IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
SlickEdit: Code in over 40 languages across 7 platforms. SlickEdit’s unmatched power, speed, and flexibility allows even the most accomplished developers to write better code faster. Download a free trial today!
  #1  
Old May 14th, 2004, 01:10 PM
riga riga is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2003
Location: Toronto
Posts: 35 riga User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 m 47 sec
Reputation Power: 0
"Directory Browsing disabled" - is it enough to protect the files?

I have an ASP application, it's an Online Certification Program.
In IIS I have a folder "Assignments_Submissions"
where I store the files in my ASP Application.
I store files in SQL Server but before I do that
I need to save it on a hard-drive and
to see if AntiVirus catches anything.
I cleanup them later manually.

One student who submitted the file
last year found the exact document
on www.essaycrawler.com

The student is completely sure that he never
emailed the file or stored it anywhere on the Web.
The file was always on the student's hard-drive.
It is his personal computer, nobody has access to it.

My question is - is it enough to
have "Directory Browsing" disabled to protect the files.
Or maybe there are some smart crawlers that
can get through?

RobO
Now we have to test the security
and investigate this case

Reply With Quote
  #2  
Old May 14th, 2004, 06:25 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 12th Plane (10500 - 10999 posts)
 
Join Date: Jun 2003
Posts: 10,679 Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level)Doug G User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 4 Weeks 1 Day 14 h 50 m 53 sec
Reputation Power: 688
Disabling directory browsing only stops browsers from listing a directory contents. Being off won't stop any client from directly accessing a file if they know the exact url, crawler or otherwise.

I'd say keep your documents in the db, or in a folder that doesn't allow anonymous web surfing.
__________________
======
Doug G
======
"Hide, hide witch! The good folk come to burn thee. Their keen enjoyment hid behind their gothic mask of duty." -Mark Clifton

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > "Directory Browsing disabled" - is it enough to protect the files?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 5 hosted by Hostway