Multiple Vendor Unprivileged User Permissions Log File Modification Vulnerability
BID:3888
Info
Multiple Vendor Unprivileged User Permissions Log File Modification Vulnerability
| Bugtraq ID: | 3888 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2002 12:00AM |
| Updated: | Jan 16 2002 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Information Anarchy 2K01 <[email protected]>. |
| Vulnerable: |
Symantec Norton Internet Security 2001 0 Microsoft IIS 5.0 Microsoft IIS 4.0 |
| Not Vulnerable: | |
Solution / Fix
Multiple Vendor Unprivileged User Permissions Log File Modification Vulnerability
Solution:
To resolve this problem, Microsoft recommends that you make the following changes on the appropriate folder (such as W3svc, W3svc1, Msftpsvc1, and so forth):
1.Remove the IUSR_ ComputerName account.
2. Modify the permissions for the Everyone group to have only the appropriate Read permission: Click Read in the Type of Access box.
Solution:
To resolve this problem, Microsoft recommends that you make the following changes on the appropriate folder (such as W3svc, W3svc1, Msftpsvc1, and so forth):
1.Remove the IUSR_ ComputerName account.
2. Modify the permissions for the Everyone group to have only the appropriate Read permission: Click Read in the Type of Access box.