Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008


all groups > iis security > november 2003 > threads for november 1 - 7, 2003

Filter by week: 1 2 3 4 5

IIS6 and ASP and COM+
Posted by jokes54321 at 11/7/2003 5:08:33 PM
We currently run an ASP application on W2K with IIS5 that calls COM+ components on another W2K server. We are upgrading to W2K3 with IIS6. The ASP pages now fail when it tries to create the COM+ object. We tried IIS5 isolation mode but the same thing happens. KB article 810564 seems to address ...more >>

Secure Channel Support
Posted by John Yurcik at 11/7/2003 4:51:53 PM
Hello, I can't get into my hotmail. When i go to log in it pops up Error: unable to access because of error with Secure Channel Support. I've tried regsvr32_rsabase.dll, but to no avail. What can I do? HELP! John Yurcik...more >>

IIS6 lockdown
Posted by Peter at 11/7/2003 3:07:13 PM
When IIS6 is installed on Windows 2003, it is in a locked- down state. How do I remove this?...more >>

isapi filter cookie
Posted by ptr1024 NO[at]SPAM yahoo.com at 11/7/2003 9:56:33 AM
Hi, I am developing a pay-per-view web based application. I am writing an ISAPI filter that handles the security issues. When a user requests a page with embedded media file located in a particular directory the ISAPI checks whether the request came from a proper place by checking cookies. If...more >>

IIS authentication against ADSI
Posted by Ch. at 11/7/2003 8:06:55 AM
Hi, we are setting up an application that pops-up a windown where credentials are to entered (using IIS), we want to authenticate this credentials against an ADSI DB within our LAN. The DMZ is a workgroup (no domain). Using a ColdFusion application authentication is OK, IIS seems to be ...more >>

login attempts
Posted by pat at 11/7/2003 7:26:12 AM
I have servers in my DMZ that show people attempting to logon guessing the user accounts and passwords, they are getting denied but wanted to know if there is any way to prevent them from even attempting to access the server. Also I have one server where they are trying local accounts and...more >>

Dial up connection
Posted by Ron at 11/7/2003 7:23:47 AM
is there anyway of monitoring/finding programs that are calling up the use of the dialer. I find that soemthing is calling up my dialer and connecting me to the internet even though I have auto connect unchecked. Any/all help will be greatly appreciated....more >>

IIS and ASP
Posted by N03L at 11/7/2003 3:56:07 AM
We seem to be under attack... My company is experiencing problems with all of our public facing ASP sites. The OWA and our CItrix server are returning ASP errors. The OWA error is... ASP error 0115 (if memory serves) Citrix allows the initial login through both the secure connection and from...more >>



event 1003 w3cctrs & even 1003 iiscntrs
Posted by M. Akram Arain at 11/7/2003 2:11:34 AM
I have a problem in the configuration of these two events in windows 2000 advance server and I will welcome your help in this area. Thank you and have a nice day. M. Akram Arain E-mail: zuneca@skyinet.net...more >>

Firewall type
Posted by Hans at 11/7/2003 1:31:04 AM
Hi. I'm looking for some recommondation on which firewall type (hw:i.e. cisco/sw: i.e. stonegate?) is best suited for my w2k adv. + IIS 5.0 webserver. As I've been hacked 100%, I want to make sure that my next installation is protected as efficient as possible. Thx....more >>

automating the process of Assigning an Existing Server Certificate to a Web Site
Posted by Srinivas K at 11/6/2003 11:58:57 PM
Can anybody help me with code on automating the procedure of assigining an exisiting Server Certificate to a given web site in IIS? I need this pretty Urgent. Thanks in advance Srinivas K...more >>

Access of images on file server
Posted by MJ at 11/6/2003 2:43:31 PM
I have a web server setup on a DMZ with an ASP application that is trying to access JPEGS on a file server that is not on the DMZ. I have a mapped drive setup on the web server pointing to the location of the JPEG images. When the pop-up appears within the ASP application that shows the ...more >>

