all groups > iis security > november 2003 > threads for november 22 - 28, 2003
Filter by week: 1 2 3 4 5
Security in hosted environment
Posted by PL at 11/28/2003 1:19:38 PM
We are providing hosting for our members on an IIS6/W2k3 standard server,
we are now considering offering scripting support but I seem to run in to numerous
security issues with this.
The problem here is that each member does not have it's own virtual dir, we already
have thousands of members ... more >>
computer downloading unrequested files
Posted by carey badoino at 11/28/2003 12:12:08 PM
Latley I have noticed that my compter has been
downloading files without me initiating anything. The
icoHow can I tell what my computer is downloading ? How
can I stop it from downloading files ? I use the Windows
XP operating system.... more >>
Disabling SSL v2 in IIS 6.0
Posted by andycheung2000 NO[at]SPAM hotmail.com at 11/28/2003 9:10:35 AM
An intrustion test vendor has suggested disabling SSL v2 on my IIS 6.0
server. I found the following article but I don't know if it's
applicable to IIS 6.0. It mentions IIS 3.0 thru to 5.1 but the reason
it doesn't say IIS6 may be because it was written in early March.
Can anyone help with thi... more >>
Replacing Certificate with another CA
Posted by Jerry Nendel at 11/28/2003 7:27:10 AM
I want to renew my certificate but with another
certificate authority. When I run the wizard it
automatically plugs in the current CA information. I'm
not ready to delete the current certificate, until I get a
certificate request created and submited to the CA. How
can I do this?... more >>
ISS basic authentication ( domain/username )
Posted by LieHanTjeng at 11/28/2003 1:39:49 AM
Hi,
I activated ISS security with basic authentication. When I
click the url, it prompted me with username/password. That
one works fine. How to put some information/message in
login box so my user knows that they need to type
domain/username in it ?
eg : Site : "servername"
Realm "... more >>
Secure Directory html works ASP does not
Posted by JJ at 11/27/2003 9:47:55 PM
Hi,
I have created a folder on my website which has basic authentication.
The website uses asp.
The only problem is in my secured folder, it only accepts the
username/password if you want to use html.
If you try and access an asp page it says the username/password does not
work.
????
... more >>
SSL
Posted by Jici at 11/27/2003 6:58:54 PM
i got a web site like www.compagny.com who work very well
and i apply the SSL encryption. Now when i type
www.compagny.com and cannot access the page because i have
to put a https: before my adress. What i have to do to
redirect my http:\\www.company.com to
https\\www.company.com.
than ... more >>
Authentication problem
Posted by PL at 11/27/2003 4:26:53 PM
I'm having a problem authenticating through IIS 6 and I cannot
figure out what the problem is.
I have created a user group called OfficeAdmins, all members
of this group should have access to the admin folder I placed on
the server.
I removed the IUSR permissions on this folder and added ... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Help,I can't merge word document in the server
Posted by lee_j at 11/27/2003 11:30:43 AM
Hi,
I want to merge a word document in the server to display in
the client side.The merge code is in a dll.In the asp server script,
I invoke the dll to merge.It raise an error when I use the default
IIS user.When I change the IIS user to administrator,It work well.
I don't know how I shoul... more >>
Windows 2003:IIS 6:File server
Posted by Bhaskar at 11/27/2003 7:51:09 AM
Hi
I have a .NET application hosted on IIs 6.0. I am using an other machine (again a windows 2003) as a file server. Whenever I try to upload a file to my fileserver through browser, it asks for an authentication. This authentication is for the localhost. I have tried to solve this problem by crea... more >>
CertificateAuthority.Request failed
Posted by cfrketx at 11/27/2003 7:41:05 AM
hello, company for which I'm working, is using IIS5.0 and certificate authority for webpages that supports our customers, yesterday I tried to create cert via intranet and something goes wrong, after attemp to contact cert authority any computer says that there is unexpected problem with CA server, ... more >>
ASP.NET W2K3 UNC: Server Error in '/' Application
Posted by Augustus at 11/27/2003 4:15:44 AM
I have problem with ASP.NET files on a NAS Appliance (W2K)
using UNC, through a W2K3 PDC IIS6, while working fine
when the virtual dir is located on the W2K3 (Standard)
Server itself.
The aspx files on the NAS generate the following error;
Access to the
path "C:\WINDOWS\Microsoft.NET\Fra... more >>
Web Site utilization
Posted by booner at 11/26/2003 7:23:26 PM
I have a web app running on IIS 5.0. I was curious how much it is getting
utilized. Some investigating and I notice log files
c:\winnt\system32\LogFiles\W3SVC1 with lots of information. Are there any
tools to help figure out how many hits (running an analysis on these log
files perhaps) a web... more >>
Adding Application Configuration for a Virtual Directory
Posted by Kevin Mei at 11/26/2003 1:12:58 PM
Hi,
I was tryying to add a new "Extension to the Application Mappings for a
Virtual Directory"; I was able to go to the "Add/Edit Application Extension
Mapping" dialog. However, the "OK button" always grayed out. I couldn't
seem to add it. I was able to add it before, this issue started to... more >>
https:// sites cached?
