Writing a new IIS policy : summary: Parent Paths allows you to use '..' in calls to MapPath and the like. By default this option is enabled and should be disabled. To disable this option go to the root of the Web site in question, right click select Properties | Home Directory | Configuration | App Options and uncheck Enable Parent Paths. my question: What security hole/hack does this create if left enabled?. Rob
This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:32:15 PDT