Please Help
Posted by Dawn at 11/6/2003 2:16:28 PM
The other day I was in Yahoo chat, and someone popped up and told me to click on to their web site. I did, and it ended up being a webcam porn site. I clicked out got off line. The next day, I got into Yahoo Messanger to check my mail, and the porn site came up. It now comes up everytime I...more >>

help
Posted by dawn at 11/6/2003 2:11:36 PM
I was chatting the other day on yahoo, and in the chat room, someone sent me a website to go to. I went and it ended up being some porn webcam site. I clicked out, but now, everytime I want to check my mail from my messenger or view someone's profile from it, that site always pops up. What...more >>

How to create backup set for SSL in IIS 5.0?
Posted by Benny, Yuan at 11/6/2003 1:28:59 PM
__________________________________________________________________ Benny Yuan ICQ#: 168627973 Current ICQ status: + More ways to contact me __________________________________________________________________ ...more >>

wildcard SSL certificates
Posted by Beth at 11/6/2003 12:54:49 PM
Hi, I would like to get a wildcard certificate for my institution. We have many servers requiring SSL, and it is getting expensive. Knowlege base article 258858 says that wildcards are not acceptable with Windows 2000 IIS, but it sound like this should have been fixed after sp1. Is t...more >>

iis Lock Down Program Problem with Fully Qualified DN
Posted by Brian at 11/6/2003 12:12:09 PM
We installed the iis lock down software that is supposed to help secure an IIS server. Once we did this we would go to our intranet site using the server name only... ex.. webserver/index.html this would allow us to view the pages fine. Once we started using the fully qualified Domain...more >>

Has anyone heard of this event and do you know what it means?
Posted by Ben F. Marshall at 11/6/2003 10:14:13 AM
Windows version 2003, IIS 6.0, Exchange 2003 I am getting event id 20 source KDC the currently selected KDC certificate was once valid, but now is invalid and no suitable replacement was found. Smartcard logon may not function correctly if this problem is not remedied. Have the system admini...more >>

GET /scripts/nsiislog.dll - 401 -
Posted by Tan Nguyen at 11/6/2003 8:40:10 AM
Hi, I got this "GET /scripts/nsiislog.dll - 401 -" in my IIS 5 log file. Does anybody have any idea? Thanks Tan...more >>

SSL : HTTPS : Error : The page cannot be displayed
Posted by Indian Ocean at 11/6/2003 7:46:23 AM
Hello, Desc. : I have completed the process for certification and installed it already to Default WebSite. write port 443 CN is my computer name. I am using this for test perpose on my local PC. So there is no firewall. ::::Main problem I am getting "The page cannot be displayed..." message...more >>

Home page piracy...
Posted by gerry at 11/6/2003 7:25:59 AM
A Search engine is somehow setting itself on my MS Explorer menu as my homepage every morning. I reset the homepage and delete all the files from this search engine i can locate to no avail. When i login the next morning, this Search engine is once again my 'Homepage'. How do I keep thi...more >>

Anonymous authentication
Posted by Chris at 11/6/2003 2:56:15 AM
I found out that disabling or removing IUSR/... user account is not enough to disable anonymous access to Web site. There is a user account NETWORK in directory wwwroot which MUST be disabled or removed to really deny anonymous access (clean install IIS 6.0, Windows Server 2003, integrated...more >>

securing ODBC connection details in ASP app's on IIS 6
Posted by sly_i NO[at]SPAM hotmail.com at 11/6/2003 2:37:04 AM
Hi All, I have a web app that uses IIS 5 Metabase to store ODBC connection details as described here (http://www.devarticles.com/art/1/592). Our comapany would like to migrate their win2k server to Windows 2003 to increase the security but when i try to add the custom class's using t...more >>

INFO: pop-up every second
Posted by bob at 11/5/2003 5:59:42 PM
Can anyone explain why i get INFO: popup every sec and they build up this makes it very fraustrating i'm about ready to slam my system to the ground?...more >>

