all groups > iis security > october 2003 > threads for october 15 - 21, 2003
Filter by week: 1 2 3 4 5
windows
Posted by gabriel n crema 2 at 10/21/2003 8:01:04 PM
hi my is gabriel wiundows help me windows xp 2001 ... more >>
Security For Child
Posted by Secure_Child at 10/21/2003 5:17:37 PM
Need Help on parental controls with my child. a friend
told me there was a certain # website and i was wondering
wat is it?... more >>
"iusr_servername" user logon errors
Posted by Mitch at 10/21/2003 3:59:15 PM
IIS Lockdown was installed along with Software Update
Service. I receive the following w3svc error in the
application log on the SUS server.
__
The server was unable to logon the Windows NT account
'iusr_susservername' due to the following error: Logon
failure: the user has not been granted th... more >>
Help installing IIS
Posted by Emily Waugh at 10/21/2003 3:45:52 PM
I am a beginner with IIS and I am simply trying to install
it from my Windows XP professional CDROM. I select it and
begin to install it. Then I get this error message every
time:
"Please insert the CD-ROM titled Windows XP Professional
Service Pack 1" into your CD-ROM Drive and press e... more >>
Setting permissions on a virtual directory
Posted by greg at 10/21/2003 3:31:41 PM
When I go to create a virtual directory I do not get a
window to allow me to specify credentials to access
remote content. From the Web Site Content Directory
window it goes directly to Access Permissions window. Any
help would be very appreciated. ... more >>
Combining Anonymous + Integrated Windows auth
Posted by samson at 10/21/2003 2:16:04 PM
I am running Intranet with Win2k/IIS 5/asp.net and am trying to force Integrated Windows auth to IE users and give a friendly error message saying "change your browser to IE" to those who access the site with none-IE browsers. In IIS 5, when I enable both Anonymous access and Integrated Windows auth... more >>
IIS 6 and Installing SSL cert Please help
Posted by Nick at 10/21/2003 12:55:02 PM
I have a windows 2003 standard stand alone webserver
(dedicated) and ordered a ssl cert from thawte which
came as a .txt file, it is saved on the root of the HDD,
i never used the built in wizzard to request the cert. I
followed this article word for word, - and it said it was
successful ... more >>
IIS website access 401.2 error
Posted by gray at 10/21/2003 11:11:28 AM
I have a web applicaton hosted on an intranet site. Even
when the NTFS perms are set to full cntl for the everyone
group & the IUSR account and the web site in IIS5 set to
allow anonyomus access the site still requires a login to
access it. It is set up on a static (internal) IP. Any
i... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Authentication with tomcat
Posted by Pascal Fluck at 10/21/2003 10:25:01 AM
Hello,
I have a problem with IIS (I think):
I'm doing a servlet that work under Tomcat 4.1. She ask for authentication
and check in a database for user and password.
She work fine directly in Tomcat access (8080 port).
But when I try to launch it trougth IIS (isapi_redirect.dll : IIS ->... more >>
SSL negotiation: vulnerability or feature by design?
Posted by mirek at 10/21/2003 10:21:45 AM
Hello,
How can I restrict IIS to use only specified SSL cipher suites? On
Apache or Netscape servers it is quite easy but on IIS it seems
impossible. If it can't be done it is for me IIS's big vulnerability
(imagine the situation when a client doesn't have strong ciphers, only
one weak, the... more >>
Administrator Account
Posted by Thomas at 10/21/2003 10:10:49 AM
I would like to use IIS in Windows XP to run an FTP
server. I understand that the password is sent in plain
text which would be visible to hackers. Also, the only
option for authentication is an Administrator account.
Is it possible to create an Administrator account which
does not have... more >>
Insufficient access permission.
Posted by Outdoorbum at 10/21/2003 9:42:25 AM
I get an error when I try to create a new project in
Visual Studio .NET telling me that it successfully created
the web project but may not run prob=perly due to
insufficient access permission. I go to IIS and set the
security permission to scripts and executables but that
does not solve t... more >>
IIS Manager error restting password
Posted by PVansch at 10/21/2003 7:56:18 AM
I'm Trying to rest passwords from a Mac using Outlook Web Access and get an error;
IIS Manager for IIS server 6.0
Error number -2147024773
I will not alow me to change passwords.... more >>
Error 401.2
Posted by Ravi at 10/21/2003 3:11:05 AM
Hi all,
Am getting the 401.2 Error "Unauthorized: Logon failed due to server configuration" whenever i try to connect to a webserver using http://Ipaddress.
