Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > october 2003 > threads for october 22 - 28, 2003

Filter by week: 1 2 3 4 5

NT Authority/System
Posted by Linda at 10/28/2003 8:19:10 PM
I'm not sure if this is the right newsgroup. But every time I am on the internet, I get this message (about ten minutes into it)telling me that there was an error, send an error report to Microsoft or not. I have tried both ways, and I get the message that NT Authoriy/System is shutting do...more >>


authentication steps???
Posted by arth at 10/28/2003 6:59:20 PM
Hi, We have a 'mixed domain' with NT4, W2k and W2k3 servers, NT4,W2k and XP clients, IIS 5, 5.1 and 6, IE5.5 and 6. All our web apps use Basic or Integrated Authentication. I am wondering if it would reduce the OS/network load if I made a lot of the resources (eg gifs, pop-ups, includes ...more >>

Setting up a restricted access website on IIS with ASP
Posted by slam NO[at]SPAM larp.com at 10/28/2003 4:45:09 PM
This may be rather basic in nature, but... If someone can point me to a tutorial on setting this up, or give instructions, that would be great. I have done some searches, but unfortunately the questions/responses seem to assume too much previous knowledge, or do not address some of the topics...more >>

Accessing FTP via RAS
Posted by Ben Joseph at 10/28/2003 3:01:05 PM
Hi All, We dial-in into 2003 server and doing FTP to another NT-4 server. It looks like based on the IP address assigned to the remote client - FTP some time works and other time it gives error Cannot connect to remote host. At that time we're not able to ping the remote server. This specially happ...more >>

Authentication login?
Posted by booner at 10/28/2003 1:29:28 PM
I've written a web application (using ASP) and sporadically we get a login dialog asking for username, password and domain (this is not a web form that I created for logging in). The web server is IIS 5.0 running on a Windows 2000 box. Can someone point me at what might be causing this? BB...more >>

ip restrictions deny access
Posted by iisquestions? at 10/28/2003 12:16:07 PM
I would like to deny access to computers from 102.168.0.0 - 102.168.254.254 with a subnet mask of 255.255.255.0 When I enter in 102.168.0.0 with subnet mask 255.255.255.0 - it does not deny. when I enter in 102.168.0.0 subnet 255.255.0.0 it DOES DENY. My iis server is on subnet 255.255.0.0, but I...more >>

IIS 6, ASP.NET, Web Request, impersonation and 401
Posted by Seb at 10/28/2003 11:12:19 AM
Hi, I have an ASP.NET app that sends HTTP WebRequests to an exchange server that requires NTLM authentication. To do so, the ASP.NET app is configured to impersonate the current user. Everything works fine, except on our test Win 2003 machine, where the web requests fail with a 401 answ...more >>

DSN connection fails when Basic authentication turned on
Posted by Drew at 10/28/2003 9:43:24 AM
Just rebuilt my Web server and added back all the user accounts. When I switch on Basic Authentication, the ASP that pull information from the SQL server fail to make the DSN connection with the following message:- "Microsoft OLE DB Provider for ODBC Drivers (0x80004005) [Microsoft][ODBC SQL...more >>



Issues with coldfusion pages and anonymous access
Posted by Dennis at 10/28/2003 1:56:04 AM
Well I am fairly certain this is something I am somehow foolishly missing in IIS configuration, I have a subfolder below my default site that has a complete coldfusion app I would like to run, but I would like it to be open to read by anonymous iusr. Now for some strange reason, the folder serves HT...more >>

Authentication against trusting domains in IIS 6.0
Posted by Jayashree Iyer at 10/27/2003 4:08:04 PM
We just migrated to IIS 6.0, and in our previous production environment, we had basic authentication against "\" for authenticating across trusted domains. The same setting does not work with IIS 6.0. Is there a new way to authenticate across domains in IIS 6? ...more >>

