Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: SharePoint securization |
|---|---|
| Date: | Thu, 18 Aug 2005 00:39:38 -0700 |
Security Architecture for SharePoint Products and Technologies: http://www.microsoft.com/technet/prodtechnol/sppt/reskit/c0661881x.mspx
SharePoint Security: http://www.brienposey.com/kb/sharepoint_security.asp 15 Seconds : SharePoint Security and .NET Impersonation: http://www.15seconds.com/issue/040511.htm Download details: Windows SharePoint Services Administrator's Guide: http://www.microsoft.com/downloads/details.aspx?FamilyID=a637eff6-8224-4b19-a6a4-3e33fa13d230&DisplayLang=en
Site Groups
*Site Group Name*
*User Rights Included*
Guest
None
Reader
Use Self-Service Site Creation
View Pages
View Items
Contributor
Use Self-Service Site Creation
View Pages
View Items
Add Items
Add/Remove Private Web Parts
Browse Directories
Create Cross-Site Groups
Delete Items
Edit Items
Manage Personal Views
Update Personal Web Parts
Web Designer
Use Self-Service Site Creation
View Pages
View Items
Add Items
Add/Remove Private Web Parts
Browse Directories
Create Cross-Site Groups
Delete Items
Edit Items
Manage Personal Views
Update Personal Web Parts
Add and Customize Pages
Apply Themes and Borders
Apply Style Sheets
Cancel Check-Out
Manage Lists
Administrator
Use Self-Service Site Creation
View Pages
View Items
Add Items
Add/Remove Private Web Parts
Browse Directories
Create Cross-Site Groups
Delete Items
Edit Items
Manage Personal Views
Update Personal Web Parts
Add and Customize Pages
Apply Themes and Borders
Apply Style Sheets
Cancel Check-Out
Manage Lists
Create Subsites
Manage List Permissions
Manage Site Groups
View Usage Data
Manage Lists
* *
*Right*
* *
* *
*Permission*
* *
*Groups Included*
* *
*Dependency Rights*
Add and customize pages
Can create ASP.NET, ASP, HTML Web pages for a site
Web Designer
Administrator
Browse directories
View Pages
Add items
Add documents to documents libraries or items to lists
Contributor
Web Designer
Administrator
View Items
View Pages
Add and remove private Web parts (Web modules)
Add and/or remove Web parts to pages
Contributor
Web Designer
Administrator
Update Web Parts
View Items
View Pages
Apply style sheets
Apply a style to the entire site
Web Designer
Administrator
View Pages
Apply themes and borders
Apply a theme and/ or border to a site
Web Designer
Administrator
View Pages
Browse directories
Browse a Web site’s directory structure
Contributor
Web Designer
Administrator
View Pages
* *
*Right*
* *
* *
*Permission*
* *
*Groups Included*
* *
*Dependency rights*
Cancel check-out
Can cancel the check-out performed by a user
Web Designer
Administrator
View Pages
Create cross-site groups
Delete and create cross-site groups, change membership
Contributor
Web Designer
Administrator
View pages
Create subsites
Create subsite
Reader
Contributor
Web Designer
Administrator
View pages
Delete items
Delete items and documents
Contributor
Web Designer
Administrator
View items
View pages
Edit items
Edit existing list items and document in the Web site
Contributor
Web Designer
Administrator
View items
View pages
Manage Lists
Delete, create, edit lists and change settings
Web Designer
Administrator
View items
View pages
Manage personal views
Manage list permissions
Change permissions for a list
Administrator
Manage lists
View items
View pages
Manage personal views
Manage personal views
Create, delete, and edit personal views
Contributor
Web Designer
Administrator
View items
View pages
Manage site groups
Administrator
View pages
Manage Web site
Perform tasks for the site or subsite
Administrator
View pages
Update personal Web parts
Update Web parts
Contributor
Web Designer
Administrator
View items
View pages
Use self-service site creation
Use to create top-level Web site
Reader
Contributor
Web Designer
Administrator
View pages
* *
*Right*
* *
* *
*Permission*
* *
*Groups Included*
* *
*Dependency rights*
View items
View items in lists, documents
Reader
Contributor
Web Designer
Administrator
View pages
View pages
Browse pages
Reader
Contributor
Web Designer
Administrator
None
View usage data
View reports on Web site use
Administrator
View pages
tevfik@itefix.no wrote:
Hi,
As you say, it all depends on your requirements. Bastion Host Template is a part of Security Guide for Windows 2003. More information can be found at http://www.microsoft.com/technet/security/prodtech/windowsserver2003/w2003hg/sgch00.mspx
After having applied that template, I run some verification tools like BSA, Nessus and C2I Security Benchmark. In my opinion, the results were acceptable.
When it comes to Sharepoint, I don't understand what you mean by default user and permissions. AFAIK, there are none. You have to set up access per site. Sub-sites can inherit permissions from the parent if you want to. In our case, there are a couple of well-managed extranet applications.
Best regards
Tevfik
Did you also review the permissions of the Sharepoint users inside of Sharepoint?
You secured the server...but what about reviewing Sharepoint?
If you have not changed the default users and their permissions and roles, many Sharepoint gurus I know say there's work to be done inside of there depending on your needs and risk.
Why did you choose that template? What risks is it averting?
Tevfik Karagülle wrote:
Hi,
What I did for a customer was to use Microsoft's Bastion Host security template on a Windows 2003 Server Web edition and Sharepoint Service v2 w/SP1.
Best regards
Tevfik Karagulle ITEFIX Consulting
http://itefix.no
-----Original Message----- From: limpiezasgomez@terra.es [mailto:limpiezasgomez@terra.es] Sent: 17. august 2005 12:12 To: focus-ms@securityfocus.com Subject: SharePoint securization
Is there any resource where I could find information on steps to secure a SharePoint Services installation?
Thanks!
Pedro
-------------------------------------------------------------- ------------- -------------------------------------------------------------- -------------
-- Letting your vendors set your risk analysis these days? http://www.threatcode.com
--------------------------------------------------------------------------- ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: SharePoint securization, tevfik |
|---|---|
| Next by Date: | RE: SharePoint securization, Soluk, Kirk |
| Previous by Thread: | Re: SharePoint securization, tevfik |
| Next by Thread: | Re: SharePoint securization, tevfik |
| Indexes: | [Date] [Thread] [Top] [All Lists] |