But the same works fine when i give http://machinename
Am not sure what exactly the problem is.
BTW, i have "Integrated Windows authenticatio... more >>
Host headers and integrated windows authentication problems
Posted by Adam Nickells at 10/20/2003 9:52:14 PM
Hi,
I posted this to the microsoft.public.inetserver.iis group, but then found
this one and thought it might be a more appropriate place.
here's the problem. It's fairly long......and it is seriously starting to
annoy me too! :-)
IIS5 - Windows 2000 Server
I've created a new website ca... more >>
cgi-bin Permisions
Posted by Graeme at 10/20/2003 5:29:17 PM
When I try to execute a .exe in my cgi-bin directory, I am told that I do
not have permission, even if I am logged on as the Administrator. I have
tried enabling all options such as execute permissions and write access, but
with no luck.
The file is a compiled C++ program, and is being called... more >>
IIS - Permissions on Admin folder
Posted by JM at 10/20/2003 1:48:15 PM
I have a quick question:
I have a site with the following structure(IIS5):
\database\ (IUSR - read, write)
\wwwroot\ (IUSR - read)
\admin\ ("AdminUser" - read, disallowed prop.)
\includes\ (IUSR - read, prop. from \wwwroot\)
\images\ (IUSR... more >>
Restrict Internet Access
Posted by Mav at 10/20/2003 9:24:06 AM
Hi. I am having issues with 4 PC's on our network, each
with a static IP address. They are being hit regularily
with viruses because the user's are surfing non-business
related sites, and downloading games etc. One virus was a
dialler virus.
I disabled the proxy settings in Internet Op... more >>
PC in continous state
Posted by Maureen at 10/20/2003 5:56:07 AM
We installed the latest hot fixes and 2 of my computers are stuck in "applying personal settings". it has been stuck for about an hour. Any suggestions? ... more >>
Missing Certificate Services
Posted by Steve at 10/18/2003 10:12:40 PM
This is probably a simple question, but I have been
unable to find any documentation on it.
I am trying to create an SSL certificate, but in the
process noticed that I do not have Certificate Services
installed. I found a Knowledge Base article that showed
how to do this, but I seem to b... more >>
Firewalls
Posted by Shell at 10/18/2003 8:07:36 PM
Having just heard about Microsoft developers confessing to
leaving at least 4 windows on XP that are subject to
hackers gaining access to one's PC, I have been trying to
research firewall info, but am confused. I've heard good
and bad things about firewalls.
Thing is, should I go buy a nam... more >>
One web application can be accessed only from server localhost; need LAN access.
Posted by no.spam NO[at]SPAM gte.net at 10/18/2003 5:53:09 PM
Windows 2000 Pro, IIS installed with all the latest updates.
I have several web applications that can be accessed from any
workstation on my LAN. However, I installed the Microsoft .NET SDK
(1.0 and 1.1) and although I can get the Quickstart Tutorials to run,
they only work from localhost on ... more >>
SSL: server certificate
Posted by coenve at 10/18/2003 11:24:56 AM
How to convert PEM file received from CA to a form usable by IIS5.1 (so that
it appear under Available Certificates in Web Server Certificate Wizard)? I
think I ought to use openssl, but i'm new to this, and command parameters
are plentiful...
Thanks,
artur
... more >>
Is it Enought Security
Posted by Curtis at 10/17/2003 11:18:20 PM
I am hosting a site and I want to know if running using
ICF and running Norton Antivirus would be enough
security? Some file from the server will be shared as
well with other users inside the network
I do have a router, but it is causing the website to
timeout when there is a period of in... more >>
Not able to access secure sites
Posted by Angie at 10/17/2003 4:09:36 PM
Recently when trying to view sites where I need a user
name and password, or a secure site, it says the page
cannot be displayed. Can anyone help? I am clueless.
