Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
all groups > iis security > december 2003 > threads for december 15 - 21, 2003

Filter by week: 1 2 3 4 5

IIS security alert - new attack?
Posted by Chris Popescu at 12/21/2003 7:07:41 PM
Hi, Does anyone know what kind of attack is this and how can be prevented? IIS servers will not be able to serve any other pages for the time when this attack is active. We use UrlScan and we have IIS 5/6 patched with latest security patches. However from IIS logs I can not see much abou...more >>


Free Buffer Overflow Protection Software for Windows 2000/XP/2003 Systems
Posted by info NO[at]SPAM sys-manage.net at 12/21/2003 9:01:58 AM
BufferShield is security software, capable of detecting and preventing attempts to execute code on the stack and the heap memory area, in order to stop the exploitation of buffer overflows. It is a very useful addition to Windows Update, minimizing the risk of unresolved security exploits, cause...more >>

How do you delete Autocomplete History?
Posted by Kristen at 12/20/2003 12:16:46 PM
I was running a search on my computer and I noticed that it saved my search on the autocomplete. I found out how to do it so that it doesn't show the autocomplete. But I want to know how to erase everything that has ever been searched so it doesn't come up any more. Thank you...more >>

Erasing autocomplete History
Posted by Desperate at 12/20/2003 12:12:38 PM
When I was running a search, I noticed that it saved the thing I searched for. I found out how to turn off the autocomplete, but can someone PLEASE tell me how to clear the autocomplete list....more >>

Access requires password
Posted by Brian at 12/20/2003 9:39:45 AM
My IIS 6 on Server 2003 worked fine for a month. Then, all of a sudden, it began prompting for a user ID and password and no id password combinations worked, including the admin. The system had not been touched for 3 days prior to this beginnning to happen. The logs show a 403.3 and 403.5...more >>

Cleaning hacked IIS server
Posted by JonR at 12/19/2003 3:51:17 PM
I have an IIS server that has thousands of folders and files that have been posted by a hacker. I have tried taking ownership, forcing new permissions, cutting off inheritance and am unable to move or delete the files. I ran The Checker to scan for trojans and backdoors, but it found nothi...more >>

Permanently turn off Integrated Windows Authentication?
Posted by Research Services at 12/19/2003 2:55:04 PM
Is there a way to permanently turn off Integrated Windows Authentication on Windows 2000 SP4 IIS 5.0? We know that you can uncheck the box for it on the Properties for that specific virtual directory under Authentication Methods, but every time the server is rebooted or if the IIS Admin Se...more >>

do i have to purchase an ssl?
Posted by blarfoc NO[at]SPAM yahoo.com at 12/19/2003 7:16:09 AM
i have a non commercial web site on my server that i ask users to log into. they have to pass a name and a password. i want to use ssl but cannot afford to buy it every 2 year. can i make my own certificiate for my https? i understand that a user will get a message saying my cert is not fro...more >>



Map folder to drive letter instead of partitioning disk
Posted by NK at 12/18/2003 8:48:49 PM
Hello, I have run into a problem and I wanted to run my idea by the group to receive your feedback on it. I would like to follow the best practice of putting the system, web content and log files in different drive partitions. However, I have to do this on an existing web server with ...more >>

Accessing Foxpro Table on server other than IIS
Posted by GeorgeO at 12/18/2003 5:24:31 PM
Hi I have two W2K member servers in an Active Directory domain. One runs IIS, the other holds dbf files that are to be accessed by ASP scripts running on iis. I am getting the following error: Microsoft OLE DB Provider for ODBC Drivers error '80040e37' I have read up on KB 175801 and done wha...more >>

Programmatically accessing individual file security configuration
Posted by dmiller NO[at]SPAM crowechizek.com at 12/18/2003 2:40:38 PM
I currently have a manual process as a part of an install that I'm trying to automate. Is there any way to do the following to an individual FILE within a virtual directory through ADSI, WMI, or some other means (ie. Win32 API's)? a. Run Start-Programs-Administrative Tools-Internet Services M...more >>

