Groups | Blog | Home


Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008


all groups > iis security > october 2003 > threads for october 15 - 21, 2003

Filter by week: 1 2 3 4 5

windows
Posted by gabriel n crema 2 at 10/21/2003 8:01:04 PM
hi my is gabriel wiundows help me windows xp 2001 ...more >>

Security For Child
Posted by Secure_Child at 10/21/2003 5:17:37 PM
Need Help on parental controls with my child. a friend told me there was a certain # website and i was wondering wat is it?...more >>

"iusr_servername" user logon errors
Posted by Mitch at 10/21/2003 3:59:15 PM
IIS Lockdown was installed along with Software Update Service. I receive the following w3svc error in the application log on the SUS server. __ The server was unable to logon the Windows NT account 'iusr_susservername' due to the following error: Logon failure: the user has not been granted th...more >>

Help installing IIS
Posted by Emily Waugh at 10/21/2003 3:45:52 PM
I am a beginner with IIS and I am simply trying to install it from my Windows XP professional CDROM. I select it and begin to install it. Then I get this error message every time: "Please insert the CD-ROM titled Windows XP Professional Service Pack 1" into your CD-ROM Drive and press e...more >>

Setting permissions on a virtual directory
Posted by greg at 10/21/2003 3:31:41 PM
When I go to create a virtual directory I do not get a window to allow me to specify credentials to access remote content. From the Web Site Content Directory window it goes directly to Access Permissions window. Any help would be very appreciated. ...more >>

Combining Anonymous + Integrated Windows auth
Posted by samson at 10/21/2003 2:16:04 PM
I am running Intranet with Win2k/IIS 5/asp.net and am trying to force Integrated Windows auth to IE users and give a friendly error message saying "change your browser to IE" to those who access the site with none-IE browsers. In IIS 5, when I enable both Anonymous access and Integrated Windows auth...more >>

IIS 6 and Installing SSL cert Please help
Posted by Nick at 10/21/2003 12:55:02 PM
I have a windows 2003 standard stand alone webserver (dedicated) and ordered a ssl cert from thawte which came as a .txt file, it is saved on the root of the HDD, i never used the built in wizzard to request the cert. I followed this article word for word, - and it said it was successful ...more >>

IIS website access 401.2 error
Posted by gray at 10/21/2003 11:11:28 AM
I have a web applicaton hosted on an intranet site. Even when the NTFS perms are set to full cntl for the everyone group & the IUSR account and the web site in IIS5 set to allow anonyomus access the site still requires a login to access it. It is set up on a static (internal) IP. Any i...more >>



Authentication with tomcat
Posted by Pascal Fluck at 10/21/2003 10:25:01 AM
Hello, I have a problem with IIS (I think): I'm doing a servlet that work under Tomcat 4.1. She ask for authentication and check in a database for user and password. She work fine directly in Tomcat access (8080 port). But when I try to launch it trougth IIS (isapi_redirect.dll : IIS ->...more >>

SSL negotiation: vulnerability or feature by design?
Posted by mirek at 10/21/2003 10:21:45 AM
Hello, How can I restrict IIS to use only specified SSL cipher suites? On Apache or Netscape servers it is quite easy but on IIS it seems impossible. If it can't be done it is for me IIS's big vulnerability (imagine the situation when a client doesn't have strong ciphers, only one weak, the...more >>

Administrator Account
Posted by Thomas at 10/21/2003 10:10:49 AM
I would like to use IIS in Windows XP to run an FTP server. I understand that the password is sent in plain text which would be visible to hackers. Also, the only option for authentication is an Administrator account. Is it possible to create an Administrator account which does not have...more >>

Insufficient access permission.
Posted by Outdoorbum at 10/21/2003 9:42:25 AM
I get an error when I try to create a new project in Visual Studio .NET telling me that it successfully created the web project but may not run prob=perly due to insufficient access permission. I go to IIS and set the security permission to scripts and executables but that does not solve t...more >>