I've tried going into Internet Options -> Security and
choosing a lower security zone, but that doesn't work.
Thanks in advanc... more >>
Session Timeout in IIS & WSS
Posted by SuperMCSE at 10/17/2003 2:44:04 PM
I am trying to timeout users of my webserver in a manner that forces them to
reauthenticate after some period of inactivity. It would be fine if this was
the global setting. Can either IIS and/or WSS enable us to do this without
modifying code? If we do have to modify code, can someone please poi... more >>
IIS Certificate Mapping password retreival
Posted by Craig Humphrey at 10/17/2003 2:01:40 PM
Hi,
has anyone noticed that if you work with certificate mappings in IIS,
programmatically, that you can enumerate all certificate mappings, and for
each one, retrieve their username and password.
Apparently the password is encrypted and then stored in the Metabase(?), but
the only API for ... more >>
asp and Urlscan
Posted by Vincent O'Mara at 10/17/2003 1:28:08 PM
after loading ( and unloading ) URLScan, none of my asp's
work. I think I have removed all of the security that the
software installed, but the still don't work. Any help
would be appreciated.... more >>
Hijack Recovery
Posted by StevenMurphyrebel1 NO[at]SPAM netzon.net at 10/17/2003 1:05:32 PM
Any advice on two critical/fatal pirate attacks on my PC.
Complete takeover on my computor while I was online and
resulted in $1,700.00 cost to me.
Attacker hijacked using Content Advisor icon in title
bar. Microsoft Informed/Repaired/Pursued hijackers who
damaged my PC.
Any one from this ... more >>
SSL and Virtual Web Sites
Posted by Ken Krause at 10/17/2003 12:59:03 PM
I have a very general question. Can we use SSL on an IIS
5.0 web server that has dozens of virtual web sites, only
some of which require SSL connections?
Also, is there a primer somewhere on SSL and IIS 5.0 that
ISN'T from Microsoft Press?
TIA,
Ken... more >>
windows pro 2000 SP4
Posted by brsienii at 10/17/2003 11:47:41 AM
SP4 does not download on my system what could be stoping it... more >>
Restrict by IP - .jsp pages
Posted by Gary at 10/17/2003 11:06:04 AM
I'm trying to restrict access to folders (and files contained within such folders) by IP Address. The functionality works great for .htm/.html files contained within the restricted directories but does not for .jsp pages (i.e. a link to a .htm page returns a "Not authorized" while a link to a .jsp ... more >>
IIS 5 security
Posted by Deb at 10/17/2003 10:17:55 AM
Hi all,
When I log on to my server as admin of the MACHINE I can open my website to
edit it. I want to be able to logon to the server as admin of the DOMAIN
and be able to edit the website. When I do this I'm prompted with a user,
password, and domain box. I type in the DOMAIN admin user, p... more >>
Outlook Express
Posted by David Levine at 10/17/2003 8:46:39 AM
I have somehow ended up with Outlook Express as my
internet email provider (?) and now when someone sends me
an email with an attachment I get the following message:
oe removed access to the following unsafe attachments in
your mail.
I have tried several things including authorizing spec... more >>
Problems with security setting on the internet
Posted by Michelle at 10/17/2003 7:11:59 AM
I have a problem trying to change my active x setting as
when i go to tools and internet options its comes up with
the following error and i dont know how to change it any
clues.
This action has been cancelled due to restrictions in
effect on this computer. Please contact your system
a... more >>
W2K/IIS5 Server Rebooting
Posted by Anthony at 10/17/2003 6:20:09 AM
Hi all,
I'm having a problem with a W2K/IIS5 server rebooting
intermittingly over the past 2-1/2 weeks. Based upon
snmp monitoring the I/O of the NIC, and comparing it to
the uptime reports, the abnormal reboot coincides to high
inbound/outbound traffic. I have a sniffer on it as of
t... more >>
Just in Time debugger (script debugger)
Posted by terry at 10/17/2003 5:18:55 AM
How can I deactivate Microsoft's debugging program?
permanently. Message constantly comes up and interrupts
my e-mail and browsing.
