IIS Parent Paths

Issue

If ASPEnableParentPaths is enabled and the parent directories have execute access, a script could run an unauthorized program in a parent directory.

Solution

Disable the ASPEnableParentPaths option on Internet Information Services (IIS).

Note

Instructions

To disable the ASPEnableParentPaths option in Microsoft® Windows® XP Professional

  1. Click Start, point to Programs, point to Administrative Tools, and then click Internet Information Services.
  2. In the Internet Information Services Manager, right-click the root of the Web site that you want to secure, and then click Properties.
  3. In the Default Web Site Properties dialog box, click the Home Directory tab, and then click Configuration.
  4. In the Application Configuration dialog box, click the Options tab, and then clear the Enable parent paths check box.

To disable the ASPEnableParentPaths option in Windows 2000

  1. Click Start, point to Programs, point to Administrative Tools, and then click Internet Services Manager.
  2. In the Internet Information Services Manager, right-click the root of the Web site that you want to secure, and then click Properties.
  3. In the Default Web Site Properties dialog box, click the Home Directory tab, and then click Configuration.
  4. In the Application Configuration dialog box, click the App Options tab, and then clear the Enable parent paths check box.

To disable the ASPEnableParentPaths option in Windows NT®

  1. Click Start, point to Programs, point to Windows NT 4.0 Option Pack, point to Microsoft Internet Information Server, and then click Internet Service Manager.
  2. In the Internet Information Services Manager, right-click the root of the Web site that you want to secure, and then click Properties.
  3. In the Default Web Site Properties dialog box, click the Home Directory tab, and then click Configuration.
  4. In the Application Configuration dialog box, click the App Options tab, and then clear the Enable parent paths check box.

To disable the ASPEnableParentPaths option if you are running Microsoft Small Business Server 2000

  1. Follow the previous steps for Windows 2000.
  2. Click OK. The Inheritance Overrides dialog box appears.

    Note

  3. Click OK to close the Inheritance Overrides dialog box.
  4. Click OK to close the Web Site Properties dialog box.

Important

Additional Information

ASPEnableParentPaths MetaBase Property Should Be Set To False (184717)


©2002-2004 Microsoft Corporation. All rights reserved.