IIS Manager error restting password
Posted by PVansch at 10/21/2003 7:56:18 AM
I'm Trying to rest passwords from a Mac using Outlook Web Access and get an error; IIS Manager for IIS server 6.0 Error number -2147024773 I will not alow me to change passwords....more >>

Error 401.2
Posted by Ravi at 10/21/2003 3:11:05 AM
Hi all, Am getting the 401.2 Error "Unauthorized: Logon failed due to server configuration" whenever i try to connect to a webserver using http://Ipaddress. But the same works fine when i give http://machinename Am not sure what exactly the problem is. BTW, i have "Integrated Windows authenticatio...more >>

Host headers and integrated windows authentication problems
Posted by Adam Nickells at 10/20/2003 9:52:14 PM
Hi, I posted this to the microsoft.public.inetserver.iis group, but then found this one and thought it might be a more appropriate place. here's the problem. It's fairly long......and it is seriously starting to annoy me too! :-) IIS5 - Windows 2000 Server I've created a new website ca...more >>

cgi-bin Permisions
Posted by Graeme at 10/20/2003 5:29:17 PM
When I try to execute a .exe in my cgi-bin directory, I am told that I do not have permission, even if I am logged on as the Administrator. I have tried enabling all options such as execute permissions and write access, but with no luck. The file is a compiled C++ program, and is being called...more >>

IIS - Permissions on Admin folder
Posted by JM at 10/20/2003 1:48:15 PM
I have a quick question: I have a site with the following structure(IIS5): \database\ (IUSR - read, write) \wwwroot\ (IUSR - read) \admin\ ("AdminUser" - read, disallowed prop.) \includes\ (IUSR - read, prop. from \wwwroot\) \images\ (IUSR...more >>

Restrict Internet Access
Posted by Mav at 10/20/2003 9:24:06 AM
Hi. I am having issues with 4 PC's on our network, each with a static IP address. They are being hit regularily with viruses because the user's are surfing non-business related sites, and downloading games etc. One virus was a dialler virus. I disabled the proxy settings in Internet Op...more >>

PC in continous state
Posted by Maureen at 10/20/2003 5:56:07 AM
We installed the latest hot fixes and 2 of my computers are stuck in "applying personal settings". it has been stuck for about an hour. Any suggestions? ...more >>

Missing Certificate Services
Posted by Steve at 10/18/2003 10:12:40 PM
This is probably a simple question, but I have been unable to find any documentation on it. I am trying to create an SSL certificate, but in the process noticed that I do not have Certificate Services installed. I found a Knowledge Base article that showed how to do this, but I seem to b...more >>

Firewalls
Posted by Shell at 10/18/2003 8:07:36 PM
Having just heard about Microsoft developers confessing to leaving at least 4 windows on XP that are subject to hackers gaining access to one's PC, I have been trying to research firewall info, but am confused. I've heard good and bad things about firewalls. Thing is, should I go buy a nam...more >>

One web application can be accessed only from server localhost; need LAN access.
Posted by no.spam NO[at]SPAM gte.net at 10/18/2003 5:53:09 PM
Windows 2000 Pro, IIS installed with all the latest updates. I have several web applications that can be accessed from any workstation on my LAN. However, I installed the Microsoft .NET SDK (1.0 and 1.1) and although I can get the Quickstart Tutorials to run, they only work from localhost on ...more >>

SSL: server certificate
Posted by coenve at 10/18/2003 11:24:56 AM
How to convert PEM file received from CA to a form usable by IIS5.1 (so that it appear under Available Certificates in Web Server Certificate Wizard)? I think I ought to use openssl, but i'm new to this, and command parameters are plentiful... Thanks, artur ...more >>

Is it Enought Security
Posted by Curtis at 10/17/2003 11:18:20 PM
I am hosting a site and I want to know if running using ICF and running Norton Antivirus would be enough security? Some file from the server will be shared as well with other users inside the network I do have a router, but it is causing the website to timeout when there is a period of in...more >>

