Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008


all groups > iis security > november 2003 > threads for november 22 - 28, 2003

Filter by week: 1 2 3 4 5

Security in hosted environment
Posted by PL at 11/28/2003 1:19:38 PM
We are providing hosting for our members on an IIS6/W2k3 standard server, we are now considering offering scripting support but I seem to run in to numerous security issues with this. The problem here is that each member does not have it's own virtual dir, we already have thousands of members ...more >>

computer downloading unrequested files
Posted by carey badoino at 11/28/2003 12:12:08 PM
Latley I have noticed that my compter has been downloading files without me initiating anything. The icoHow can I tell what my computer is downloading ? How can I stop it from downloading files ? I use the Windows XP operating system....more >>

Disabling SSL v2 in IIS 6.0
Posted by andycheung2000 NO[at]SPAM hotmail.com at 11/28/2003 9:10:35 AM
An intrustion test vendor has suggested disabling SSL v2 on my IIS 6.0 server. I found the following article but I don't know if it's applicable to IIS 6.0. It mentions IIS 3.0 thru to 5.1 but the reason it doesn't say IIS6 may be because it was written in early March. Can anyone help with thi...more >>

Replacing Certificate with another CA
Posted by Jerry Nendel at 11/28/2003 7:27:10 AM
I want to renew my certificate but with another certificate authority. When I run the wizard it automatically plugs in the current CA information. I'm not ready to delete the current certificate, until I get a certificate request created and submited to the CA. How can I do this?...more >>

ISS basic authentication ( domain/username )
Posted by LieHanTjeng at 11/28/2003 1:39:49 AM
Hi, I activated ISS security with basic authentication. When I click the url, it prompted me with username/password. That one works fine. How to put some information/message in login box so my user knows that they need to type domain/username in it ? eg : Site : "servername" Realm "...more >>

Secure Directory html works ASP does not
Posted by JJ at 11/27/2003 9:47:55 PM
Hi, I have created a folder on my website which has basic authentication. The website uses asp. The only problem is in my secured folder, it only accepts the username/password if you want to use html. If you try and access an asp page it says the username/password does not work. ???? ...more >>

SSL
Posted by Jici at 11/27/2003 6:58:54 PM
i got a web site like www.compagny.com who work very well and i apply the SSL encryption. Now when i type www.compagny.com and cannot access the page because i have to put a https: before my adress. What i have to do to redirect my http:\\www.company.com to https\\www.company.com. than ...more >>

Authentication problem
Posted by PL at 11/27/2003 4:26:53 PM
I'm having a problem authenticating through IIS 6 and I cannot figure out what the problem is. I have created a user group called OfficeAdmins, all members of this group should have access to the admin folder I placed on the server. I removed the IUSR permissions on this folder and added ...more >>



Help,I can't merge word document in the server
Posted by lee_j at 11/27/2003 11:30:43 AM
Hi, I want to merge a word document in the server to display in the client side.The merge code is in a dll.In the asp server script, I invoke the dll to merge.It raise an error when I use the default IIS user.When I change the IIS user to administrator,It work well. I don't know how I shoul...more >>

Windows 2003:IIS 6:File server
Posted by Bhaskar at 11/27/2003 7:51:09 AM
Hi I have a .NET application hosted on IIs 6.0. I am using an other machine (again a windows 2003) as a file server. Whenever I try to upload a file to my fileserver through browser, it asks for an authentication. This authentication is for the localhost. I have tried to solve this problem by crea...more >>

CertificateAuthority.Request failed
Posted by cfrketx at 11/27/2003 7:41:05 AM
hello, company for which I'm working, is using IIS5.0 and certificate authority for webpages that supports our customers, yesterday I tried to create cert via intranet and something goes wrong, after attemp to contact cert authority any computer says that there is unexpected problem with CA server, ...more >>

ASP.NET W2K3 UNC: Server Error in '/' Application
Posted by Augustus at 11/27/2003 4:15:44 AM
I have problem with ASP.NET files on a NAS Appliance (W2K) using UNC, through a W2K3 PDC IIS6, while working fine when the virtual dir is located on the W2K3 (Standard) Server itself. The aspx files on the NAS generate the following error; Access to the path "C:\WINDOWS\Microsoft.NET\Fra...more >>

Web Site utilization
Posted by booner at 11/26/2003 7:23:26 PM
I have a web app running on IIS 5.0. I was curious how much it is getting utilized. Some investigating and I notice log files c:\winnt\system32\LogFiles\W3SVC1 with lots of information. Are there any tools to help figure out how many hits (running an analysis on these log files perhaps) a web...more >>