Turn Off SSL
Posted by Brian Thurman at 12/18/2003 1:33:11 PM
When IIS 5 starts with the default settings, it listes on ports 80 and 443. I have the ability to modify the IP addresses and ports for non-secure communications but the settings for the Secure identities are not enabled. I have a separate web server which needs to run on port 443 using ...more >>

IIS authentication across domains
Posted by Ken Widmaier at 12/18/2003 11:30:11 AM
We are running a asp application on an IIS 5 server. Part of the application reads account and domain names of the users and stores it in a database. This works fine as long as the users are in the same domain as the IIS server. When users are in a sister domain in the same forest, the ...more >>

Homepage Hijacking
Posted by e jones at 12/18/2003 9:50:51 AM
I have a couple of problems. One my homepage has been changed to find4u.net, I have followed microsofts instructions to get it back, I bought new antivirus software, loaded both spybot and ad-aware, i even tried to use the registry to change it, but every time I shut down and reboot it is...more >>

shutting down a server with iis and asp
Posted by John at 12/18/2003 8:33:01 AM
ok heres the deal yesterday i was Remote desktoping in to my computer when i opened a program that was using all my cpu when that happed it kicked me off Remote Desktop and i could not get back in to my computer the whole day anyways i was going to use IIS and ASP to write a aspscript to r...more >>

OWA via SSL & redirect stopped working????
Posted by Harrison Midkiff at 12/18/2003 6:20:10 AM
Hello: I have been using OWA with SSL and have been redirecting the http to https per TechNet Q279681. Everything has been working fine until the other day IE started getting a different error message which caused the redirect the break. Now I am getting "HTTP Error 403 - Forbidden"...more >>

https problem
Posted by stutzdaniel NO[at]SPAM yahoo.de at 12/18/2003 1:01:30 AM
Hello, When I want to use OWA from a Browser outside my LAN with the URL https://www.mydomain.com/exchange I get an error message "page cannot be viewed". (SSL 2.0, SSL 3.0 and TLS 1.0 is activated on the browser. I can access other sites with https.) It works doing the same from within the...more >>

HTTPS PROBLEM
Posted by stutzdaniel NO[at]SPAM yahoo.de at 12/18/2003 12:15:25 AM
Hello, When I want to use OWA from a Browser outside my LAN with the URL https://www.mydomain.com/exchange I get an error message "page cannot be viewed". (SSL 2.0, SSL 3.0 and TLS 1.0 is activated on the browser. I can access other sites with https.) It works doing the same from within the...more >>

IIS5.0 + ADSI + Inetgrated Auth.
Posted by Petr SIMUNEK at 12/17/2003 9:27:21 PM
Scenario: -------------------------- - Native W2K domain - Multiple DS and MS - IIS installed on one of the Member Servers - Main public WEB site with security set to ANONYMOUS ACCESS uses LOCAL IUSER_MachineName account of this member server. Inside Virtual Dir with security set to INTEGRATE...more >>

'CertificateAuthority.Request'
Posted by Paul Jones at 12/17/2003 7:39:06 PM
Failed to create 'CertificateAuthority.Request' object. I am getting this error on a Windows 2003 Certificate Server when trying to submit a certificate request. There are no invalid characters in the certificate. Thanks, Paul...more >>

Outlook WebAccess (Exchange 2003) with SSL on IIS 6 (Windows 2003)
Posted by Andreas Hilp at 12/17/2003 6:04:54 PM
Hello, I want to use Outlook WebAccess (Exchange 2003) with SSL on an IIS 6 which is running on a Windows 2003 server. I have created a certificate successfully. After I have installed this on the default website you cannot connect to the https/SSL port 443. But the IIS is listening on this p...more >>

spy ware
Posted by F.G.Yates at 12/17/2003 3:47:00 PM
I recieved a pop up message while I was on the internet. "Microsoft has detected that you have tracking software installed in your machine. This is not a virus, but a programin your machine that montors and transmits all your online activities and is a serious violation of your privacy. Cl...more >>