Not able to access secure sites
Posted by Angie at 10/17/2003 4:09:36 PM
Recently when trying to view sites where I need a user name and password, or a secure site, it says the page cannot be displayed. Can anyone help? I am clueless. I've tried going into Internet Options -> Security and choosing a lower security zone, but that doesn't work. Thanks in advanc...more >>

Session Timeout in IIS & WSS
Posted by SuperMCSE at 10/17/2003 2:44:04 PM
I am trying to timeout users of my webserver in a manner that forces them to reauthenticate after some period of inactivity. It would be fine if this was the global setting. Can either IIS and/or WSS enable us to do this without modifying code? If we do have to modify code, can someone please poi...more >>

IIS Certificate Mapping password retreival
Posted by Craig Humphrey at 10/17/2003 2:01:40 PM
Hi, has anyone noticed that if you work with certificate mappings in IIS, programmatically, that you can enumerate all certificate mappings, and for each one, retrieve their username and password. Apparently the password is encrypted and then stored in the Metabase(?), but the only API for ...more >>

asp and Urlscan
Posted by Vincent O'Mara at 10/17/2003 1:28:08 PM
after loading ( and unloading ) URLScan, none of my asp's work. I think I have removed all of the security that the software installed, but the still don't work. Any help would be appreciated....more >>

Hijack Recovery
Posted by StevenMurphyrebel1 NO[at]SPAM netzon.net at 10/17/2003 1:05:32 PM
Any advice on two critical/fatal pirate attacks on my PC. Complete takeover on my computor while I was online and resulted in $1,700.00 cost to me. Attacker hijacked using Content Advisor icon in title bar. Microsoft Informed/Repaired/Pursued hijackers who damaged my PC. Any one from this ...more >>

SSL and Virtual Web Sites
Posted by Ken Krause at 10/17/2003 12:59:03 PM
I have a very general question. Can we use SSL on an IIS 5.0 web server that has dozens of virtual web sites, only some of which require SSL connections? Also, is there a primer somewhere on SSL and IIS 5.0 that ISN'T from Microsoft Press? TIA, Ken...more >>

windows pro 2000 SP4
Posted by brsienii at 10/17/2003 11:47:41 AM
SP4 does not download on my system what could be stoping it...more >>

Restrict by IP - .jsp pages
Posted by Gary at 10/17/2003 11:06:04 AM
I'm trying to restrict access to folders (and files contained within such folders) by IP Address. The functionality works great for .htm/.html files contained within the restricted directories but does not for .jsp pages (i.e. a link to a .htm page returns a "Not authorized" while a link to a .jsp ...more >>

IIS 5 security
Posted by Deb at 10/17/2003 10:17:55 AM
Hi all, When I log on to my server as admin of the MACHINE I can open my website to edit it. I want to be able to logon to the server as admin of the DOMAIN and be able to edit the website. When I do this I'm prompted with a user, password, and domain box. I type in the DOMAIN admin user, p...more >>

Outlook Express
Posted by David Levine at 10/17/2003 8:46:39 AM
I have somehow ended up with Outlook Express as my internet email provider (?) and now when someone sends me an email with an attachment I get the following message: oe removed access to the following unsafe attachments in your mail. I have tried several things including authorizing spec...more >>

Problems with security setting on the internet
Posted by Michelle at 10/17/2003 7:11:59 AM
I have a problem trying to change my active x setting as when i go to tools and internet options its comes up with the following error and i dont know how to change it any clues. This action has been cancelled due to restrictions in effect on this computer. Please contact your system a...more >>

W2K/IIS5 Server Rebooting
Posted by Anthony at 10/17/2003 6:20:09 AM
Hi all, I'm having a problem with a W2K/IIS5 server rebooting intermittingly over the past 2-1/2 weeks. Based upon snmp monitoring the I/O of the NIC, and comparing it to the uptime reports, the abnormal reboot coincides to high inbound/outbound traffic. I have a sniffer on it as of t...more >>