Adding Application Configuration for a Virtual Directory
Posted by Kevin Mei at 11/26/2003 1:12:58 PM
Hi, I was tryying to add a new "Extension to the Application Mappings for a Virtual Directory"; I was able to go to the "Add/Edit Application Extension Mapping" dialog. However, the "OK button" always grayed out. I couldn't seem to add it. I was able to add it before, this issue started to...more >>

https:// sites cached?
Posted by Brook at 11/26/2003 9:29:09 AM
Does anyone know if https sites are cached? Thanks, Brook...more >>

Domain Secret?
Posted by thegalaxyboy at 11/26/2003 7:37:33 AM
Dear IIS Community, I am configuring an ISA server with RSA SecurID authentication using the instructions titled 'Using the Web Filter for authenticaton for RSA Security'. And one of the steps is to "...import the domain secret to the IIs server...". Where in IIS do you import the d...more >>

IIS6.0 Download exe problem
Posted by John Collins at 11/26/2003 6:10:32 AM
Running: IIS 6.0 on Windows 2000 server. Whenever I attempt to download an exe off of my server, I receive the following error: Internet Explorer cannot download <insert file name> from <insert website name>. Internet Explorer was not able to open this Internet site. The requested site ...more >>

Problems viewing .pdf etc... over secure https:\\ pages
Posted by Richard sahonta at 11/26/2003 2:28:46 AM
Hello All... I am the network technician at a school and we cannot view pdf files. We receive a Microsoft Internet explorer error. the error appears only when it is pdf file that is being downloaded. I have placed a .bmp file in the same same folder with same permissions and setup a hyper...more >>

hacker
Posted by dina ibrahim at 11/26/2003 1:23:02 AM
Someone has hacked my email after blocking the sender for a few times. I live alone, and no one knows my password. I don't know how that happened. After blocking out their emails, this person hacked my email, and started to use my old email to send messages to my new email ! This person se...more >>

cannot logintp secure web sites
Posted by mickey at 11/25/2003 9:26:07 PM
Problem : I cannot get into secure web sites.. I have worked with several forum groups and technical assistances and have tryed several things but after 4 days I still cannot get into sites where I have to have a userid and password. I cannot download from windows live update," it says wi...more >>

Problem using ssl Error :Cannot find server or DNS Error
Posted by gopivp NO[at]SPAM hotmail.com at 11/25/2003 8:30:44 PM
i'm using winxp iis 5 and i have create a certificate using iis then from mmc i copy that certificate to my desktop after that from the iis pending request i browse that certificate(copy desktop).when i try to access the page with https the following error occur I have read all the KB articles...more >>

Requiring Client Certificate
Posted by Tim at 11/25/2003 7:04:40 PM
Can someone point me in the right direction regarding requiring client certificates. I need to know if requiring client side certificates is it possible to specify the acceptable client certificates and deny any others, if so how do you configure them on the server & client. What is the...more >>

WebDAV security on IIS problems
Posted by msnews.microsoft.com at 11/25/2003 12:58:49 PM
Hey All, I have been beating my head over this one for a long time. It has to do with setting up a WebDAV folder in IIS and setting permissions on that folder to two accounts - one with read access and the other with full. From all the documentation, this should be a simple task. WebDAV is ...more >>

SSL Certificate
Posted by MS at 11/25/2003 12:17:17 PM
Hello, I've installed an SSL certificate I created on an IIS 5.0 server. Whenever our client use the website, they are asked to accept our SSL certificate even after they install it. Is there a way to prevent the users from getting prompted to install our certificate over and over again? Thank...more >>

2 SSL certs for 1 IIS site?
Posted by J Yue at 11/25/2003 12:01:21 PM
We have an IIS site with a SSL cert installed. We are setting up a new extra URL and a new cert to access this site and needed SSL for it. Can we configure IIS to accept 2 certs for the same site? so you will be getting SSL no matter which URL you use to get to the site. Thanks -jas ...more >>

Controling Content by User
Posted by Rob at 11/25/2003 9:45:16 AM
I need to be able to control the content of the site by which user logs in. Say have an extra link on the admin group account for admin changes to the site. Any help is appreciated....more >>

Force disconnect from IIS 5 ftp server
Posted by mickx at 11/25/2003 8:58:13 AM
Hi 1st time here, so excuse my ignorance and if this thread has been discussed. Is it possible, within IIS5, to configure the ftp server to tear down the connection after a 'configurable' number of failed auth attempts with a bad id / passwd? tx in advanced...more >>

