Saul
Fri Jul 25 03:08:04 CDT 2008
1. Not all _layouts pages are restricted - when you click on View all
site content link on your left nav, you goto /_layouts/viewlsts.aspx,
which is not restricted.
2. To replicate the issue, if you have a WSS 3.0 site
- enable anonymous authentication enabled (
http://tinyurl.com/5glx),
- click on Site Actions - Create, under Libraries, select Picture
Library, and create new one.
- Upload an image.
- Switch to anonymous access, ensure that there are no saved
credentials on your machine (check IE options, browsing history,
delete password, delete cookies and check Start -> Control Panel ->
User Accounts -> Advanced -> Manage Password).
- Then on the image library, tick the little checkbox next to image
- Click Actions -> Downloads
The browser should then goto /_layouts/Dladvopt.aspx and prompt you
with an login box.