Just in Time debugger (script debugger)
Posted by terry at 10/17/2003 5:18:55 AM
How can I deactivate Microsoft's debugging program? permanently. Message constantly comes up and interrupts my e-mail and browsing. THEN I can't get rid of the (large) notice asking me if I want to use the current debugger. I do not need this "feature". Thanks....more >>

hijacked homepage
Posted by gl202 NO[at]SPAM hotmail.com at 10/17/2003 12:53:04 AM
Hello, I'm having problems with another web page taking over my default homepage on internet launch without my consent. Can anyone suggest a solution? ...more >>

Win2000 cannot password protect .asp page
Posted by Bryan O'Malley at 10/16/2003 2:54:33 PM
I am having the exact same problem as described below. I've followed the many instructions on the web for how to password protect a web site or directory. They work fine if you're trying to access .html pages. When you try to access a .asp page, however, you get three password boxes then a 40...more >>

Asp.Net.Vulnerability: Asp.Net buffer overflows (potential security problems)
Posted by dinis NO[at]SPAM ddplus.net at 10/16/2003 12:37:08 PM
Have anybody tested if the latest RPC vulnerabilities can be executed from an Asp.Net page running in an un-patched server? Since it is possible to make direct Win32 API calls from Asp.Net there is a high change that these vulnerabilities will work. If that is possible, please provide the test...more >>

Asp.Net.Vulnerability: Win32 API calls (potential security problems)
Posted by dinis NO[at]SPAM ddplus.net at 10/16/2003 12:29:49 PM
Asp.Net.Vulnerability: Win32 API calls (potential security problems) Since win32 calls are supported in Asp.Net and cannot be disabled when the website is running with 'Full trust', it is imperative to identify all potentially dangerous Win32 DLLs. Here is a short list of the ones we have iden...more >>

Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
Posted by dinis NO[at]SPAM ddplus.net at 10/16/2003 12:05:26 PM
At the moment the only method available to disable direct Win32 calls from Asp.Net pages (using for example: " Declare Function WinExec Lib "kernel32" Alias "WinExec" (ByVal lpCmdLine As String, ByVal nCmdShow As Long) As Long") is to reduce the website's trust level from 'Full trust' to 'Medium...more >>

securing files on IIS web directories
Posted by Leo at 10/16/2003 10:16:19 AM
is there a way to prevent someone from linking to my .asp files directly on my web site, for example http://www.mysite.com/public/file.asp and see the contents. I'd like to have them receive an error just like you do when you access an unauthorized folder. is there such a thing as a .htacc...more >>

content password
Posted by tarry at 10/16/2003 9:14:10 AM
How do unblock when forgotten password?And where do find answers to ? on thi8s page? Thanks...more >>

Supervisor
Posted by Rodney at 10/16/2003 8:46:52 AM
How do I recreate a supervisor password when I do not know the original. Thanks...more >>

Prevent direct access to files in IIS
Posted by Leo at 10/16/2003 8:36:56 AM
is there a way to prevent direct access to files in IIS like you can prvent access to directories? for example: http://www.mydomain.com/folder/folder.asp I have proper permissions for /folder/ but anyone can access /folder.asp if they know the file name. Is there some kind of file (like ...more >>

W2K, IIS Lockdown, and Word
Posted by Bryan Siders at 10/16/2003 8:22:36 AM
Environment: Windows 2000 Server SP4 + latest hotfixes, IIS with ASP enabled, Office 2000 (namely Word and Excel) I have a web application that creates a Word document from a template on the web server, saves the new document in a temporary location, and redirects the client to the newly- ...more >>

hijacking home page
Posted by john at 10/16/2003 4:47:00 AM
I have recently been hijacked on my start page of IE. If I change the start page from tools in IE it works until I reboot my machine. I have found the search page that is taking over in the Registry and have deleted it and renamed it. However once I reboot the start page is back to the one ...more >>

Software Update Service
Posted by SUS Help at 10/15/2003 6:50:59 PM
SUS - can you download just the cabs and txt file from somewhere so you do not need to setup a SUS server with access to the internet?...more >>

