Home Operation and Maintenance Windows Operation and Maintenance Win2008 R2 WEB Server Security Settings Guide - Folder Permission Setting Tips

Win2008 R2 WEB Server Security Settings Guide - Folder Permission Setting Tips

Jun 01, 2017 am 10:52 AM

This article mainly introduces the folder permission setting skills of the Win2008 R2 WEB serverSecurity Setting Guide, friends in need can refer to the following

Through the control file folder permissions to improve site security.

Permission settings in this article include two aspects, one is the permissions of the system directory and drive letter, and the other is the permission settings of the upload folder of the application.

System directory

Make sure that all drive letters are in NTFS format. If not, you can use the command convert d:/fs:ntfs to convert to NTFS format.

All disk root directories only give system and administrators permissions, othersdelete.

There will be several prompts for the system drive letter, just confirm it directly. Before doing this step, your operating environment software must be installed before you can do it. Otherwise, it may cause software installation errors. Remember that all security operation settings must be done after the software is installed.

Site directory

Each website corresponds to a directory, and add IUSR and IIS_IUSRS permissions to this website directory, which only give "list folder content" and "read" permissions.

For example, I created a wwwroot directory in the root directory of drive D, and then created a blog.postcha.com directory in it. This directory contains my website program. Among them, wwwroot only needs to inherit the permissions of the d disk, and for the blog.postcha.com directory, we need to add two more permissions, namely IUSR and IIS_IUSRS.

wwwroot permissions:


Site directory permissions:


General All websites have the function of uploading files and pictures, but the files uploaded by users are not trustworthy. Therefore, the upload directory must be set separately. To upload the directory, you also need to add "modify" and "write" permissions to the IIS_IUSRS group.



After the above setting, with an execution permission, once the user uploads a malicious file, our server It fell, but we have to give it here, so we have to cooperate with IIS to set it up again.

In iis7 and above, this setting is very convenient. Open the IIS manager, find the site, select the upload directory, double-click under IIS in the middle column to open "Handler Mapping", then select "Edit Function Permissions" and uncheck "Script".

Okay, let’s open the upload folder and see if there is an extra web.config.

The content in web.config is as follows:


<?xml version="1.0" encoding="UTF-8"?>
<configuration>
  <system.webServer>
    <handlers accessPolicy="Read" />
  </system.webServer>
</configuration>
Copy after login

means all files in the upload directory (including all subfolders) will only have read-only permissions. In this way, even if the user uploads a malicious file, it will not be effective.

The value can be "Read, Execute, Script", which means "read-only, execute, script" respectively.

Each website program has different functions and settings. Minimum permissions are maximum security.

The above is the detailed content of Win2008 R2 WEB Server Security Settings Guide - Folder Permission Setting Tips. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

AI Hentai Generator

AI Hentai Generator

Generate AI Hentai for free.

Hot Article

R.E.P.O. Energy Crystals Explained and What They Do (Yellow Crystal)
2 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
Repo: How To Revive Teammates
1 months ago By 尊渡假赌尊渡假赌尊渡假赌
Hello Kitty Island Adventure: How To Get Giant Seeds
1 months ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

What are the operation and maintenance tools under window What are the operation and maintenance tools under window Mar 05, 2025 am 11:17 AM

This article reviews Windows-based server management tools. It compares free (PowerShell, Windows Admin Center) and commercial options (SCCM, Azure Arc), highlighting their functionality, cost, and complexity. The choice depends on needs, budget, a

How to solve the problem that Tencent Cloud has downloaded? How to solve the problem that Tencent Cloud has downloaded? Mar 05, 2025 am 11:18 AM

This article guides users on opening files downloaded from Tencent Cloud. It addresses common issues like corrupted downloads, incompatible file formats, and software conflicts, offering troubleshooting steps and suggesting contacting Tencent Cloud

How to use Tencent Cloud Lightweight Application Server Tutorial for Using Tencent Cloud Lightweight Application Server How to use Tencent Cloud Lightweight Application Server Tutorial for Using Tencent Cloud Lightweight Application Server Mar 05, 2025 am 11:16 AM

This guide details using Tencent Cloud Lightweight Application Servers (LAS). It covers account setup, instance creation (specifying region, configuration, image, security, and storage), and application deployment. Key features include cost-effecti

Tutorial on the mobile version of Tencent Cloud to cancel the account without real name Tutorial on the mobile version of Tencent Cloud to cancel the account without real name Mar 05, 2025 am 11:20 AM

Deleting unregistered Tencent Cloud mobile accounts is impossible without verification. The article explains why account deletion requires verification and details how uninstalling the associated app is the most effective workaround to sever the app

What to do if the windows installation error is not started? What to do if the windows installation error is not started? Mar 05, 2025 am 11:19 AM

This article addresses common Windows installation and boot errors. It details troubleshooting steps for issues like corrupted media, hardware problems, driver conflicts, partitioning errors, BIOS settings, and software conflicts. Solutions include

Recommended Windows Operation and Maintenance Tools What are the Windows Operation and Maintenance Software? Recommended Windows Operation and Maintenance Tools What are the Windows Operation and Maintenance Software? Mar 05, 2025 am 11:15 AM

This article reviews free and paid Windows server administration tools. It compares built-in options like Server Manager & PowerShell with commercial solutions such as SolarWinds and Microsoft System Center, emphasizing the trade-offs between co

What are the main tasks of Windows Operation and Maintenance Engineers What are the main tasks of Windows Operation and Maintenance Engineers Mar 05, 2025 am 11:14 AM

This article details the key responsibilities and essential skills of a Windows systems administrator. It covers system installation/configuration, monitoring/troubleshooting, security management, backup/recovery, patch management, automation, and u

See all articles