The information in this article applies to:
SYMPTOMSWhen you install the FrontPage Server Extensions on a drive that is formatted on a FAT partition, you are informed that the Web is insecure. When you run the Check and Fix reports, the following error message occurs:
CAUSEThe FrontPage 2000 Server Extensions store the contents of the _vti_bin folder (traditionally stored in the content area) in the following path: <Drive>:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\40\isapiThis folder is mapped into each site as a virtual directory. If this location is on a FAT partition, FrontPage considers it to be insecure. This is because you cannot set file-level permissions on a FAT partition. When installed on NTFS, the ACLs are set with everyone having Read and Execute permissions on this folder and its contents. This is in order to disallow the possible security threat of uploading malicious code to the _vti_bin folder and executing it. WORKAROUND
To secure an ISP environment, you should have only NTFS partitions and you should lock them down.
The program files and WINNT directories should only have Read permissions. In some cases, they can have Execute permissions by Everyone and Write permissions only by Administrators/SYSTEM and other trusted accounts and groups. The only option is to convert the boot drive to NTFS in order to provide the tightest possible security.
Additional query words: front page
Keywords : fpse2000 |
Last Reviewed: November 5, 1999 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |