Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
all groups > iis security > december 2003 > threads for december 8 - 14, 2003

Filter by week: 1 2 3 4 5

Authentication Error - HELP
Posted by gregnowlives NO[at]SPAM yahoo.co.uk at 12/14/2003 11:45:13 AM
Hi, I'm trying to set up my home pc with 2000 pro IIS 5 installed. After writing a simple asp page to open a database and pull back the records of a table to test, I am getting an error :- c:\inetpub\wwwroot\adotest\backup\myhols.mdb Provider error '80040e4d' Authentication failed. ...more >>


is this a bug?????
Posted by Mel at 12/13/2003 12:32:57 AM
i am constantly receiving e-mails which are supposedly from "public support" at microsoft, subject "newest network critical upgrade,or bug announcement" also a returned e-mail which i have no knowledge of ever sending, supposedly to rrqstiv@bigfoot.com norton keeps deleting the offendin...more >>

Importing CERT into Win2k for IIS
Posted by Jeff Fink at 12/12/2003 2:11:49 PM
I have two parts to the CERT. I have the original part I sent the supplier which looks like this: -----BEGIN NEW CERTIFICATE REQUEST----- <cert info> -----END NEW CERTIFICATE REQUEST----- and I have the response sent by the Cert supplier. I can go into MMC and add the Certificates snap-in,...more >>

sign in
Posted by swbell.net at 12/12/2003 1:04:33 PM
it won't let me sign in with my password which is rascal w5ujojoe@swbell.net...more >>

Microsoft FTP Server problem on W2K?
Posted by DavidM at 12/12/2003 10:53:57 AM
We have a mainframe at work that FTPs file to a Microsoft W2K FTP server using SP4. Since the mainframe appears to be bogged down at times and doesn't seem to respond to FTP requests on its server nor respond quickly enough when it sends files out, I made a request to have all outgoing FTP file...more >>

"we have been hacked"
Posted by RLF at 12/12/2003 10:53:50 AM
Our web home page (tools<internet options<general< homepage)seems to be hijacked, or as the information on the page we are directed to suggests (see below) "we have been hacked". My question: is the info below legitimate? Can we or should we follow the instructions it provides to rid ou...more >>

Send form information via e-mail
Posted by Alan at 12/12/2003 9:21:24 AM
My smtp server requires a log on. When I configure a website with my smtp information then try and fill out a form on my web site it says that it can't send it because it requires a log on, but there is no where in the 2002 extension set to provide this information. Here is the error I a...more >>

IIS 6.0 IISADMPWD help
Posted by Greg at 12/12/2003 9:21:24 AM
I'm trying to configure IISADMPWD within IIS 6.0 with no luck. I have created an virtual directory to C:windows\systems...iisadmpwd. When I browse I get this error: The page cannot be found HTTP Error 404 - File or directory not found. Internet Information Services (IIS) I'm using ...more >>



cannot publish the *.asp files from the Netscape
Posted by Chris Klapuic at 12/12/2003 3:27:20 AM
Hi I cannot publish the *.asp files from the Netscape Composer 7.1 or 4.79, but it works fine if I change the extension to anything else .htm etc. Bit on what I am trying to do. At my work place we provide maintenance support and the procedures are everything to us, but unfortunately t...more >>

That nice old ISAPI to scramble ASP scripts?
Posted by Alexander Maltsev at 12/11/2003 10:14:58 PM
Hello gents and ladies, I haven't used this thing for several years and now can't recall its name. The magic thing I'm talking abot is an ISAPI extention plus an utility that scramble .ASP sources into unreadable state (i.e. no one can read the source, say an intruder or a client that wishes t...more >>

IIS Lockdown Wizard
Posted by John at 12/11/2003 10:09:44 PM
Hi Sorry if this is a repeat, but my news server only stores 200 messages! The MS Baseline Security Analyser recommends installing the IIS Lockdown tool, but I have a live webserver with lots of important sites on, and only accessible by remote admin terminal services. All the site use most...more >>

Windows 2003 (IIS6) security question
Posted by ML.net at 12/11/2003 8:25:37 PM
If you enable (success) auditing for "Audit Logon Events" or "Audit Account Logon Events" will it log I_User account logon's? Obviously, my concern would be for a high traffic web server getting an essentail DOS attack against itself due to a high volume amount of logging in the security logs. ...more >>