How to define cipher type allowed in an ssl session
Posted by Danny Schelberg at 11/25/2003 8:05:11 AM
Does anyone know where exactly in a Win2K IIS 5.0 Server you would define the cipher type allowed in an ssl session. I sumise that it is a registry tweak and would appreciate any info on this topic Regards, Danny Schelberg CCNA, MCSE, MCP + I Network Engineer Procurestaff Volt I...more >>

Name of certificate doesnot match name of site.
Posted by BWilliams at 11/25/2003 6:06:10 AM
I have generated a certificate using Certificate Server. Everything is working, except I get "The name of the certificate is invalid or does not match the name of the site." I have re-generated the certificate several ways according to article 813618 and 232161. I am trying to use an ip address inst...more >>

how do I force secure ASP.NET session cookies?
Posted by Ed at 11/25/2003 3:17:30 AM
I am running a pure SSL website using forms authentication with encrypted authentication cookies. I can tell ASP.NET to issue the authentication cookie with .Secure=true so that the browser only submits the cookie over an SSL connection. However, the server does respond to http requests ...more >>

are my binaries being exposed on my ASP.NET website?
Posted by Ed at 11/25/2003 3:16:50 AM
We've had some security consultants go over our website looking for vulnerabilities, and they've found a binary file exposure problem, but I can't reproduce it - has anyone seen something like this? My website runs on SSL and uses forms-based authentication. IIS lockdown and URLScan 2.5 ...more >>

Hardware Firewall recomendation needed
Posted by Mini Me at 11/25/2003 3:12:45 AM
Our office currently has a server connected to the Internet that allows our employees and clients to access it via HTTP, HTTPS, FTP and email. We put it behind a linksys router and passed the appropriates ports directly to that machine while blocking all other ports. However, we're moving ...more >>

Unable to Connect to Secure Web Page with I.E. 6
Posted by Riad at 11/25/2003 3:10:05 AM
I am unable to connect to secure web pages (e.g. logging in to hotmail)with internet explorer 6. I have gone through the security settings - but no luck... Please Help! ...more >>

IIS authentication for Sharepoint
Posted by Sweta at 11/25/2003 12:45:32 AM
Hi, Can you tell me how IIS and Sharepoint communicate about authenticated users??? Regards, Sweta...more >>

Security implications of giving F access to directory
Posted by Spook at 11/24/2003 9:46:04 PM
Hi My ASP based website relies heavily on an MS Access database to display it's content. The database is outside the root directory of my site, so it cannot be accessed via the web, and a System DSN has been set up on the server. This worked fine, until the security of my database became an issu...more >>

Problem with Internet Explorer 6.0 and secure sights
Posted by Misti at 11/24/2003 8:48:14 PM
With Internet Explorer 6.0 I keep getting "page cannot be displayed" error on secure sights. I have a Dell brand computer and they have not been able to solve this problem. Please help. Thank You! Mistie6802@yahoo.com...more >>

Website got hacked
Posted by Chirashi at 11/24/2003 7:56:28 PM
My website got hack and I want to know how can I replace my index.asp, index.html, default.html and default.asp. Everything else is okay but they seem to have replace these 4 files, how can I replace these files if my original ones have been replaced. Thanks ...more >>

kerberos for iis ?
Posted by Sanjay at 11/24/2003 6:18:22 PM
Hi, Is there a simple howto on getting a Win2K client, logged on to Active Directory (AD) domain, get a file from IIS server (running on AD server) with Kerberos authentication ..? -- IIS server is running on the Active Directory server (win2k domain server). Win2k Server, SP2 IIS 5.0 --...more >>

Windows authentication failing
Posted by ktuel NO[at]SPAM streck.com at 11/24/2003 5:05:08 PM
I have a very small website, 1 page right now, it is for internal use only. I have anonymous access disabled and windows authentication enabled. When any user, even the web server itself, uses IE to connect to this site, I get a box requesting my usename, password and domain. All machines in ...more >>

removing cmd.exe properly
Posted by danny schelberg NO[at]SPAM volt.com at 11/24/2003 2:52:45 PM
I recently followed the article below as an added IIS lockdown step. Removing cmd.exe for some reaseon does not work since it keeps getting restored by what I sumise to be windows file protection. Does anyone know what else I can do to insure cmd.exe does not return to the default path eve...more >>

install security process incomplete
Posted by Sherryl at 11/24/2003 2:09:57 PM
upon downloading critical security updates, KB828035 will download but quits at install. After several attempts to complete install without success Im baffled. Any help???...more >>

