[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference chefs::ms-exchange

Title:Microsoft Exchange Server
Notice:
Moderator:FLASK2::SYSTEM
Created:Fri Feb 17 1995
Last Modified:Thu Jun 05 1997
Last Successful Update:Thu Jun 05 1997
Number of topics:1099
Total number of notes:5174

1016.0. "Exchange V5 and Web (HTTP) access" by XANADU::CUMMINGS (Jerry Cummings, TeamLinks) Mon Apr 21 1997 18:23

I just upgraded an Exchange V4 server to V5 and enabled
Active Server Pages with it. It seems that I can look
at any mailbox if I'm logged into the domain with an
account that has admin priveleges and then use the web
interface.

This seems like a security problem. I hope I've overlooked
something in the setup. Does anyone know anything about
this problem?

Thanks,
Jerry
T.RTitleUserPersonal
Name
DateLines
1016.1Is it different for a locally created profile ?.tunsrv2-tunnel.imc.das.dec.com::fosterStan Foster - foster@mail.dec.comWed Apr 23 1997 07:2115
The web connector uses the credentials for whatever account you 
logged in with so if admin has permissions to access any mailbox you 
will get those rights via the web connector the same as you would by 
creating a local profile and accessing a mailbox while logged into 
admin.

If you are able to gain access via the web connector but not from a 
local profile while logged into admin then that would be cause for 
concern.

So I'd start by creating a profile on a Win95 or NT client system 
while logged in as administrator and see if the behaviour is 
different. If it is the same then check who has what permissions. If 
it is different (you are denied access from the local profile but can 
still access via the web) then we can investigate more.. 
1016.2XANADU::CUMMINGSJerry Cummings, TeamLinksWed Apr 23 1997 21:006
Yes, logged in as Administrator I was able to add a profile that
access a different mailbox. Would you happen to know what priv
I would remove from admin accounts to disable this? 

Thanks,
Jerry
1016.3I think it is just a question of permissionstunsrv2-tunnel.imc.das.dec.com::fosterStan Foster - foster@mail.dec.comFri Apr 25 1997 06:475
I dont think it is a question of removing privs from Admin but 
setting the appropriate permissions on Exchange objects to restrict 
what Admin can do. I dont recall offhand the exact permissions on 
what objects you would need to adjust but if you cant find it I can 
go ask an expert.