Hit-highlighting does not rely on IIS authentication (328832)
The information in this article applies to:
- Microsoft Index Server 3.0
This article was previously published under Q328832 We strongly recommend that all users upgrade to Microsoft Internet Information Services (IIS) version 6.0 running on Microsoft Windows Server 2003. IIS 6.0 significantly increases Web infrastructure security. For more information about IIS security-related topics, visit the following Microsoft Web site: SYMPTOMS
Hit-highlighting may return documents that an anonymous user may not have access to if the user knows the hit-highlighting URL.CAUSE
Hit-highlighting with Webhits.dll only relies on the Microsoft Windows NT Access Control List (ACL) configuration. It does not rely on non-ACL based security mechanisms such as the following: - The Microsoft Internet Information Services (IIS) authentication configuration
- IP address restrictions on files within the Webroot
STATUSThis behavior is by design.
Modification Type: | Minor | Last Reviewed: | 6/22/2006 |
---|
Keywords: | kbprb KB328832 |
---|
|