Windows servers don't use Linux-style chmod numbers like 755 or 644. Instead, each folder has an access control list (ACL) that says which Windows accounts can read or write it. Your website's code runs under its own application pool identity, and that identity needs write access wherever your site saves files.
This article shows how to save files the right way, what to do when you see “Access denied”, and how to stop an uploads folder being used to run malicious scripts.
Where to save files
| Folder | Use it for | Visitors can download? |
|---|---|---|
App_Data | Private files: generated reports, logs, file-based databases, uploaded documents you serve through code | No, IIS blocks it |
An uploads folder in the web root | Public files: product images, avatars | Yes |
bin | Never write here | No |
Writing any file into bin (or changing web.config) from code makes ASP.NET restart the application, which logs everyone out and slows the site.
Build paths correctly
Never hard-code a path such as C:\inetpub\wwwroot\uploads or copy one from your PC. Your site's real path on the server is different. Let the server work it out:
// ASP.NET (C#) var folder = Server.MapPath("~/uploads"); // or HostingEnvironment.MapPath var safeName = Guid.NewGuid().ToString("N") + Path.GetExtension(file.FileName).ToLowerInvariant(); file.SaveAs(Path.Combine(folder, safeName));
' Classic ASP (VBScript) Dim folder folder = Server.MapPath("/uploads")
// PHP $folder = __DIR__ . '/uploads';
If you get “Access to the path … is denied”
- Check the path is inside your site. Print it temporarily (
Response.Write(folder)) and make sure it is under your web root, not a folder from your development PC. - Check the folder exists. Create it with FTP or File Manager first, or create it in code with
Directory.CreateDirectory(folder). - Check the file isn't in use or read-only. Close streams with
usingblocks; a file opened by one request can't be overwritten by another. Files uploaded by FTP from some tools can carry a read-only flag. - Ask us to grant write access. If the path is right and the error remains, open a ticket with the exact folder path (for example
/public_html/uploads) and we will check the permissions for your site.
Stop scripts running from the uploads folder
If an attacker manages to upload shell.aspx or shell.php to a public folder and then opens it in a browser, they can take over your site. Place this web.config inside the uploads folder so IIS refuses to run or serve script files there:
<?xml version="1.0" encoding="UTF-8"?> <configuration> <system.webServer> <security> <requestFiltering> <fileExtensions allowUnlisted="true"> <add fileExtension=".asp" allowed="false" /> <add fileExtension=".aspx" allowed="false" /> <add fileExtension=".ashx" allowed="false" /> <add fileExtension=".asmx" allowed="false" /> <add fileExtension=".php" allowed="false" /> </fileExtensions> </requestFiltering> </security> <handlers accessPolicy="Read" /> </system.webServer> </configuration>
Requests for those extensions now get a 404, and accessPolicy="Read" stops any handler that runs scripts. If adding the <handlers> line causes a 500.19 “locked” error, remove that line; the request filtering part still blocks the listed extensions.
Safe upload checklist
- Allow-list extensions (for example
.jpg,.png,.webp,.pdf) and reject everything else. Don't rely on the browser's content type. - Rename files to a random name as in the code above. This avoids overwriting, odd characters and double extensions like
photo.jpg.aspx. - Limit the size in code and in
web.config(maxRequestLengthandmaxAllowedContentLength; see web.config Essentials). - Keep private documents in
App_Dataand serve them through a page that checks the user is logged in. - Watch your disk space. Uploads count towards your plan's storage, so delete files you no longer need.
PHP and WordPress
The same rules apply. If WordPress can't upload media or install updates, it is usually because the wp-content folder isn't writable; open a ticket with the path. The web.config above works in wp-content/uploads too.
Need help?
If something doesn't work as described, open a support ticket from your client area or message us on WhatsApp at 01818160926. Tell us the folder path and the exact error, and we will check the permissions for you.
Categories
Written by
FimuroHost Team
Technical Writer