Posted by Brook at 11/26/2003 9:29:09 AM
Does anyone know if https sites are cached?
Thanks,
Brook... more >>
Domain Secret?
Posted by thegalaxyboy at 11/26/2003 7:37:33 AM
Dear IIS Community,
I am configuring an ISA server with RSA SecurID
authentication using the instructions titled 'Using the
Web Filter for authenticaton for RSA Security'. And one
of the steps is to "...import the domain secret to the IIs
server...".
Where in IIS do you import the d... more >>
IIS6.0 Download exe problem
Posted by John Collins at 11/26/2003 6:10:32 AM
Running: IIS 6.0 on Windows 2000 server.
Whenever I attempt to download an exe off of my server, I
receive the following error:
Internet Explorer cannot download <insert file name> from
<insert website name>.
Internet Explorer was not able to open this Internet site.
The requested site ... more >>
Problems viewing .pdf etc... over secure https:\\ pages
Posted by Richard sahonta at 11/26/2003 2:28:46 AM
Hello All...
I am the network technician at a school and we cannot view
pdf files. We receive a Microsoft Internet explorer error.
the error appears only when it is pdf file that is being
downloaded. I have placed a .bmp file in the same same
folder with same permissions and setup a hyper... more >>
hacker
Posted by dina ibrahim at 11/26/2003 1:23:02 AM
Someone has hacked my email after blocking the sender for
a few times. I live alone, and no one knows my password.
I don't know how that happened. After blocking out their
emails, this person hacked my email, and started to use
my old email to send messages to my new email ! This
person se... more >>
cannot logintp secure web sites
Posted by mickey at 11/25/2003 9:26:07 PM
Problem : I cannot get into secure web sites..
I have worked with several forum groups and technical
assistances and have tryed several things but after 4 days
I still cannot get into sites where I have to have a
userid and password. I cannot download from
windows live update," it says wi... more >>
Problem using ssl Error :Cannot find server or DNS Error
Posted by gopivp NO[at]SPAM hotmail.com at 11/25/2003 8:30:44 PM
i'm using winxp iis 5 and i have create a certificate using iis then
from mmc i copy that certificate to my desktop after that from the iis
pending request i browse that certificate(copy desktop).when i try to
access the page with https the following error occur
I have read all the KB articles... more >>
Requiring Client Certificate
Posted by Tim at 11/25/2003 7:04:40 PM
Can someone point me in the right direction regarding
requiring client certificates. I need to know if
requiring client side certificates is it possible to
specify the acceptable client certificates and deny any
others, if so how do you configure them on the server &
client. What is the... more >>
WebDAV security on IIS problems
Posted by msnews.microsoft.com at 11/25/2003 12:58:49 PM
Hey All,
I have been beating my head over this one for a long time. It has to do
with setting up a WebDAV folder in IIS and setting permissions on that
folder to two accounts - one with read access and the other with full. From
all the documentation, this should be a simple task. WebDAV is ... more >>
SSL Certificate
Posted by MS at 11/25/2003 12:17:17 PM
Hello,
I've installed an SSL certificate I created on an IIS 5.0 server. Whenever
our client use the website, they are asked to accept our SSL certificate
even after they install it. Is there a way to prevent the users from getting
prompted to install our certificate over and over again? Thank... more >>
2 SSL certs for 1 IIS site?
Posted by J Yue at 11/25/2003 12:01:21 PM
We have an IIS site with a SSL cert installed.
We are setting up a new extra URL and a new cert to access this site and
needed SSL for it.
Can we configure IIS to accept 2 certs for the same site? so you will be
getting SSL no matter which URL you use to get to the site.
Thanks
-jas
... more >>
Controling Content by User
Posted by Rob at 11/25/2003 9:45:16 AM
I need to be able to control the content of the site by
which user logs in. Say have an extra link on the admin
group account for admin changes to the site. Any help is
appreciated.... more >>
Force disconnect from IIS 5 ftp server
Posted by mickx at 11/25/2003 8:58:13 AM
Hi
1st time here, so excuse my ignorance and if this thread
has been discussed.
