IUSR Security Settings

Thread: IUSR Security Settings

    Andrew Sinning

    IUSR Security Settings

    Our company has recently developed of an "off the shelf" product with an ASP server component. In developing the product, we came to conclude that IUSR security settings would have to be set to "full control" for 2 of the directories within our application folder in order for the application to read, write, create and delete files.<BR><BR>Now we have a prospective client whose web administrator says that this is not acceptable within their security paradigm.<BR><BR>What am I missing? Is there a more secure way to do this?

    They are right...

    ...You really should look at some "in the background" NTLM functions to authenticate users when they need to access specific secured areas. I believe there is an article at http://www.eggheadcafe.com that speaks to this.