Web DAV vulnerability
Posted by Don at 11/5/2003 4:43:46 PM
I am getting scanned to death today on the web dav vulnerability discussed in MS03-007 security bulletin. I installed the IIS lockdown tool and URLScan and they are denying the connections but I am seeing scans at least every minute. Is there all of a sudden a new outbreak of this? Why tod...more >>

What is the IUSR Password?
Posted by tapana at 11/5/2003 4:27:59 PM
What is the password of IUSR should be set?...more >>

can install 404.dll without using IIS Lockdown tool?
Posted by JoseIsMe at 11/5/2003 3:11:16 PM
Hello, Is it possible to install 404.dll on IIS without using the full-blown IIS Lockdown tool? Thanks, Jose...more >>

IIS domain member
Posted by Craig at 11/5/2003 2:31:53 PM
We have a domain setup for only the main servers of the company (workstations in a seperate domain).We are adding an internet web/application server to the server domain. Is it absolutely wrong to make this web server part of this server domain? I want this new webserver to communicate fla...more >>

Something to think about next time boss wants information...
Posted by Carroll P. MacDonald at 11/5/2003 2:29:03 PM
This happened a couple of years ago: How do feel about a boss who wants to know everybody's Passwords on the server, including FTP user names and passwords. I worked for this fellow who hired me as their administrator to the networks and web servers, he wanted me to keep track of all the user...more >>

Intranet application
Posted by Agus at 11/5/2003 12:46:10 PM
Help! I am configuring a intranet application, here is the logic 1- When the user hits the site, authentication is required, and we are using their windows user. 2-A query is then run depending on the user. A menu of items the user can do are displasyed. This step works and we know then that the ...more >>

HTTP works on SSL Port !
Posted by jeapou2 NO[at]SPAM hotmail.com at 11/5/2003 12:37:16 PM
I have a site in IIS that "Require secure chanel (SSL)" is checked. TCP Port : 6666 SSL Port : 7777 When I try http://mysite:6666 - I see a page indicate that the site require SSL - GOOD ! When I try https://mysite:7777 - I see my page with the yellow lock and when I double-click on the lo...more >>

Error creating Class's in the ISS 6 Metabase schema
Posted by sly_i NO[at]SPAM hotmail.com at 11/5/2003 11:16:53 AM
Hi All, I have a web app that uses IIS 5 Metabase to store ODBC connection details as described here (http://www.devarticles.com/art/1/592/2). Our comapany would like to migrate their win2k server to Win 2003 to increase the security but when i try to add the custom class's using the m...more >>

recreate iusr_ account
Posted by isnms at 11/5/2003 10:41:08 AM
I had to do a repair on nt4 with iis4. Now iusr_ account is missing from user manager. How can this be recreated short of uninstalling option pack and reinstalling it?...more >>

IIS 6/Win 2003 anonymous access
Posted by Eoin Mooney at 11/5/2003 8:27:50 AM
Hi , We have a product that uses Win 2000 Server /IIS 5 . We have not problems with this setup in accessing elements via ASP - The product works fine We are moving to Win 2003 Ent / IIS 6 and we have run into trouble. We cannot perform a task that we were able to do. It seems it we do...more >>

HTTP 401.3 - Access denied by ACL on resource
Posted by fatbastard at 11/5/2003 8:08:16 AM
IIS 5 using NTFS permissions on Windows 2000 Server. Within the site there is a trusted users login. I can test the login successfully but some users outside the corp. domain or LAN are unable to access this part of the web. Some are getting no login box and immediatly get the 401.3 err...more >>

home page
Posted by jerry at 11/5/2003 6:50:12 AM
My home page defaults to one of two search engine pages I deleted all files with these names and reset my home page but they keep returning....more >>

Anonymous login
Posted by Kyle at 11/5/2003 5:32:45 AM
I am new to my company, so I did not set this up but, they hired me to support it.anyway..I have two 2000 Advanced Servers clustered to have a 24/7 uptime for IIS Version 5 here is where I am stuck, I can run IIS on node 1 without any problems, but when I move the IIS group from node 1 to ...more >>

