Brent Gardner's Blog

It's all about the code.

Syndication

Tags

    No tags have been created or used yet.

Navigation

Retrieve IUSR Password

Anytime you setup a password for a service it gets stored with reversible encryption. The software needs to be able to retrieve the password to log in as that user. IIS is no exception. When you setup the IUSR password, it gets encrypted and stored on disk, but since the encryption is reversible, you can still get at it. MS seems to want to hide this from you: AdsUtil and MetaBaseExplorer have access to the password, but obfuscate it before display. Luckily I wrote my own utility which will let you see the password. 

If you haven't yet, just download AdsiExplorer, and browse to your website. The AnonymousUserPass property contains the IUSR password in plain text!

Happy password retrieval,

Brent

Published Tuesday, June 26, 2007 12:25 PM by Brent

Comments

No Comments

Anonymous comments are disabled