file traversal

Discussion in 'ASP .Net Security' started by scottrm, Jun 1, 2004.

  1. scottrm

    scottrm Guest

    In classic asp you could help mitigate file traversal problems by uncheking the allow parent paths option in IIS home directory/configuration/options which disallowed the use of the ../ syntax. However this does not seem to work in asp.net, any way to enforce this? Also does anyone know a good way to avoid using the ../ syntax for links apart from hard coding the full url path
     
    scottrm, Jun 1, 2004
    #1
    1. Advertising

  2. scottrm

    [MSFT] Guest

    Hello,

    Thank you for the post. Currently I am performing some research on this
    issue, to see if there is a proper solution for ASP.NET. I will update you
    as soon as possible.

    Luke
    Microsoft Online Support

    Get Secure! www.microsoft.com/security
    (This posting is provided "AS IS", with no warranties, and confers no
    rights.)
     
    [MSFT], Jun 2, 2004
    #2
    1. Advertising

  3. scottrm

    [MSFT] Guest

    Hello,

    So far as I researched, this option doesn't make sense in ASP.NET. Pretty
    much most of IIS settings do not affect asp.net at all. Usually, asp.net
    has its own settings (eg. machine.config etc..) that you use for
    configuration.

    To protect problems related to this issue, we should rely on ASP.NET
    security and NTFS security, to restrict user access other folders.

    Luke
    Microsoft Online Support

    Get Secure! www.microsoft.com/security
    (This posting is provided "AS IS", with no warranties, and confers no
    rights.)
     
    [MSFT], Jun 3, 2004
    #3
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. Wynan James
    Replies:
    1
    Views:
    1,591
    Miguel De Anda
    Oct 6, 2003
  2. Big Jim

    Fous Traversal Policy

    Big Jim, Jan 27, 2006, in forum: Java
    Replies:
    0
    Views:
    414
    Big Jim
    Jan 27, 2006
  3. Xavier Decoret

    recursive traversal of file

    Xavier Decoret, Aug 15, 2003, in forum: Python
    Replies:
    2
    Views:
    408
    Paul McGuire
    Aug 19, 2003
  4. manstey
    Replies:
    3
    Views:
    325
    Serge Orlov
    May 24, 2006
  5. Mark
    Replies:
    2
    Views:
    186
Loading...

Share This Page