IIS Basic Authentication & Windows 98 machine
Posted by Jennifer at 12/11/2003 2:14:45 PM
I just configured Basic Authentication on a few areas of my web server and it works fine, except for people who are on a Windows 98 machine. When they try to log in, the login box keeps reappearing instead of accepting the user/password info. Did I miss a setting somewhere? What do I need...more >>

ISAPI Authentication
Posted by Kevin at 12/11/2003 1:00:50 PM
I'm considering writing an ISAPI filter to handle authentication. Will it completely replace the configured windows authentication or will it serve as an extra authentication step before the windows authentication? The documentation says that I can return SF_STATUS_REQ_NEXT_NOTIFICATION ...more >>

HTTP Trace command vulnerability
Posted by GregG at 12/11/2003 10:28:08 AM
I have been notified from my client after a vulnerability assessment that their web server (on the Exchange 2K server running OWA) has the "HTTP Trace Commnad" enabled and that it was a vulnerability. I cannot find any place to disable this or even very much about it. Anyone know about t...more >>

URLScan
Posted by rich_legend NO[at]SPAM yahoo.com at 12/11/2003 10:05:04 AM
Hi Guys Can anyone help with allowing full stops using URLScan the error is Client at 127.0.0.1: URL contains extension '.', which is not specifically allowed. Request will be rejected. Site Instance='1', Raw URL='/TestWeb' I can not find '.' any where in the urlscan.ini file This is...more >>

Problems with Administrator users
Posted by Rane Bowen at 12/11/2003 9:51:11 AM
Hi. I hope that I am posting to the correct group and that someone can provide me with some clues with a particular problem we are having. First some background: Our document management system uses iis with a custom isapi filter. The user (after authenticating via ntlm) is presented with a...more >>

URLScan Config for Internet Synchronization
Posted by Martin Cline at 12/11/2003 9:28:44 AM
I have a box running WinXP/IIS setup to run an Access database with internet synchronization. The box was hacked by W32.Spybot.Worm. I do have URLScan 2.5 enabled, but .exe extensions need to be allowed for the internet synchronization to work. Is there anyway to deny all .exe extensions except...more >>

IIS, Basic authentication, Default domains, and Session
Posted by craig_j_dawson NO[at]SPAM hotmail.com at 12/11/2003 8:01:37 AM
I have two ASP web pages running on IIS 5. Both are configured to require basic authentication. Page1 has a default domain of domain1 for authentication purposes. Page2 has a default domain of domain2. When a user access page1, they must provide credentials in the logon dialog: username: user...more >>

Login into OWA
Posted by eddie at 12/11/2003 7:50:24 AM
When my users try to log into the OWA to check their email from the WEB they continue to get asked their username and password. They enter the correct information but they are never logged in to view their email. I have to turn on the windows intergrated logon in order for them to see th...more >>

Secured sight
Posted by Joe Kaz at 12/11/2003 6:47:52 AM
I want to block one specific sight, and I can do that, but it also blocks my home page for Yahoo. I even added yahoo as a sight to alway be viewed. What can I do?...more >>

Cannot access Secure Sites
Posted by Susan at 12/11/2003 6:46:07 AM
Cannot access secure sites -- keep getting 'page not available' message....more >>

basic question - intranet/internet
Posted by KJ at 12/11/2003 6:01:20 AM
I'm new to the networking end of things. What is involved in making an intranet webapp available to the internet? And what is involved in making an internet webapp an intranet app only? When making a intranet webapp available to the internet, what kind of hardware changes are needed? I ass...more >>

Granting IP Addresses in IIS
Posted by skc at 12/11/2003 1:28:24 AM
Running Windows 2000 Server. I need to grant IP addresses from our client, as their IP addresses have changed. The client now has a IP range, and quite a few of them - I need help on how to enter them into the Granted list: E.g. Scope [x.x.x.0] Site_Name - x.x.x.10 - x.x.x.129 Scop...more >>

Safari can't handle non-anonymous type schemes
Posted by Chris F at 12/11/2003 12:09:55 AM
OK, I have a site in IIS 6.0 that I removed the anonymous access to for now. I just don't want the general public looking at the site while it's under development, not even a splash page. So, I took the anonymous access off (via the properties window), which in turn, removed IUSR_SERVER from the ...more >>

