
17
Remove any Application Pools that are defined and not in use, such as the
DefaultAppPool
2.2.7 Anonymous Access Identity
By default IIS7 is setup to use the built-in Windows user account called
IUSR
for anonymous request
authentication. This means that when a request is made to your web site without authenticating with the web
server will use IUSR for the NTFS file permissions.
The IUSR account is setup to be a low privilege account, but there may be cases where you want to change
this to another account, for example if you want to isolate between multiple web sites or applications. The
IUSR account is inherently a member of the Users group which may allow for additional unnecessary access to
files.
2.2.8 Setup Request Filtering
Make sure that you have the Request Filtering Role Service for IIS installed. Under the IIS root (applicable for
all web sites) click on Request Filtering. Select the URL tab and click Deny Sequence.
When a string is added to the Deny Sequence if it is matched in the url IIS will return a 404 Not Found
response, and the request will not reach the ColdFusion server.
Summary of Contents for 38043740 - ColdFusion Standard - Mac
Page 5: ...5 ...
Page 12: ...12 Next Click Add Roles and select the checkbox next to Web Server IIS ...
Page 26: ...26 ...
Page 33: ...33 ...
Page 38: ...38 ...