IIS for Win XP Pro
Posted by Christy at 11/24/2003 1:47:06 AM
I have setup IIS 5.1 in my Win XP Pro, after setup i can't view or display the .asp page but it's work for .htm page. how can i solve this problem?...more >>

server 2003 ASPNET and DC
Posted by John Smith at 11/23/2003 10:31:57 PM
I have tried to follow the instructions that I carried out for Win2k now I cannot get my website to work on a server 2003 Domain Controller. Is there better instructions out there than the MS instructions which are all out of date? Also, there is not Local Security Policy in the Admin tools,...more >>

401.3 error with IIS 6.0 on Windows Server 2003
Posted by Ranjith at 11/23/2003 4:22:43 PM
I have an ASP .NET Application running on a windows server 2003 system. Configured IIS to use integrated windows authentication. As an admin of the system, I do not have a problem accessing the web site hosted on this system. But other users in the domain get a 401.3 Unauthorized due to ACL on r...more >>

Multiple SSL on diffrent nics???? Please help
Posted by G_Man at 11/23/2003 11:56:07 AM
OK......!! I have got this working before but now it just seems it does not want to work!! I have a web server running IIS 6 on Windows 2003 Enterprise edition It has 4 network cards and should run 1 web site per network card as each site needs it's own SSL cert I have removed the use all una...more >>

Anonymous Virtual Directory Requires Authentication
Posted by DX at 11/23/2003 10:23:40 AM
I set up a virtual directory within the default web site. Clicked this virtual directory and went to properties- >Directory Security->Edit Enable anonymouse access->ensure enable anonymous access is checked and using iusr_machine with correct passwd. But when I try to access this virtual ...more >>

IE problems
Posted by Raf at 11/23/2003 4:10:31 AM
Each time a restart my computer and use internet explorer the default page changes and the list of recently viewed pages turns into porn site. Is this common and what is the solution. Thanks...more >>

does IPSec provide enough security for web server?
Posted by Isabella at 11/23/2003 12:34:25 AM
I have only IPSec installed, no firewall or anti-virus. Is that secure for a web server? Isabella ...more >>

Unable to access our SSL page
Posted by Paul at 11/22/2003 1:22:37 PM
Hi All, I have setup IIS to require a SSL connection to access my website. However, when i try to connect Internet Explorer says that the page cannot be displayed. If i then try to access the site without the https, i am told that i cannot access it because its requires SSL. Additionally...more >>

Anonymouse access causes Unauthorized Access error
Posted by Barry Fitzgerald at 11/22/2003 11:53:04 AM
I am getting an access error ( HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials. Internet Information Services (IIS)) when trying to access the default web site on a Win2003 Server that is in a domain using anymous access. This occurs if I disable the Integrated Win...more >>

unable to connect a secure site
Posted by vikas at 11/22/2003 11:37:00 AM
hi i am getting the following message on my web browser. can someone tell me what and why this is happening. and what is the solution or remedy for it? The page must be viewed over a secure channel The page you are trying to access is secured with Secure Sockets Layer (SSL). ---------...more >>

Forcing client to have certificates
Posted by Andrew at 11/22/2003 11:26:31 AM
Hi.. How do you configure your website so that it forces clients to have a certificate before allowing access? Andrew ...more >>

IIS 5.0 can't handle multiple request at the same time with the same Web site(Application)?
Posted by Rayman at 11/22/2003 10:59:26 AM
Dear All, I am currently using Windows 2000 SP 4 with IIS 5.0. I found that IIS 5.0 can't handle multiple request at the same time=20 with the same Web site(Application), here is the code for testing: -----------------------Begin-------------------- <% response.write "Start Time : " & now(...more >>

IIS 6 - UNC - 401.1 - Access is denied due to invalid credentials
Posted by Augustus at 11/22/2003 4:35:51 AM
I've setup a Windows 2003 Standard Server as PDC with IIS and a NAS (Dell PV 725) with Windows Powered 2000 Server. A simple website (IUSR read-only, client R/W) with a password protected directory for the website statistics (no IUSR, client read-only). This situation hosted locally on the W...more >>

IIS account as a domain admin
Posted by scanner2001 at 11/22/2003 2:45:11 AM
In a conversation recently, one of my co-workers was arguing that it was acceptable to set up the IIS anonymous account as a domain user that is a domain admin. I argued against this point, noting that if someone were to be able to "hack" thru a web page, they would have full control over not...more >>

Website keeps asking Windows login
Posted by rhu at 11/22/2003 1:31:05 AM
I run Win2k Adv. Server (with IIS4/5?). I set up a website on it. Each time when I'm opening the site from another machine it always asks me to login with my Windows username and password. Please anyone help to tell me what's going wrong in my IIS settings? Thanks....more >>


DevelopmentNow Blog