HTTP Error 403.15
Posted by RTML at 12/10/2003 11:48:33 PM
Hi, I am having error 403.15 when multiple users try to call the website. Configuration: -User authentication via ADSI (different Server with the WebServer) -Upon authenticated, the default page will be called from the WebServer Checking from Microsoft website, this error is related to ...more >>

IIS Isolation Mode
Posted by Amol Naik at 12/10/2003 8:56:08 PM
HI, We have been building an application for IIS 5.0. But now we want to move to IIS 6.0. We tried to install using the same scripts that we had used for IIS 5.0. It seems to install fine. There were some changes in the scripts that we have done .. like the virtual directory getting created...more >>

IIS5, FTP from behind router?
Posted by Rob Mayo at 12/10/2003 6:45:57 PM
I have a cable (broadband) for an ISP. I have a Linksys cable modem that gets an IP automatically from my ISP (xxx.xxx.xxx.xxx) and sends it to my Linksys Wireless router. Behind the router, I have 2 pcs. Both are Windows 2000 Professional, IIS5, with ftp installed. They both get their IP addres...more >>

Security for delegation in a domain
Posted by Sven at 12/10/2003 1:21:08 PM
I want to create an object on a web server running windows 2003(IIS6)in a domain from an ActiveX-DLL(prnadmin.dll) from the Resource Kit, which lists the shared printers on a third server. It works properly under NT4 an Windows 2000 Servers. If I want to list the printers on a Windows 2003 Server it...more >>

Error Processing a Renewed Certificate
Posted by ccn NO[at]SPAM tpgl.com at 12/10/2003 12:48:03 PM
Hello All, I have been searching everywhere for some leads on the following error: We have a stand-alone Windows 2000 CA. We are using SSL for OWA. The certificate we created in 2002 has expired. I am trying to renew the certificate but I keep getting the following error: Your reques...more >>

MInimum priviledges required for Managing IIS
Posted by neverknow at 12/10/2003 7:18:28 AM
Hi, I am looking to give developers enough priviledges to manage their IIS, doing routine tasks as creating virtuals, setting authentication parameters etc, without giving them local ADmini rights on the workstation. Can this be done ? If yes, how ? Also, I want them to be able to debu...more >>

security
Posted by Hasnain at 12/10/2003 1:24:52 AM
I want password of nazimali780171@hotmail.com...more >>

homepage
Posted by george at 12/9/2003 9:44:47 PM
frequently, my home page is changed to "www.cool- search.net" without my permission. is this a virus / worm. how can i get this out so i dont have to keep going to "internet options" to change it back. anyone?...more >>

Windows 2003 Small Business Server & IIS Security
Posted by Robert Waite at 12/9/2003 9:31:39 PM
David Wang on 12/03/03 in this forum gave an excellent blueprint on securing IIS 6.0 in Windows 2003 Small Business Server (SBS). He, and others, said it is a bad idea to idea to host Public Web Sites on SBS. So my question is: What would be the network configuration/settings/blueprint for hav...more >>

Integrated windows authentication won't work
Posted by David Gagné at 12/9/2003 9:25:17 PM
Hi, I'm running windows 2000 server. I have an IIS web site with Anonymous access that works fine. I want to set the security to "Integrated Windows authentication" for one folder inside this web site. When I clear the "Allow Anonymous" and check the "Integrated Windows authentication" box, for ...more >>

SSL Wildcard Certificate Replacement
Posted by Steve at 12/9/2003 8:09:45 PM
I have 2 web sites for a single domain. One is for my www site and the other is for all other subdomains. I initially installed a SSL certificate for the www site and it expires on 12/12. I purchased a 1 year wildcard certificate to cover the www and all other subdomains. I installed t...more >>

Internet Connection Firewall with Multiple IP's for IIS
Posted by Tom at 12/9/2003 4:12:04 PM
When I switch on the Internet Connection Firewall, it will only allow port 80 access to IIS on ONE IP address. How can I allow access to the other WebSites that are configured with different IP addresses (on the same network adapter) ? I start to think that it is not possible to use multipl...more >>

anonymous password
Posted by peter at 12/9/2003 10:34:02 AM
does anybody know wath this means: The registry key for IIS subauthenticator is not configured correctly on local machine, the anonymous password sync feature is disabled. i cant find anything of it on support.microsoft.com or eventid.net thanks peter ...more >>