HTTP 403.4 Error
Posted by Jim at 10/27/2003 2:12:16 PM
I'm trying to get a distance learning software package (Flex Training by Online Development) up. This software is based primarily on Active Server Pages (ASP). It works fine without SSL/128 enabled. But once I enable SSL, the final page that is supposed to launch the "class" returns a H...more >>

http:// to https:// redirect
Posted by stp at 10/27/2003 1:29:03 PM
Does anyone know how to redirect http:// requests that hit a SSL site automaticlly to https:// ??? I'm not a programmer so please go easy on my... :-) Thanks!!! Scott...more >>

BUG?: Can't disable "Trusted" for Certificates Issued by MS Certificate Server
Posted by Ohaya at 10/27/2003 10:32:15 AM
Hi, I think that I have encountered a somewhat serious "bug" somewhere. I can't tell if it's a CryptoAPI bug, an IIS bug, or whatever, so I'm cross-posting this to several newsgroups. This seems like (to me) a rather serious problem, and I'll try to describe what's happening as best I can, ...more >>

Application using IUSR_Anonymous
Posted by Harkin Banks at 10/27/2003 10:17:40 AM
We have internally developed apps running on our IIS 5.0 Intranet server. These apps use the anonymous login to query AD for object resolution in order to process security permissions. This worked great with W2K DCs. Since we have upgraded to W2K3 DCs only, it has stopped working. My educated gue...more >>

Windows authentication
Posted by Steve at 10/27/2003 6:19:53 AM
Hi all, I have an Intranet Win2K server running IIS 5. 3 websites are defined - the default on port 80, and the admin site and a sharepoint site on alternate ports. Security is set to Window authentication for all sites, and NTFS security to the appropriate directories is set accordingly....more >>

SSL problems since install of new certificate
Posted by andy NO[at]SPAM leates.com at 10/27/2003 5:16:41 AM
Hi all I installed a new SSL certificate this morning on one of our web servers [NT 4.0 SP6a with IIS 4.0]. I can see in Key Manager that the certificate has been installed OK and is valid, but the SSL secured area of our web site no longer functions - just get page can not be displayed. I ...more >>

Pro's & Con's...
Posted by Matt Rowe at 10/27/2003 4:47:15 AM
Hello all, Before I get to babbling on, please feel free to correct me if I'm wrong at any point, and please forgive the massive long post for such a simple queery! I'm in the process of designing the infrastructure for when we move to Win2k network/domain. I'm not very experianced in I...more >>

Hackers trying to break into IIS
Posted by Don Schultz at 10/26/2003 4:48:36 PM
I had some hackers break into my web server when I was running NT 4.0. I upgraded to 2000 and put URLScan on the system and it appears to have stopped them but they continue to try and gain access. Most often now they simply give up after entering a command that looks like this in the log ...more >>

urlscan log
Posted by karl at 10/25/2003 9:04:08 PM
Hi, Anyone knows what the below entry in a urlscan log means? "Received malformed request which resulted in error 50 while modifying the 'SERVER' header.Request will be rejected with response code 400." I looked up the corresponding entry in the weblog, and it was served with a 200 status...more >>

Broadcasts, GET & SEARCH attacks on the server causing havoc
Posted by Paul at 10/25/2003 6:27:33 PM
It started out with a massive comms bill. 1GB over the download limit for a month. I couldn't work it out, but the same thing happened the next month, and this month. I started to have a look around.. My ISP shows we are downloading roughly 100MB every 24 hours which is ridiculous for the type...more >>

External access to HTTP
Posted by David Martin at 10/25/2003 11:50:38 AM
I set up a simple web page which I can access from inside the office. I configured my dsl router to direct HTTP requests to my IIS server. But for some reason, from outside, I get the message, we "cannot find the web site." Does IIS have some automatic security feature blocking requests fr...more >>

Error Message when visiting a frequented web site
Posted by Ladonna at 10/24/2003 7:58:26 PM
I get the following message page when I visit a commercial web site I normally visit to shop. What does it mean and how should I respond? Runtime Error Description: An application error occurred on the server. The current custom error settings for this application prevent the details o...more >>