Sending Plain Texts to SQL from IIS
Posted by Dawn at 11/5/2003 4:33:55 AM
Hello I've been told today that when sending or retrieving data from a webserver using NT authentication then IDs and passwords are sent as plain text. Does anyone know if something can be put in place to encript this information. Thanks...more >>

IIS Login Failure Security Policy Issue
Posted by ksmith_uk NO[at]SPAM hotmail.com at 11/5/2003 2:09:20 AM
Hi All, Here is the error I keep getting on an IIS server, it is a member of a 2k domain, and it runs fine for a couple of hours but then stop giving access. Error from IE: HTTP 401.1 - Unauthorized: Logon Failed Internet Information Services System Event log Error from server: Eve...more >>

Please help me stop the SPAM coming through my server
Posted by cdowsett NO[at]SPAM hotmail.com at 11/4/2003 8:32:30 PM
I am in desperate need of some help here. Halloween weekend I had around 20 GB of Spam traffic go through my server. I am running 2000 Server with the default SMTP server that comes with IIS 5.0 The messages seemed to be the same messages coming from different IP addresses and addressed to...more >>

malicious program take over of search engine?
Posted by catkins NO[at]SPAM d1sports.net at 11/4/2003 5:22:59 PM
I can't get a search engine to work help me eliminate the problem please? can some one walk me through it?...more >>

how to setup authentication trust between two machines/servers.
Posted by Peter Rilling at 11/4/2003 3:53:01 PM
Suppose that I have two servers each running different sites. They both require authentication (using NT authentication). They are both on the same domain so when a user logs into either, they can use the same username/password. On one of the machines, there are hyperlinks pointing to conten...more >>

IIS 6 401.1 Error with Integrated Security
Posted by jordan_mccall NO[at]SPAM hotmail.com at 11/4/2003 2:06:30 PM
I am experiencing some very bizarre authentication problems with an ASP.Net app on IIS 6. I'm on Server 2003 standard, using a virtual dir on the default site. The virtual dir has only integrated authentication checked. Users authenticate just fine if they are on Win2K. Clients with XP ge...more >>

secure web site
Posted by mike at 11/4/2003 12:31:14 PM
Hi i have secured a web site with a certificate and basic auhtentication. when a user goes to the web site with IE via https to the web site he is prompted for a passwors, which is OK, but the user then marks the save password option. my question is - SSL is not supposed to do that, h...more >>

Lost controll of permissions in ISS
Posted by Mark B at 11/4/2003 10:56:06 AM
I run XpPro & IIS 5.0 and have been sucsesfully using ASP and Access database on my web server. After re-installing my OS I can't set folder permissions or remember how I did it before. Any changes are reset to Read Only. Most documentation I see says to grant the IUSR_computername user a...more >>

ASPNET account was reset
Posted by Pat at 11/4/2003 4:27:54 AM
Not sure if I am in the right section on this Someone reset the aspnet account password during a server lockdown, now my .net applications won't work. Is there a way that I can get the applications back in sync with the password that the aspnet account now uses? Or do I have to reinstal...more >>

** READ THIS BEFORE POSTING - answers to frequently asked questions 2003.11.03
Posted by Karl Levinson [x y] mvp at 11/3/2003 11:35:38 PM
Before you post a question to a Microsoft.public.*.security newsgroup, note that your question may already be answered below: Answers to Top Frequently Asked Questions: http://securityadmin.info My question is not mentioned below. How do I get an answer immediately, with no waiting? http:...more >>

anybody seeing this in their logs?
Posted by anonymous NO[at]SPAM discussions.microsoft.com at 11/3/2003 7:07:34 PM
What does this mean? /scripts/root.exe /c+dir /MSADC/root.exe /c+dir 403 /c/winnt/system32/cmd.exe /c+dir 404 /d/winnt/system32/cmd.exe /c+dir 404 /scripts/..%5c../winnt/system32/cmd.exe /c+dir 500 - /_vti_bin/..%5c../..%5c../..% 5c../winnt/system32/cmd.exe /c+dir 500 - /_mem_bin/..%5c../....more >>