Internal IP address security IIS 6.0
Posted by Chris Somsak at 12/17/2003 12:51:21 PM
Something we've noticed with IIS 6.0 vs IIS 5.0 is that the client system shows the internal IP of the webserver, which is something we'd prefer not to broadcast. To reproduce this just use telnet to connect to a webserver on port 80 and type GET / That will show you some info as well as the inte...more >>

Use Apache
Posted by Ben at 12/17/2003 12:23:46 PM
It is alot more secure and has a lot more support for other features. And if you didnt know apache can run on windows! Switch to Apache...more >>

Integrated Authentication for IIS 5.1 on XP
Posted by dc at 12/17/2003 8:41:18 AM
I have migrated a Websphere application to XP from NT, and I am now having problems with IIS security. My app was working on NT with "NT Challenge/Response" authentication for IIS directory security but does not want to work on XP IIS 5.1 with "Integrated Windows authentication" checked. ...more >>

Cross Site Forbidden Error
Posted by apicaller NO[at]SPAM yahoo.com at 12/17/2003 8:21:06 AM
Anyone know if the error message below is being returned by IIS or not? All of a sudden any URL that contains a % or ' throws the error below. I encrypt some URLS which naturally have % in them. Several apps are broke due to this! 403: Access Forbidden Due to the presence of Cross Site S...more >>

Remote file access from IIS
Posted by Ravi at 12/17/2003 12:55:27 AM
Hi I am trying to access files located on different machines on my network through my IIS. Any help would be appreciated. Thanks...more >>

web-based login page
Posted by leo at 12/16/2003 11:39:48 PM
I use IIS 6.0, I want to use web-based login page, how can I do ?...more >>

Strange application popup
Posted by ja at 12/16/2003 7:35:11 PM
I have the following Application Pop Up in an event log on one of our computers: Event ID: 26 "Application popup: Government Computer : Your ISP will be notified" Is this something that has popped up on the computer in question or is it something that has popped up on a computer trying to l...more >>

can't register CSR - invalid X500 Char - HELP!!
Posted by Tim at 12/16/2003 5:07:29 PM
I'm using IIS6.0 on WIndows 2003 Web Edition. I'm trying to create a new CSR, but it won't allow me to add a comma to my Organization name. I've researched this is a problem in IIS5.0, and it recommends putting the org name in quotes. It still gives me the error in 6.0. Does anybody ha...more >>

SUS question
Posted by Dave at 12/16/2003 4:58:04 PM
This seems the best NG for my question so here goes. MS recommend installing SUS on a dedicated server. Does anyone know why this is ? I appreciate the web server is heavily locked down when installing SUS and can see why you wouldn't want to run other web sites on the same box. But, why woul...more >>

Best security practices for IIS6/2203
Posted by hal NO[at]SPAM nospam.com at 12/16/2003 4:40:07 PM
I am assisting our web developers in setting up IIS6 on a new 03 box and am looking for some whitepapers to best practices for securing and Intranet/Internet site. In particular I am looking for something that discusses the use of the predefined users IWAM_<server> and IUSR_<server> names in re...more >>

** READ THIS BEFORE POSTING - answers to frequently asked questions 2003.12.16
Posted by Karl Levinson [x y] mvp at 12/16/2003 3:13:52 PM
Before you post a question to a Microsoft.public.*.security newsgroup, note that your question may already be answered below: Answers to Top Frequently Asked Questions: http://securityadmin.info My question is not mentioned below. How do I get an answer immediately, with no waiting? http:...more >>

IIS 6.0 Network services startup
Posted by navneet at 12/16/2003 3:06:05 PM
Hi, I have installed IIS 6.0 on W2K3 Enterprise. I have configured the 3 sites as per the necessary requirements and the sites as well as the concerned application pools are up and running. If I run/enable the application pools using Network Service or Local Service accounts, the pool will stop upo...more >>

pop ups....
Posted by Rafael at 12/16/2003 1:58:31 PM
this pop ups just keep on comming and comming, i know there are pop ups blockers that you can buy, but before someone helped me do it by changing something in the computer some configuration.... anyone? thx ...more >>