IIS Lockdown Tool and CGI
Posted by Stacy Smith at 10/24/2003 4:41:04 PM
I have installed and run the IIS lockdown tool today. It caused a failure of a perl based web calendar called WebEvent. Everytime we open the .pl file, we receive an error that the page cannot be found. I edited the urlscan.ini file to allow for .pl files. However, when opening the URL in the br...more >>

Integrated Windows authentication with NDS
Posted by Thomas at 10/24/2003 2:56:20 PM
Hi, I have a client who is thinking about running a intranet on IIS6 with Integrated Windows authentication. As the client is using Novell Directory Service, I need to know if the integrated windows authentification will work with NDS instead of an Active Directory. Has anyone here had any exp...more >>

Ports used by windows update
Posted by ja at 10/24/2003 1:57:03 PM
How should a firewalll be configured to allow Windows Update? ...more >>

URLScan Sent verb 'SEARCH' WORM?
Posted by ja at 10/24/2003 1:47:51 PM
The last couple of months we have gotten thousands of: Sent verb 'SEARCH', which is not specifically allowed. Request will be rejected. In our URL scan logs. Is this a worm or what? It bugs me I can't see all the information being sent from the logs. ...more >>

IIS Lockdown Tool
Posted by Rich at 10/24/2003 1:05:04 PM
-What exactly does the Lockdown do? -Does it just reset existing switches or does it load additional software? -If switches are reset, what are they and what are they set to? -Is there an undo?...more >>

Spam/pop ups
Posted by Ronnie at 10/24/2003 12:31:17 PM
We have spam and pop ups on our internet. Can you recommend any package to remove these and prevent them in future. Thanks please reply to fredron@vhe0310.freeserve.co.uk...more >>

403 Forbidden - Localhost only
Posted by raghuvansh NO[at]SPAM yahoo.com at 10/24/2003 12:18:33 PM
"403 Forbidden - The server denies the specified Uniform Resource Locator (URL). Contact the server administrator. (12202) Internet Security and Acceleration Server" I get this message everytime i access http://localhost but i can access my default asp.net page by going to http://machinename. ...more >>

SSL using AES
Posted by Sam Gammon at 10/24/2003 9:31:07 AM
Can I establish a connection between IE6 and IIS6 and require that connection to be 256bit SSL using the AES algorithm? OR can the AES (rijndael) algorithm be used even at 128bit natively within IIS? ...more >>

Can I increase number of authentication attempts before 401.3 error?
Posted by Tyler Robbins at 10/24/2003 8:43:48 AM
Is there a way to increase the number of authentication attempts you are allowed to submit before you fail and get the 401.3 authentication failed page. We have a situation where a client is intermittently failing authentication to our server. While we are investigating the root cause of...more >>

virus/trojan log analysis
Posted by Ian at 10/24/2003 3:11:14 AM
I have searched google but it's obvious I am using the wrong keywords as I get a lot of articles that don't answer my problem. My manager wants some software, free preferably or low cost, that will show him virus attempts on our IIS server by analyzing the log files. I have told him to ign...more >>

Too Many Users Connected
Posted by Kamikazee at 10/24/2003 12:44:21 AM
i am getting the 'HTTP 403.9 - Access Forbidden: Too many users are connected Internet Information Services' error....im running xp pro with a workgroup setup and i am wondering how i can fix this problem...it only happens after i try to access the intranet site after a few times... Che...more >>

CGI\Perl Security Considerations
Posted by thunderbolt at 10/23/2003 9:45:48 PM
My corporate web site is running on Win2k SP4\IIS5. Currently, all the = content is either HTML or ASP. My web developer has developed some cgi = scripts (Perl 5) to do a price calculation. Are there any serious = security considerations that should prevent me from loading a Perl = interprete...more >>

Urlscan 2.5 unattended install
Posted by I A A Choice at 10/23/2003 7:51:06 PM
Hi, Firstly I have noticed that the URLScan bundled with IISLockdown is version 2. You need to update to 2.5 afterwards. Why isn't iislockd relased with 2.5 bundled? I am looking at doing unattended install of iislockdown across over 100 servers. IISLockdown installs URLScan 2 in ...more >>