Frontpage
Posted by Kevin Coffman at 11/3/2003 5:41:48 PM
Hello, Is there security issues with frontpage 2000 if you are not utilizing frontpage extensions on the webserver? I only use frontpage to creage the .htm document that I upload to the server and was told that since it is a frontpage document there are security issues...more >>

FTP and IIS HACK!!!
Posted by David Little at 11/3/2003 4:41:39 PM
I know very little about hacking or the like. I have a problem I hope someone can help me with. My FTP server is getting modified by someone or something. I am running IIS on win2k server. I have NAV Corporate Edition 2.7. I have a hardware-based firewall with ports open for FTP, SMTP, P...more >>

Forms Based Authentication
Posted by Steve Williams at 11/3/2003 12:08:53 PM
I am trying to setup my OWA on my server. I was told I have to enable SSL and then enable Forms Based Authentication, on the IIS?? I cannot find where Forms based authentication is locations?? Can anyone help>...more >>

Access Database Permissions for IIS?
Posted by dave NO[at]SPAM simcik.com at 11/3/2003 9:43:51 AM
This should be a simple question, but it has turned into quite the quagmire for us here at work that's lasted . In short, how should an ISP configure IIS/Win2K to allow secure dynamic access to Access/Jet databases via ASP and ADO, with particular emphasis on the "secure"? We found the standar...more >>

IIS/Domain Security
Posted by Lewin Wanzer at 11/3/2003 8:55:11 AM
I am involved in trying to setup a website that will give users of our domain a heads up and also allow them to change their passwords through the web server for our domain. I have not come across an article that clearly shows the process. Does anyone have any ideas where I could find one ...more >>

FTP, IIS 6, How to get the Logon Screen to prompt?
Posted by Rick Cass at 11/3/2003 8:29:58 AM
Can't figure out how to get prompted for user logon. All users are using Internet Explorer 6.0 or better. How can I setup the logon screen so users can login? Windows 2003 w/ IIS 6.0 Just setup IIS 6.0 on my new 2003 server. Added a new FTP site and pointed to folder on local machine - ...more >>

Secure website access
Posted by Dan D. at 11/3/2003 7:26:08 AM
I have Windows Server 2003 with Project Server 2003 installed. Project web access works through http. I then installed a certificate and configured site for SSL, 128 bit. When I access the site now, I receive Page not found. If I try to access via http, I receive a message indicating I...more >>

iis6: Login Failed asp.net to SQL
Posted by Medvjed at 11/3/2003 12:12:10 AM
I'm migrating a asp.net webapp from win2000 to win2003. the app is making a trusted connection from ASP.NET to SQL Server. the error is: Login failed for user 'NT AUTHORITY\NETWORK SERVICE'. kb: http://support.microsoft.com/default.aspx?kbid=316989 says: CAUSE When you use ASP.NET, the defa...more >>

IIS Third-Party Tools References
Posted by Matt at 11/2/2003 6:02:00 PM
Can anyone give me good references on tools for IIS web server? I mean from administrators point of view, what famous/common third-party tools that we should use to administer IIS? Or just IIS itself is good enough? Please advise! Thanks ...more >>

[LONG] Differences between SSL client authentication - Win2K/IIS5 vs. Win2K3/IIS6
Posted by Ohaya at 11/1/2003 12:01:30 PM
Hi, [Apologies again for the cross-post, as I think that some questions overlap NG coverages.] Background ========== I've been testing with SSL client authentication scenarios with both Win2K/IIS5 and Win2K3/IIS6. Most recently, this work has been with Win2K/IIS5, as that is the produc...more >>

Question about certificates in IIS
Posted by Daniel Walzenbach at 11/1/2003 1:06:39 AM
Hi, =20 I'm confronted with the following scenario: I want to host INTERNET = sites and INTRANET sited on an IIS. The communication should be = encrypted. I therefore plan to install a certificate. My question is now = weather I need two different certificates or if one is enough? Best...more >>


DevelopmentNow Blog