Windows 2003 Upgrade Questions
Posted by interflex NO[at]SPAM hotmail.com at 12/16/2003 10:58:51 AM
We are currently hosting sites on a single server running Win 2000. We want to: a) Upgrade to 2003 and move the sites to this new OS b) We want to ensure that the new infrastructure has fail-over (hence if one web server fails the other keeps going) c) Does 2003 offer the same Index Server s...more >>

How is this done?
Posted by Kevin at 12/16/2003 8:03:05 AM
We're developing our own site and we are curious about how other sites are implemented. Can someone tell me how this site may have been done? Go to http://www.datek.com/ and click on the green 'Datek Log-In' button at the top of the page. I recognize that you are taken to a page protected b...more >>

Unwanted icons
Posted by Rudy at 12/16/2003 3:42:25 AM
Several unwanted icons have lodged themselves just under the address window on microsoft exploser 6. These are unwanted links to various internet sites. Does anyone know how to get rid of them? I have run virus detection software and they are not located as a virus....more >>

ASP Server.CreateObject("OracleInProcServer.XOraSession")
Posted by J. Koch at 12/16/2003 3:13:08 AM
Hi, I'm trying to create the object OracleInProcServer.XOraSession in ASP and I get the folowing error: Server object error 'ASP 0178 : 80070005' Server.CreateObject Access Error The call to Server.CreateObject failed while checking permissions. Access is denied to this object. ...more >>

resetting password
Posted by Mindy at 12/15/2003 6:39:48 PM
Hello, I have forgotten the password I used to set content advisor up. How do I reset the password in Internet explorer? Mindy ...more >>

Cannot access Web site after business hours
Posted by Peter V at 12/15/2003 6:18:37 PM
Have just installed Windows Server 2003 (Small Business Server 2003)& transferred web to IIS 6. It works fine during the day, but access to the site is denied after business hours????? ie site does not work between 5:30pm & 7:00am Any Ideas...more >>

restrict by browser type
Posted by Jeremy at 12/15/2003 4:43:38 PM
Is there any sort of filter or configuration that would allow me to restrict access via user-agent/browser type in IIS5 and/or 6? TIA, Jeremy ...more >>

How to setup PW Protect site and how to log users?
Posted by Sean at 12/15/2003 1:01:10 PM
Hello, I need to setup a password protected website for our company by using windows 2000 server (IIS 5), and also need to LOG and monitored each user's activited. Could someone help me out with this one. Thank you, ...more >>

IWAM account
Posted by Chuck at 12/15/2003 11:29:24 AM
I upgraded to WinXP last week and installed IIS. When I try to run my web app (Java Applet and lots of ASP), I get the following error logged in EventViewer: Event Type: Failure Audit Event Source: Security Event Category: Logon/Logoff Event ID: 534 Date: 12/15/2003 Time: 1:18:10 PM U...more >>

OWA and IIS over SSL
Posted by Rob Kerner at 12/15/2003 10:30:38 AM
I finally set up a certificate on my IIS server for Outlook web access. My question is how do I set up a redirect. The old address is http://servername.ucdavis.edu/exchange, and I want them to be autoredirected to the https site. In IIS Admin, it is using a virtual folder called \\b...more >>

Why is my web site so slow?
Posted by Mystery at 12/15/2003 8:42:03 AM
I have a standard install IIS server running with Windows Authentication on our Small Business Server at work (1024/512 ADSL). I'm running a small asp web site that generates pages from our sales database of around 1k per page (no graphix, just text). I'm using a PDA (HP iPAQ) and a Bluetooth ...more >>

Unauthorized: Logon Failed
Posted by cg NO[at]SPAM gbo.ch at 12/15/2003 4:56:46 AM
Hi, I've many clients computers whit XP professional OS and=20 2000 professional in a Windows 2000 domain, my intranet=20 server is =E0 Windows 2000 server (IIS 5.0). Any time that a client XP try to view the home page of=20 Intranet, obtains a error message "HTTP 401.1 -=20 Unauthorized: Lo...more >>


DevelopmentNow Blog