Mutual Authentication
Posted by Matt Frame at 10/15/2003 6:42:09 PM
I was told to turn on Mutual Authentication in IIS 5.0 to correct a problem I am having receiving a client certificate. Can anyone tell me where to do this? Thanks, Matt ...more >>

authenticated access prob. - can't login!
Posted by NickyW at 10/15/2003 5:56:15 PM
Hi, Can anyone help. I have a folder on my website that has 'anonymous access' and 'basic authentication' disabled, and requires 'intergrated Windows authentication'. This used to work fine, but all of a sudden it won't let me in! . The login box appears, I have checked the username, password a...more >>

Local login fails on Active Directory
Posted by David Hewitt at 10/15/2003 5:33:51 PM
We have installed Active Directory with one primary controller and one secondary controller. The secondary controller hosts a web site. The web site is properly accessed from computers outside the domain, but there are problems inside the domain. For example, no passwords are accepted f...more >>

Does anyone know how to add permitted SMTP relay IP to the SMTP server via script
Posted by Eric Smith at 10/15/2003 4:15:54 PM
Does anyone know how to add permitted SMTP relay IP to the SMTP server via script? I am writing a install script that will add the local loopback 127.0.0.1 to the SMTP server's relay permitted IP range. I couldn't find any reference on how to do this programmatically. Thanks Eric ...more >>

How to require domain information in IIS authentication
Posted by Eric at 10/15/2003 1:30:08 PM
I have IIS5 setup with only Integrated Windows Authentication. Users are prompted for Username/Password/Domain. Regardless of what they enter for domain (or if they leave domain blank), they are allowed in (as long as username and password are valid). I want to require the 3 pieces of i...more >>

Unknown user with Head and "?? icon found to have directory rights
Posted by rmitchell at 10/15/2003 1:06:26 PM
I have an Unknown user with "Head" and "?" icon found to have directory rights. Name is S-1-5-21-1083265345- 1937840800-64982 etc Where is this coming from? Is it a security breach?...more >>

Security patch for Explorer 6.0
Posted by J David at 10/15/2003 11:26:01 AM
SP 828750 will not install in Explorer 6 (message: "Explorer 6 i srequired to install this patch"). SP 818521 installed without problem. Note: After hiring Bellsouth DSL service the Explorer logo changed, ut Bellsouth claims there no changes to Explorer....more >>

How to secure PDFs on a site with page-level security?
Posted by beth.rosselot NO[at]SPAM mt.com at 10/15/2003 10:05:52 AM
I'm trying to solve a problem that seems like it should have a straightforward solution... I'm designing a site (IIS 4.0) with page-level security - each page that needs to be secure checks the credentials of the user in the session object and redirects to a log in page if the credentials ar...more >>

spam
Posted by Monica at 10/15/2003 9:52:15 AM
I am being inundated with spam with huge attachments which clog my mail box within hours. Half are supposedly from Microsoft, others from Postmaster or others with differing topic lines. I am deleting these but, without opening them, have no way of reporting them as spam. I have used up al...more >>

Windows NT server 4
Posted by john at 10/15/2003 6:29:11 AM
how can you view all internet sites visited by each machine in a network that runs on Window NT Server Version 40?...more >>

Remove Prono sites
Posted by Jay at 10/15/2003 5:43:28 AM
When I go into internet I get popup of a prono site asking me to subscribe thru a premium no how do I block this site from appearing. Jay ...more >>

Authentication by IIS (completed quesn)
Posted by Vikas at 10/15/2003 4:15:37 AM
Hi IIS provides 5 kinds of authentication viz.basic digest certificate integrated and anonymous. we have a .net application on the 'intranet' hosted on IIS 5.1 Win 2k server. we have an Active directory for accounts. This application will be accessed by A) Netscape browsers on Linux...more >>

remove directory browsing permissions
Posted by Mark at 10/15/2003 2:57:46 AM
Hi, A site running under IIS6 which has the Directory Browsing option turned off is still allowing a web user to browse directories in the site structure. Is there something further required to prevent this? Thanks, Mark...more >>


DevelopmentNow Blog