to "machine" in machine.config  but nothing changes.

Finally I tried to unistall completely and reinstall both asp.net 1.1 and 2.0 

But after the installation the aspnet_wp processes are still running under Administrator account.

Any suggestion?

Thank you very much 

 

HosamKamel
Asp.Net User
Re: security problem9/29/2007 4:54:36 PM

0/0

 You Can do the following

  • Create a weak account that has the permissions necessary for running the ASP.NET worker process, and then configure the <processModel> section of the Machine.config file to run the worker process under that account.
  • Configure the <processModel> section of the Machine.config file to run the ASP.NET worker process under the SYSTEM account or an Administrator account, instead of the machine account.

 This is the workaround that Microsoft has descried it here http://msdn2.microsoft.com/en-us/library/aa579070.aspx

http://support.microsoft.com/kb/315158 

http://msdn2.microsoft.com/en-us/library/kd3se23d(VS.71).aspx

 

 


Hosam Kamel



Remember to click on Mark as answer on the post that helped you
2 Items, 1 Pages 1 |< << Go >> >|


Free Download:

Books:
People, States and Fear: The National Security Problem in International Relations Authors: Barry Buzan, Pages: 250, Published: 1983
People, States and Fear: National Security Problem in International Relations Authors: Barry Buzan, Pages: 350, Published: 1991
Operating System Concepts Authors: Abraham Silberschatz, Peter B. Galvin, Pages: 780, Published: 1994
Web Security, Privacy and Commerce Authors: Simson Garfinkel, Gene Spafford, Pages: 756, Published: 2001
Zones of Amity, Zones of Enmity: The Prospects for Economic and Military Security in Asia Authors: James Sperling, Yogendra K. Malik, David J. Louscher, Pages: 144, Published: 1998
The Crisis in Social Security: Problems and Prospects Authors: Michael J. Boskin, George F. Break, Pages: 214, Published: 1977
Security in Computing Authors: Charles P. Pfleeger, Shari Lawrence Pfleeger, Pages: 746, Published: 2003
Proposals to Deal with the Social Security Notch Problem: 1985, 99th Congress, 1st Session Authors: unknown, Pages: 35, Published: 1985

Web:
PC World - What's the Biggest Security Problem? Experts, hackers debate cyberterror, digital teens, and holey software.
Microcosm of a massive security problem | Latest Security News ... Oct 21, 2008 ... Some interesting trends emerge when Jon Oltsik gives a talk on endpoint security and asks the attendees about their IT infrastructure and ...
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Zlib Advisory 2002 ... The problem was then reported by other people but the zlib authors did not correctly appreciate the security implications and thus the seriousness of this ...
Microsoft Security Advisory (925984): Vulnerability in PowerPoint ... Sep 27, 2006 ... There is no charge for support that is associated with security updates ... This may include providing a security update through our monthly ...
US-CERT Vulnerability Note VU#238678 AppGate Network Security AB, Not Vulnerable, 2-Sep-2004 .... http://www.openpkg. org/security/OpenPKG-SA-2004.038-zlib.html ...
Security Public Relations Excuse Bingo security very seriously. You don't understand the context, Our proactive technology solutions prevent that, security problem excuse BINGO, We use ...
A Serious Security Problem…and a Timely Blog « The JD Edwards Advisor A Serious Security Problem…and a Timely Blog. Posted by Lee Kroon on July 29, 2008. Yesterday, Oracle issued an urgent Security Alert about a vulnerability ...
Crime: The Real Internet Security Problem Crime: The Real Internet Security Problem. Details. Comments. More from user. Crime: The Real Internet Security Problem - 58 min - Jan 24, 2006 ...
Cross Site Scripting Info There are specific bugs in a wide range of web server products, including Apache , that allow for or contribute to the exploitation of this security problem. ...
WordPress › Blog » WordPress 2.3.3 1.5.0, caused by the same XML-RPC protocol security problem that has been solved in Wordpress by the new release, WP [...] ...

Videos:
Crime: The Real Internet Security Problem Google TechTalks January 24, 2006 Phillip Hallam-Baker Dr Hallam-Baker is a leading designer or Internet security protocols and has made substantia...
Crime: The Real Internet Security Problem Google TechTalks January 24, 2006 Phillip Hallam-Baker Dr Hallam-Baker is a leading designer or Internet security protocols and has made substantia...
Excel: Database security problem In this short video, I show you a security issue when saving password together with a database query.
Owasp5018 -Rohyt Belani- OffShoring Application Development? Security Problems? Recorded at the Open Web Application Security Project (www.OWASP.org) NYC Conference on Sep 25, 2008 - Content produced by www.MediaArchives.com - Ma...
Social Security Problem Social Security is one of the six major economic problems facing the United States over the next fifteen years.
Facebook Security Problems Uploaded by / Subido por Alex-Kid
Gears and the Mashup Problem Google Tech Talks September, 20 2007 ABSTRACT Mashups are the most interesting innovation in software development in decades. Unfortunately, the br...
Security Issue in Cloob.com In this video you'll see a small bug in Cloob.com live chat system found by Siavash Mahmoudian in action. Using this small security issue you are ab...
The Secure Information Sharing Problem and Solution Approaches The secure information sharing problem is one of the oldest and most fundamental and elusive problems in information security. Mission objectives dic...
Security Problem at The Orleans Hotel You think you trust that safe in your hotel? The ones at The Orleans in Las Vegas aren't attached to anything, and are lighter then you think! Presen...




Search This Site:










plesk 7.5 for windows and dotnetnuke 3.0.13

dnnv3.0.4 beta - add new user/vendor not shown unless ...

logging in as admin / host

certificate issue -- keyset does not exist

faq - health monitoring in asp.net 2.0

how to export/backup help favorites in vs2005?

dnn3 - remove default search box

doubt - > related to asp.net web application

dnn 4 standard modules source files

trial download

multiple type of users, with multiple user login pages in one web application

enterprise oltp system using dnn

omniportal 0.4 release

problem install dnn.survey module for 3.0.13

using querystring in hyperlink

textual status from an array

how do you pass data from one web part to another?

menu problem ..

security role

can not find file dotnetnuke_4.0.0_install\providers\dataproviders\sqldataprovider\dotnetnuke_template.mdf

selectednodestyle doesn't work when enabling ajax

bug: not all depencies honor "copy local"

module width in the module settings

general web hosting questions

what is serialized in the pagesettings?

web access failed

form based authentication problem plz help

host settings and file manager problems 3.1 and now 3.1.1

no list at class property of html element when a css is linked

adding aspx below the dnn root

 
All Times Are GMT