Is it possible, within IIS5, to configure the ftp server to
tear down the connection after a 'configurable' number of
failed auth attempts with a bad id / passwd?
tx in advanced... more >>
How to define cipher type allowed in an ssl session
Posted by Danny Schelberg at 11/25/2003 8:05:11 AM
Does anyone know where exactly in a Win2K IIS 5.0 Server
you would define the cipher type allowed in an ssl
session. I sumise that it is a registry tweak and would
appreciate any info on this topic
Regards,
Danny Schelberg
CCNA, MCSE, MCP + I
Network Engineer
Procurestaff
Volt I... more >>
Name of certificate doesnot match name of site.
Posted by BWilliams at 11/25/2003 6:06:10 AM
I have generated a certificate using Certificate Server. Everything is working, except I get "The name of the certificate is invalid or does not match the name of the site." I have re-generated the certificate several ways according to article 813618 and 232161. I am trying to use an ip address inst... more >>
how do I force secure ASP.NET session cookies?
Posted by Ed at 11/25/2003 3:17:30 AM
I am running a pure SSL website using forms authentication
with encrypted authentication cookies. I can tell ASP.NET
to issue the authentication cookie with .Secure=true so
that the browser only submits the cookie over an SSL
connection.
However, the server does respond to http requests ... more >>
are my binaries being exposed on my ASP.NET website?
Posted by Ed at 11/25/2003 3:16:50 AM
We've had some security consultants go over our website
looking for vulnerabilities, and they've found a binary
file exposure problem, but I can't reproduce it - has
anyone seen something like this?
My website runs on SSL and uses forms-based
authentication. IIS lockdown and URLScan 2.5 ... more >>
Hardware Firewall recomendation needed
Posted by Mini Me at 11/25/2003 3:12:45 AM
Our office currently has a server connected to the Internet that allows
our employees and clients to access it via HTTP, HTTPS, FTP and email.
We put it behind a linksys router and passed the appropriates ports
directly to that machine while blocking all other ports.
However, we're moving ... more >>
Unable to Connect to Secure Web Page with I.E. 6
Posted by Riad at 11/25/2003 3:10:05 AM
I am unable to connect to secure web pages (e.g. logging
in to hotmail)with internet explorer 6.
I have gone through the security settings - but no luck...
Please Help!
... more >>
IIS authentication for Sharepoint
Posted by Sweta at 11/25/2003 12:45:32 AM
Hi,
Can you tell me how IIS and Sharepoint communicate about
authenticated users???
Regards,
Sweta... more >>
Security implications of giving F access to directory
Posted by Spook at 11/24/2003 9:46:04 PM
Hi
My ASP based website relies heavily on an MS Access database to display it's content. The database is outside the root directory of my site, so it cannot be accessed via the web, and a System DSN has been set up on the server.
This worked fine, until the security of my database became an issu... more >>
Problem with Internet Explorer 6.0 and secure sights
Posted by Misti at 11/24/2003 8:48:14 PM
With Internet Explorer 6.0 I keep getting "page cannot be
displayed" error on secure sights. I have a Dell brand
computer and they have not been able to solve this
problem. Please help. Thank You! Mistie6802@yahoo.com... more >>
Website got hacked
Posted by Chirashi at 11/24/2003 7:56:28 PM
My website got hack and I want to know how can I replace my index.asp,
index.html, default.html and default.asp. Everything else is okay but they
seem to have replace these 4 files, how can I replace these files if my
original ones have been replaced. Thanks
... more >>
kerberos for iis ?
Posted by Sanjay at 11/24/2003 6:18:22 PM
Hi,
Is there a simple howto on getting a Win2K client, logged on to Active
Directory (AD) domain, get a file from IIS server (running on AD server)
with Kerberos authentication ..?
-- IIS server is running on the Active Directory server (win2k domain
server).
Win2k Server, SP2
IIS 5.0
--... more >>
Windows authentication failing
Posted by ktuel NO[at]SPAM streck.com at 11/24/2003 5:05:08 PM
I have a very small website, 1 page right now, it is for internal use
only. I have anonymous access disabled and windows authentication
enabled. When any user, even the web server itself, uses IE to
connect to this site, I get a box requesting my usename, password and
domain. All machines in ... more >>
removing cmd.exe properly
Posted by danny schelberg NO[at]SPAM volt.com at 11/24/2003 2:52:45 PM
I recently followed the article below as an added IIS
lockdown step. Removing cmd.exe for some reaseon does not
work since it keeps getting restored by what I sumise to
be windows file protection. Does anyone know what else I
can do to insure cmd.exe does not return to the default
path eve... more >>
install security process incomplete
Posted by Sherryl at 11/24/2003 2:09:57 PM
upon downloading critical security updates, KB828035 will
download but quits at install. After several attempts to
complete install without success Im baffled. Any help???... more >>
IIS for Win XP Pro
Posted by Christy at 11/24/2003 1:47:06 AM
I have setup IIS 5.1 in my Win XP Pro, after setup i
can't view or display the .asp page but it's work
for .htm page. how can i solve this problem?... more >>
server 2003 ASPNET and DC
Posted by John Smith at 11/23/2003 10:31:57 PM
I have tried to follow the instructions that I carried out for Win2k
now I cannot get my website to work on a server 2003 Domain Controller.