IP blocking in IIS
Posted by Noone at 10/23/2003 7:37:35 PM
I have a range of IPs I would like to block from accessing IIS. Can anyone help with the format of the IP address/Subnet mask to add in the "IP Address and Domain Name Restrictions" page? For instance, I would like to block all addresses in the 61.32.x.x range. Is the correct entry 61.32.0.1 ...more >>

IIS 5.0 SSL Redirect
Posted by spt at 10/23/2003 6:32:12 PM
Does anyone know how to redirect http:// requests to an SSL site to HTTPS:// on the IIS server? Thanks in advance! Scott...more >>

IIS 5 SSL client question
Posted by spt at 10/23/2003 6:30:36 PM
I created my own cert server. I generated an SSL certificate and installed it into IIS 5. It works fine but I get the security alert dialog box everytime. How do I force the client to trust the certificate? If you click view certificate and then install certificate it still pops up eve...more >>

IIS 6.0 COM App cant write to event log
Posted by Robb Murdock at 10/23/2003 3:01:44 PM
Greetings: Ever since I moved to IIS 6.0/Win 2003 Server Web, my ISAPI dll can't write to the event log using the vb app.logevent method. There is no error, just no data. If I evoke the ISAPI DLL from a stand-alone app running as a logged in user, it works fine; and also works fine unde...more >>

Q: 4 Servers with Same SSL Cert?
Posted by Michael Beaudet at 10/23/2003 2:35:43 PM
Hi, I'm getting to be at my wits end on this one and thought I'd do a shout out to the community to see if I could get some help. We're running IIS v5 on two machines that sit behind a load balancer (Cisco Content Switch if you must know). In this scenario any requests that come i...more >>

How to require password for a website unless source address is on local network
Posted by Ingmar at 10/23/2003 1:31:53 PM
Hi all, We have a website running on our local network. We need to make this website accessable for a few people on the Internet so we use ISA server publishing to "securely publish" this site online. How can we make sure a password is required for the website, unless the request comes from ou...more >>

Securing login pages
Posted by Joe at 10/23/2003 1:17:03 PM
A developer has created a page on our non-ssl site that asks the user for login information. When the user hits submit they are sent to a page on our secure ssl site which process the information and authenticates the user. He says that when the user hits submit a secure connection is es...more >>

How can person with USER privileges administer IIS 5.0?
Posted by Konrad Rusz at 10/23/2003 11:21:30 AM
Hi, I need to give some users on the local machines right privileges to administer IIS 5.0. These users belong to USER group (not ADMINISTRATOR) on local computer (these are not domain accounts but only local). IIS is working on local PC and users ought to be allowed to do all activities that...more >>

Encryption
Posted by tom NO[at]SPAM hitekequip.com at 10/23/2003 11:13:41 AM
I am not an expert at this, so I hope this is not a stupid question. I have people putting their name and addresses into a contact list on a Sharpoint Team website. Is there a way to get SSL or something else to make the link encrypted? I have had several people say they don't want to...more >>

IIS6 - Integrated Authentication Probs
Posted by JayDee at 10/23/2003 11:12:26 AM
I originally posted this in IIS group, but I thought I'd try here, I'm really stuck getting integrated authentication to work accross a web server to a UNC share on another server If anyone feels so inclined, Id really appreciate any help on offer. Heres the problem It seems that when ...more >>

VIRUS PROTECTION
Posted by JAD at 10/23/2003 9:23:10 AM
I have an IIS server which allows an upload to an internal SQL database. How can I virus protect the data stream? On access virus protection products such as SOPHOS will not work in isolation since the uploaded file doesn't "Touch the sides" and is not saved to the IIS disk. Is there anythi...more >>

Disable SSL2 ?
Posted by Mike at 10/23/2003 9:05:25 AM
I am running SSL on one of my sites. A scan was recently performed by QualysGuard. It recommends disableing SSL 2. I found this article on MS. Shouls SSL2 be disabled? Server is NT4, sp6a, IIS4, urlscan and fully patched. http://support.microsoft.com/default.aspx?scid=kb;en-us;187498 Th...more >>

