|
SSL will not change the way the auth popup behaves. As to the other security issues, unless you are requiring mutual certificate authentication via SSL, server cert only SSL secures your session (i.e. session hijacking attacks), but does nothing to prevent other types (buffer overflows, etc.) which are not session dependant. I am guessing that one of the two above is the correct interpretation for your question, but if I am still missing it, let me know.
Ted Nichols Ipswitch QA
-----Original
Message-----
What about using an SSL? Bruce is correct. Your remotely accessible web sites and/or virtualdirectories should never be run with administrator privileges. If the authpopup is a problem there is only one safe work around. Always login to theadmin from the server itself, and connect to http://localhost/iadmin . Whatthis does is that it tries to use the credentials of the windows (i.e. theconsole session you used to login to windows) user if the IIS user does nothave the necessary permissions. The popup would only happen if both setsdon't have the permissions needed. Remotely, the auth popup is a necessaryevil. Ted NicholsIpswitch QA -----Original Message-----From: [EMAIL PROTECTED][mailto:[EMAIL PROTECTED]] On Behalf Of Bruce BarnesSent: Sunday, September 24, 2006 8:53 AMTo: [email protected]Subject: RE: [IMail Forum] Results after Upgrading to Imail 2006.1 For security purposes, the ISS USER should NEVER have administrativeprivileges If you give the ISS user administrative privileges, you open your server upto being "managed" by every hacker that happens upon your system. If you are going to run Imail 2006.1, on a DEDICATED BOX, then you can useIIS for the user. If you run Imail 2006.1 on a NON-DEDICATED BOX, that is you are also runningweb services on the box for web pages, you need to set up a SEPARATE USERfor anonymous Imail use and give that user the necessary privileges forImail. If you use the standard IIS user AND have other websites running onthe machine, then you are giving privileges to the other sites that nostandard web access user should have because the IMAIL user has way too manyprivileges to be considered secure. SPECIAL NOTE TO THOSE RUNNING DATABASES FOR WEBSITES OTHER THAN IMAIL: Ifyou are running BOTH IMAIL and STANDARD WEBSITES with databases, yourdatabases are wide open to hackers because of the elevated privileges thatIMAIL installs for the IIS user. If you are running any kind of SECURE DATABASES or SECURE WEBSITES, you areopening yourself up to even bigger problems. On a properly secured web server, the STANDARD IIS USER SHOULD NEVER HAVEANYTHING MORE THAN ANONYMOUS READ-ONLY ACCESS Once again, we are still reviewing IMAIL and strongly looking to abandon theproduct because of the LACK of SECURITY provided by ISS when IMAIL isrunning on a machine that also hosts standard websites. Bruce BarnesChicagoNetTech Inc -----Original Message-----From: [EMAIL PROTECTED][mailto:[EMAIL PROTECTED]] On Behalf Of Ted NicholsSent: Friday, September 22, 2006 16:22To: [email protected]Subject: RE: [IMail Forum] Results after Upgrading to Imail 2006.1 The authentication popup happens because WMI, which is used to manageservices in the admin, requires administrator privileges to manage services.If your IIS user does not have the privileges needed, the authenticationpopup will happen. I have not seen 0 length mailbox issue before, but willinvestigate. Ted NicholsIpswitch QA -----Original Message-----From: [EMAIL PROTECTED][mailto:[EMAIL PROTECTED]] On Behalf Of Martin SchaibleSent: Friday, September 22, 2006 5:13 PMTo: Ipswitch IMail Mailing ListSubject: [IMail Forum] Results after Upgrading to Imail 2006.1 Hi, Today we moved a customers site from Imail 8.22 to Imail 2006.1. The Upgradewas quite relaxing. The customer has as spare server which he now uses for a few domains withabout 60 Accounts. I was quite surprised to see a Quad Xeon 2.88 GHz fromCompaq. Honestly, it hurts a bit to see a machine like this for a suchreally small Imail site. This server will have a really bored life. I have two open questions: #1 I think, Imail 2006.1 does not like mailbox files with zero bytes size.We had tons of messages in the log, complaining that the mail box couldn'tbe opened. After deleting the empty mail boxes, the error disappeared. Isthis a bug after migration? #2 Which this power machine, the webmail runs nearly with warp 9.5, butaccessing the "services", a login window popped up. I had to authentificatemyself with a windows login. I know, that we had the case here and it has doto with the NTFS security settings. I searched the archives and the KB, buti couldn't find help. Any idea? |
- Re: [IMail Forum] Results after Upgrading to Imail 2006.... Matrosity Hosting
- RE: [IMail Forum] Results after Upgrading to Imail ... Ted Nichols
- Re: [IMail Forum] Results after Upgrading to Im... Matrosity Hosting