IIS Stops responding
Posted by Hector Bonilla at 12/9/2003 8:55:22 AM
Dear Microsoft People, The server we have is running an application that uses IIS, at some time IIS stops responding unexpectedly and returns to the user a violation access and IIS gets down, is not a big issue, as I restart IIS manually and the dialogue between client and server restarts...more >>

Domain Authentication
Posted by Patriot at 12/9/2003 8:17:11 AM
I have created a virtual directory and used VB.NET and ASP.NET for my web app and it works great. My question is; can I secure this application to where only domain admins can open the site? Thank you... ...more >>

SSL and certificates
Posted by Kevin at 12/9/2003 6:30:00 AM
Are client certificates necessary for SSL or just server certificates? The Microsoft help for setting up SSL takes you through creating a server root certificate and another server certificate and then installing each on all of the clients. But other documentation that I have read sugg...more >>

SSL & non-secure items
Posted by Gareth James at 12/9/2003 1:37:14 AM
Hi, I have setup a website running via IIS that is secured via SSL. When I try to access the page, a dialog window appears saying that there are secure and non-secure items on the page and whether I want to display the non-secure items. The question is that when I click on No, the padlo...more >>

Integrated Windows authentication
Posted by ms90933 at 12/8/2003 11:51:46 PM
I used the "Integrated Windows authentication" on IIS 5.0 But when I use IE to connect the IIS, still get a dialog for password. Why ? Any advise will be appricated...more >>

Secure IIS FTP
Posted by Jason Lee at 12/8/2003 11:19:23 PM
Does anyone know of a (preferably free) product that provides secure ftp ability for IIS FTP? Something similar to SafeTP <http://safetp.cs.berkeley.edu/>. I would use SafeTP but the client doesn't work on Windows XP, I'm not sure about its 2003 Server compatibilty, and there are publized ...more >>

unauthorized default browser
Posted by Alice at 12/8/2003 6:54:07 PM
I have an unauthorized default browser on my internet explorer, all attempts to get rid of it have failed. HELP...more >>

site asks for user name/pw for anonymous login
Posted by Gilbert at 12/8/2003 3:52:54 PM
I'm running IIS 5.1 and when I try to get to the site by using the IP address and I click on a specific link (which points to a .htm file) it brings up an authentication menu. I checked the ACL and the file has the same security attributes as all the other files. It didn't do this before...more >>

IIS 5.1 and FTP access errors
Posted by Ken Torri at 12/8/2003 2:21:22 PM
I have IIS 5.1 and FTP services active on a Windows XP Professional system. I am getting "FTP Folder Errors" when trying to access an FTP folder through a firewall. Access works fine via local lan using "localhost" or lan computername as the host name. Port 21 is opened up on my firewall...more >>

Redirect to SSL for entire ASP.NET application
Posted by Stephen Walch at 12/8/2003 12:33:06 PM
I wish to enforce SSL for an entire ASP.NET application (including the custom authentication page and all other pages). To achieve this, I am using the "Require SSL" on the Virtual Directory in IIS. This works, but when users hit the non-SSL version of the page (http:/...) they get an ugly err...more >>

Security
Posted by Rex at 12/8/2003 9:36:09 AM
I am having trouble with securing my web site. It is a Corporate web and I need to know how to stop someone from editing it in front page. If I turn off authoring that stops that but I have .XLS spread sheets that need to be able to be saved and with authoring off I can't. I have tried all...more >>

Unauthorized / Service Unavailable ??
Posted by Barry Fitzgerald at 12/8/2003 7:15:39 AM
I have a new web server (win2003) that is part of a new domain (win2003) that was just set up a couple of weeks ago. Everything except the web server seems to be acting properly. There is a default.htm page set up on the default web site and also a .NET app in a virtual directory. The site wo...more >>

authentication/login scheme
Posted by Kevin at 12/8/2003 6:41:09 AM
I am a developer, not an administrator and want to ask you guys for advice on designing a login/authentication scheme for a new .Net C# product. -The product will run on customers' intranets. (The website may be accessed remotely but we are not ruling out forcing them to go through a VPN...more >>


DevelopmentNow Blog