Moving SSL Certificates
Posted by hparkerlsmo at 10/23/2003 8:14:16 AM
How would you go about identifying and then moving the SSL Certificates from a Win2K IIS 5.0 server to a new Server? What would be the best method to accomplish this?...more >>

how to apply security to iis to sql
Posted by paul bearne at 10/23/2003 7:45:03 AM
Hi What is the recomended way to conect to a sql db from webserver iis 2000 to sql 2000 in mixed mode I am looking for a technet etc. artical showning users / password for direct and via com+ i.e. do I just grant I_USSER rights to all the db's I need to access! If so how do I pr...more >>

user accounts
Posted by George at 10/23/2003 5:37:22 AM
im having trouble accessing an site over a local intranet from other computers. I cant allow anonymous access as the site wont work properly...but when it asked for a user name and passwork nothing i try will work...and i dont have a clue where to configure those user accounts. i am using ...more >>

multiple secure websites on a server
Posted by Hai Minh at 10/23/2003 2:13:54 AM
I have a Windows2000 server with IIS 5 and I set up 3 website on it. It's OK with HTTP protocol. Now my manager want to use SSL with all 3 sites. I configured the first site and it worked well. But when I configured the second site, I can not open the first site with HTTPS. It's always tak...more >>

system32\inetsrv\ntdfault.mdb information
Posted by DotCom at 10/22/2003 9:48:07 PM
I am new to administering IIS. I notice an incredible number of file access to = "system32\inetsrv\ntinst1.mdb" there is another dbase called=20 system32\inetsrv\ntdfault.mdb as well, but that one is not open. is this the metadatabase, and should there be several access(s) a = second, or do ...more >>

Can't get Web-based printing to work in Windows 2000 Server
Posted by Stephen Stormont at 10/22/2003 2:31:33 PM
We have a Windows 2000 Server with SP4 applied. The server is running IIS, and has URLSCAN installed. The IIS lockdown tool has been run on this server. I have edited the registry and set "DisableWebPrinting" to "0". I have edited URLSCAN and allowed the .printer extension. W...more >>

IIS Admin Security
Posted by Mike at 10/22/2003 2:28:12 PM
I have a citrix enviroment that I have publised the IIS Admin tool. I, unfortunatley, am not in an Active Directory enviroment. I need to lock down the tool to prevent 2nd level admins from being able to delete any websites. As well the only way that I can get them access to the tool is to...more >>

passwd protecting directories
Posted by Larry at 10/22/2003 2:05:47 PM
I have a web author who would like to restrict access to one directory on his web site. He would like to use a global login for memeber access only. Where do I start to implement this? Thanks...more >>

IIS 6.0 - All Unknown CGI Extensions
Posted by Todd Beebe at 10/22/2003 12:32:43 PM
Can anyone provide a complete list of what will be blocked/denied if I prohibit 'All unknown CGI Extensions' and 'All unknown ISAPI Extensions'?...more >>

Protecting my server
Posted by James at 10/22/2003 12:31:11 PM
Hi. I am about to install a Windows 2000 webserver on the internet. However I am concerned about it getting attacked. Can anyone point me to info on how to secure it or know of any software I can use. Thanks....more >>

Virus W32/Dumaru.a@MM
Posted by Suzanne Daze at 10/22/2003 10:02:58 AM
A few days ago I received two e-mails from Microsoft saying that I had to upload a patch. When I went to the attachment it did not seem from Microsoft so I closed and deleted this e-mail. I contacted you (lost the file number you gave me) and know I have received this message 3 times wit...more >>

"Keyset does not exist" error when installing SSL
Posted by chamberlain_mike NO[at]SPAM hotmail.com at 10/22/2003 1:32:02 AM
Error message: "Keyset does not exist" System: Win2000 Server with IIS5 I get the above error message on the final stage of the wizard when trying to install an SSL certificate on a website. I have tried many times with certs from different CAs with the same result. As suggested in an MS K...more >>


DevelopmentNow Blog