THEN I can't get rid of the (large) notice asking me if I
want to use the current debugger. I do not need
this "feature". Thanks.... more >>
hijacked homepage
Posted by gl202 NO[at]SPAM hotmail.com at 10/17/2003 12:53:04 AM
Hello,
I'm having problems with another web page taking over my
default homepage on internet launch without my consent.
Can anyone suggest a solution?
... more >>
Win2000 cannot password protect .asp page
Posted by Bryan O'Malley at 10/16/2003 2:54:33 PM
I am having the exact same problem as described below. I've followed the
many instructions on the web for how to password protect a web site or
directory. They work fine if you're trying to access .html pages. When you
try to access a .asp page, however, you get three password boxes then a
40... more >>
Asp.Net.Vulnerability: Asp.Net buffer overflows (potential security problems)
Posted by dinis NO[at]SPAM ddplus.net at 10/16/2003 12:37:08 PM
Have anybody tested if the latest RPC vulnerabilities can be executed
from an Asp.Net page running in an un-patched server? Since it is
possible to make direct Win32 API calls from Asp.Net there is a high
change that these vulnerabilities will work.
If that is possible, please provide the test... more >>
Asp.Net.Vulnerability: Win32 API calls (potential security problems)
Posted by dinis NO[at]SPAM ddplus.net at 10/16/2003 12:29:49 PM
Asp.Net.Vulnerability: Win32 API calls (potential security problems)
Since win32 calls are supported in Asp.Net and cannot be disabled when
the website is running with 'Full trust', it is imperative to identify
all potentially dangerous Win32 DLLs. Here is a short list of the ones
we have iden... more >>
Asp.Net.Vulnerability: Full Trust (current security problems and possible solutions)
Posted by dinis NO[at]SPAM ddplus.net at 10/16/2003 12:05:26 PM
At the moment the only method available to disable direct Win32 calls
from Asp.Net pages (using for example: " Declare Function WinExec Lib
"kernel32" Alias "WinExec" (ByVal lpCmdLine As String, ByVal nCmdShow
As Long) As Long") is to reduce the website's trust level from 'Full
trust' to 'Medium... more >>
securing files on IIS web directories
Posted by Leo at 10/16/2003 10:16:19 AM
is there a way to prevent someone from linking to my .asp
files directly on my web site, for example
http://www.mysite.com/public/file.asp and see the
contents. I'd like to have them receive an error just like
you do when you access an unauthorized folder. is there
such a thing as a .htacc... more >>
content password
Posted by tarry at 10/16/2003 9:14:10 AM
How do unblock when forgotten password?And where do find
answers to ? on thi8s page? Thanks... more >>
Supervisor
Posted by Rodney at 10/16/2003 8:46:52 AM
How do I recreate a supervisor password when I do not know
the original.
Thanks... more >>
Prevent direct access to files in IIS
Posted by Leo at 10/16/2003 8:36:56 AM
is there a way to prevent direct access to files in IIS
like you can prvent access to directories?
for example: http://www.mydomain.com/folder/folder.asp
I have proper permissions for /folder/ but anyone can
access /folder.asp if they know the file name. Is there
some kind of file (like ... more >>
W2K, IIS Lockdown, and Word
Posted by Bryan Siders at 10/16/2003 8:22:36 AM
Environment: Windows 2000 Server SP4 + latest hotfixes,
IIS with ASP enabled, Office 2000 (namely Word and Excel)
I have a web application that creates a Word document from
a template on the web server, saves the new document in a
temporary location, and redirects the client to the newly-
... more >>
hijacking home page
Posted by john at 10/16/2003 4:47:00 AM
I have recently been hijacked on my start page of IE. If
I change the start page from tools in IE it works until I
reboot my machine.
I have found the search page that is taking over in the
Registry and have deleted it and renamed it. However once
I reboot the start page is back to the one ... more >>
Software Update Service
Posted by SUS Help at 10/15/2003 6:50:59 PM
SUS - can you download just the cabs and txt file from
somewhere so you do not need to setup a SUS server with
access to the internet?... more >>
Mutual Authentication
Posted by Matt Frame at 10/15/2003 6:42:09 PM
I was told to turn on Mutual Authentication in IIS 5.0 to correct a problem
I am having receiving a client certificate. Can anyone tell me where to do
this?