Is there better instructions out there than the MS instructions which are
all out of date?
Also, there is not Local Security Policy in the Admin tools,... more >>
401.3 error with IIS 6.0 on Windows Server 2003
Posted by Ranjith at 11/23/2003 4:22:43 PM
I have an ASP .NET Application running on a windows server 2003 system.
Configured IIS to use integrated windows authentication. As an admin of
the system, I do not have a problem accessing the web site hosted on
this system. But other users in the domain get a 401.3 Unauthorized due
to ACL on r... more >>
Multiple SSL on diffrent nics???? Please help
Posted by G_Man at 11/23/2003 11:56:07 AM
OK......!!
I have got this working before but now it just seems it does not want to work!!
I have a web server running IIS 6 on Windows 2003 Enterprise edition
It has 4 network cards and should run 1 web site per network card as each site needs it's own SSL cert
I have removed the use all una... more >>
Anonymous Virtual Directory Requires Authentication
Posted by DX at 11/23/2003 10:23:40 AM
I set up a virtual directory within the default web site.
Clicked this virtual directory and went to properties-
>Directory Security->Edit Enable anonymouse access->ensure
enable anonymous access is checked and using iusr_machine
with correct passwd.
But when I try to access this virtual ... more >>
IE problems
Posted by Raf at 11/23/2003 4:10:31 AM
Each time a restart my computer and use internet explorer
the default page changes and the list of recently viewed
pages turns into porn site. Is this common and what is
the solution. Thanks... more >>
does IPSec provide enough security for web server?
Posted by Isabella at 11/23/2003 12:34:25 AM
I have only IPSec installed, no firewall or anti-virus. Is that secure for a
web server?
Isabella
... more >>
Unable to access our SSL page
Posted by Paul at 11/22/2003 1:22:37 PM
Hi All,
I have setup IIS to require a SSL connection to access my website. However,
when i try to connect Internet Explorer says that the page cannot be
displayed.
If i then try to access the site without the https, i am told that i cannot
access it because its requires SSL.
Additionally... more >>
Anonymouse access causes Unauthorized Access error
Posted by Barry Fitzgerald at 11/22/2003 11:53:04 AM
I am getting an access error ( HTTP Error 401.1 - Unauthorized: Access is
denied due to invalid credentials. Internet Information Services (IIS))
when trying to access the default web site on a Win2003 Server that is in a
domain using anymous access. This occurs if I disable the Integrated
Win... more >>
unable to connect a secure site
Posted by vikas at 11/22/2003 11:37:00 AM
hi
i am getting the following message on my web browser. can
someone tell me what and why this is happening. and what
is the solution or remedy for it?
The page must be viewed over a secure channel
The page you are trying to access is secured with Secure
Sockets Layer (SSL).
---------... more >>
Forcing client to have certificates
Posted by Andrew at 11/22/2003 11:26:31 AM
Hi..
How do you configure your website so that it forces clients to have a
certificate before allowing access?
Andrew
... more >>
IIS 5.0 can't handle multiple request at the same time with the same Web site(Application)?
Posted by Rayman at 11/22/2003 10:59:26 AM
Dear All,
I am currently using Windows 2000 SP 4 with IIS 5.0.
I found that IIS 5.0 can't handle multiple request at the same time=20
with the same Web site(Application), here is the code for testing:
-----------------------Begin--------------------
<%
response.write "Start Time : " & now(... more >>
IIS 6 - UNC - 401.1 - Access is denied due to invalid credentials
Posted by Augustus at 11/22/2003 4:35:51 AM
I've setup a Windows 2003 Standard Server as PDC with IIS
and a NAS (Dell PV 725) with Windows Powered 2000 Server.
A simple website (IUSR read-only, client R/W) with a
password protected directory for the website statistics
(no IUSR, client read-only).
This situation hosted locally on the W... more >>
IIS account as a domain admin
Posted by scanner2001 at 11/22/2003 2:45:11 AM
In a conversation recently, one of my co-workers was arguing that it was
acceptable to set up the IIS anonymous account as a domain user that is a
domain admin. I argued against this point, noting that if someone were to be
able to "hack" thru a web page, they would have full control over not... more >>
Website keeps asking Windows login
Posted by rhu at 11/22/2003 1:31:05 AM
I run Win2k Adv. Server (with IIS4/5?). I set up a
website on it. Each time when I'm opening the site from
another machine it always asks me to login with my
Windows username and password. Please anyone help to
tell me what's going wrong in my IIS settings? Thanks.... more >>
|