Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...CheckDiskAccess - DNN has full acess to whole server?!CheckDiskAccess - DNN has full acess to whole server?!
Previous
 
Next
New Post
4/19/2017 12:05 PM
 

Hi,

I did a clean server installation.

OS Version: Microsoft Windows NT 6.3.9600.0

Web Server Version: Microsoft-IIS/8.5

.NET Framework Version: 4.0.30319.42000

ASP.NET Identity: IIS APPPOOL\xxxxx

Host Name: -

Physical Path:

D:\HostingSpaces\xxxxx\wwwroot

Site URL: -

Relative Path: /

I have created a separate application pool identify, set it as follow: (Identity = ApplicationPoolIdentity, Load User Profile = True )

https://drive.google.com/file/d/0B7ulnEuMfJHXbVpxOElhWWFNUUU/view?usp=sharing

Next, I set the Folder Permission (read, write, list) for D:\HostingSpaces\xxxxx\wwwroot using the application pool identity.


Unfortunately, the Analyzer still showing this, what did I miss?

CheckDiskAccess : Checks extra drives/folders access permission outside the website folder
Hackers could access drives/folders outside the website
D:\HostingSpaces\xxxx - Read:Y, Write:Y, Create:Y, Delete:N
D:\HostingSpaces - Read:Y, Write:Y, Create:Y, Delete:N
D:\ - Read:Y, Write:Y, Create:Y, Delete:N
C:\ - Read:Y, Write:Y, Create:Y, Delete:N
E:\ - Read:Y, Write:Y, Create:Y, Delete:N


One more thing, in the dnn host dashboard, I saw CAS permission to be "ReflectionPermission, WebPermission, AspNetHostingPermission"

is this normal?

 

Thank you for your kind help.



 

 

 

 

 

 
New Post
6/24/2017 8:52 PM
 
Did you ever get an answer to this?
 
New Post
6/25/2017 6:00 AM
 

Hi,

I have the same warning and I like an answer on this as well :-)

Regards, Ton


Art is hard work, inspiration is the cream on top of it. See my watercolors at www.watermansite.com and my enamel art at www.watermanshop.com
 
New Post
8/16/2018 10:02 PM
 
C:\ - Read:Y, Write:Y, Create:Y, Delete:N

From this read ApplicationPoolIdentity is in users group which grants it access to C:\ with those permissions.

https://stackoverflow.com/questions/5...

I think this may shine some light on this issue as I am curious as well. Any other thoughts?
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...CheckDiskAccess - DNN has full acess to whole server?!CheckDiskAccess - DNN has full acess to whole server?!


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out