Thanks,
Matt
... more >>
authenticated access prob. - can't login!
Posted by NickyW at 10/15/2003 5:56:15 PM
Hi,
Can anyone help.
I have a folder on my website that has 'anonymous access' and 'basic
authentication' disabled, and requires 'intergrated Windows authentication'.
This used to work fine, but all of a sudden it won't let me in! . The login
box appears, I have checked the username, password a... more >>
Local login fails on Active Directory
Posted by David Hewitt at 10/15/2003 5:33:51 PM
We have installed Active Directory with one primary
controller and one secondary controller.
The secondary controller hosts a web site.
The web site is properly accessed from computers outside
the domain, but there are problems inside the domain.
For example, no passwords are accepted f... more >>
Does anyone know how to add permitted SMTP relay IP to the SMTP server via script
Posted by Eric Smith at 10/15/2003 4:15:54 PM
Does anyone know how to add permitted SMTP relay IP to the SMTP server via
script?
I am writing a install script that will add the local loopback 127.0.0.1 to
the SMTP server's relay permitted IP range. I couldn't find any reference on
how to do this programmatically.
Thanks
Eric
... more >>
How to require domain information in IIS authentication
Posted by Eric at 10/15/2003 1:30:08 PM
I have IIS5 setup with only Integrated Windows
Authentication. Users are prompted for
Username/Password/Domain. Regardless of what they enter
for domain (or if they leave domain blank), they are
allowed in (as long as username and password are valid).
I want to require the 3 pieces of i... more >>
Unknown user with Head and "?? icon found to have directory rights
Posted by rmitchell at 10/15/2003 1:06:26 PM
I have an Unknown user with "Head" and "?" icon found to
have directory rights. Name is S-1-5-21-1083265345-
1937840800-64982 etc
Where is this coming from?
Is it a security breach?... more >>
Security patch for Explorer 6.0
Posted by J David at 10/15/2003 11:26:01 AM
SP 828750 will not install in Explorer 6
(message: "Explorer 6 i srequired to install this
patch").
SP 818521 installed without problem.
Note: After hiring Bellsouth DSL service the Explorer
logo changed, ut Bellsouth claims there no changes to
Explorer.... more >>
How to secure PDFs on a site with page-level security?
Posted by beth.rosselot NO[at]SPAM mt.com at 10/15/2003 10:05:52 AM
I'm trying to solve a problem that seems like it should have a
straightforward solution...
I'm designing a site (IIS 4.0) with page-level security - each page
that needs to be secure checks the credentials of the user in the
session object and redirects to a log in page if the credentials
ar... more >>
spam
Posted by Monica at 10/15/2003 9:52:15 AM
I am being inundated with spam with huge attachments
which clog my mail box within hours. Half are supposedly
from Microsoft, others from Postmaster or others with
differing topic lines. I am deleting these but, without
opening them, have no way of reporting them as spam. I
have used up al... more >>
Windows NT server 4
Posted by john at 10/15/2003 6:29:11 AM
how can you view all internet sites visited by each
machine in a network that runs on Window NT Server
Version 40?... more >>
Remove Prono sites
Posted by Jay at 10/15/2003 5:43:28 AM
When I go into internet I get popup of a prono site
asking me to subscribe thru a premium no how do I block
this site from appearing.
Jay ... more >>
Authentication by IIS (completed quesn)
Posted by Vikas at 10/15/2003 4:15:37 AM
Hi
IIS provides 5 kinds of authentication viz.basic digest
certificate integrated and anonymous.
we have a .net application on the 'intranet' hosted on IIS
5.1 Win 2k server. we have an Active directory for
accounts.
This application will be accessed by
A) Netscape browsers on Linux... more >>
remove directory browsing permissions
Posted by Mark at 10/15/2003 2:57:46 AM
Hi,
A site running under IIS6 which has the Directory
Browsing option turned off is still allowing a web user
to browse directories in the site structure. Is there
something further required to prevent this?
Thanks,
Mark... more >>
|