all groups > iis security > december 2003 > threads for december 8 - 14, 2003
Filter by week: 1 2 3 4 5
Authentication Error - HELP
Posted by gregnowlives NO[at]SPAM yahoo.co.uk at 12/14/2003 11:45:13 AM
Hi,
I'm trying to set up my home pc with 2000 pro IIS 5 installed. After
writing a simple asp page to open a database and pull back the records
of a table to test, I am getting an error :-
c:\inetpub\wwwroot\adotest\backup\myhols.mdb
Provider error '80040e4d'
Authentication failed.
... more >>
is this a bug?????
Posted by Mel at 12/13/2003 12:32:57 AM
i am constantly receiving e-mails which are supposedly
from "public support" at microsoft, subject "newest
network critical upgrade,or bug announcement" also a
returned e-mail which i have no knowledge of ever
sending, supposedly to
rrqstiv@bigfoot.com
norton keeps deleting the offendin... more >>
Importing CERT into Win2k for IIS
Posted by Jeff Fink at 12/12/2003 2:11:49 PM
I have two parts to the CERT. I have the original part I sent the supplier
which looks like this:
-----BEGIN NEW CERTIFICATE REQUEST-----
<cert info>
-----END NEW CERTIFICATE REQUEST-----
and I have the response sent by the Cert supplier. I can go into MMC and
add the Certificates snap-in,... more >>
sign in
Posted by swbell.net at 12/12/2003 1:04:33 PM
it won't let me sign in with my password which is rascal
w5ujojoe@swbell.net... more >>
Microsoft FTP Server problem on W2K?
Posted by DavidM at 12/12/2003 10:53:57 AM
We have a mainframe at work that FTPs file to a Microsoft W2K FTP server
using SP4. Since the mainframe appears to be bogged down at times and
doesn't seem to respond to FTP requests on its server nor respond quickly
enough when it sends files out, I made a request to have all outgoing FTP
file... more >>
"we have been hacked"
Posted by RLF at 12/12/2003 10:53:50 AM
Our web home page (tools<internet options<general<
homepage)seems to be hijacked, or as the information on
the page we are directed to suggests (see below) "we have
been hacked".
My question: is the info below legitimate? Can we or
should we follow the instructions it provides to rid ou... more >>
Send form information via e-mail
Posted by Alan at 12/12/2003 9:21:24 AM
My smtp server requires a log on. When I configure a
website with my smtp information then try and fill out a
form on my web site it says that it can't send it because
it requires a log on, but there is no where in the 2002
extension set to provide this information. Here is the
error I a... more >>
IIS 6.0 IISADMPWD help
Posted by Greg at 12/12/2003 9:21:24 AM
I'm trying to configure IISADMPWD within IIS 6.0 with no
luck.
I have created an virtual directory to
C:windows\systems...iisadmpwd.
When I browse I get this error:
The page cannot be found
HTTP Error 404 - File or directory not found.
Internet Information Services (IIS)
I'm using ... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
cannot publish the *.asp files from the Netscape
Posted by Chris Klapuic at 12/12/2003 3:27:20 AM
Hi
I cannot publish the *.asp files from the Netscape
Composer 7.1 or 4.79, but it works fine if I change the
extension to anything else .htm etc.
Bit on what I am trying to do. At my work place we provide
maintenance support and the procedures are everything to
us, but unfortunately t... more >>
That nice old ISAPI to scramble ASP scripts?
Posted by Alexander Maltsev at 12/11/2003 10:14:58 PM
Hello gents and ladies,
I haven't used this thing for several years and now can't recall its
name. The magic thing I'm talking abot is an ISAPI extention plus an
utility that scramble .ASP sources into unreadable state (i.e. no one
can read the source, say an intruder or a client that wishes t... more >>
IIS Lockdown Wizard
Posted by John at 12/11/2003 10:09:44 PM
Hi
Sorry if this is a repeat, but my news server only stores 200 messages!
The MS Baseline Security Analyser recommends installing the IIS Lockdown
tool, but I have a live webserver with lots of important sites on, and only
accessible by remote admin terminal services. All the site use most... more >>
Windows 2003 (IIS6) security question
Posted by ML.net at 12/11/2003 8:25:37 PM
If you enable (success) auditing for "Audit Logon Events" or "Audit Account
Logon Events" will it log I_User account logon's? Obviously, my concern
would be for a high traffic web server getting an essentail DOS attack
against itself due to a high volume amount of logging in the security logs.
... more >>
IIS Basic Authentication & Windows 98 machine
Posted by Jennifer at 12/11/2003 2:14:45 PM
I just configured Basic Authentication on a few areas of
my web server and it works fine, except for people who
are on a Windows 98 machine. When they try to log in, the
login box keeps reappearing instead of accepting the
user/password info. Did I miss a setting somewhere? What
do I need... more >>
ISAPI Authentication
Posted by Kevin at 12/11/2003 1:00:50 PM
I'm considering writing an ISAPI filter to handle
authentication.
Will it completely replace the configured windows
authentication or will it serve as an extra
authentication step before the windows authentication?
The documentation says that I can return
SF_STATUS_REQ_NEXT_NOTIFICATION ... more >>
HTTP Trace command vulnerability
Posted by GregG at 12/11/2003 10:28:08 AM
I have been notified from my client after a vulnerability
assessment that their web server (on the Exchange 2K
server running OWA) has the "HTTP Trace Commnad" enabled
and that it was a vulnerability. I cannot find any place
to disable this or even very much about it. Anyone know
about t... more >>
URLScan
Posted by rich_legend NO[at]SPAM yahoo.com at 12/11/2003 10:05:04 AM
Hi Guys
Can anyone help with allowing full stops using URLScan the error is
Client at 127.0.0.1: URL contains extension '.', which is not
specifically allowed. Request will be rejected. Site Instance='1',
Raw URL='/TestWeb'
I can not find '.' any where in the urlscan.ini file
This is... more >>
Problems with Administrator users
Posted by Rane Bowen at 12/11/2003 9:51:11 AM
Hi.
I hope that I am posting to the correct group and that someone can provide
me with some clues with a particular problem we are having.
First some background:
Our document management system uses iis with a custom isapi filter. The
user (after authenticating via ntlm) is presented with a... more >>
URLScan Config for Internet Synchronization
Posted by Martin Cline at 12/11/2003 9:28:44 AM
I have a box running WinXP/IIS setup to run an Access database with internet
synchronization. The box was hacked by W32.Spybot.Worm. I do have URLScan
2.5 enabled, but .exe extensions need to be allowed for the internet
synchronization to work. Is there anyway to deny all .exe extensions except... more >>
IIS, Basic authentication, Default domains, and Session
Posted by craig_j_dawson NO[at]SPAM hotmail.com at 12/11/2003 8:01:37 AM
I have two ASP web pages running on IIS 5. Both are configured to
require basic authentication. Page1 has a default domain of domain1
for authentication purposes. Page2 has a default domain of domain2.
When a user access page1, they must provide credentials in the logon
dialog:
username: user... more >>
Login into OWA
Posted by eddie at 12/11/2003 7:50:24 AM
When my users try to log into the OWA to check their email
from the WEB they continue to get asked their username and
password. They enter the correct information but they are
never logged in to view their email. I have to turn on
the windows intergrated logon in order for them to see
th... more >>
Secured sight
Posted by Joe Kaz at 12/11/2003 6:47:52 AM
I want to block one specific sight, and I can do that, but
it also blocks my home page for Yahoo. I even added yahoo
as a sight to alway be viewed. What can I do?... more >>
Cannot access Secure Sites
Posted by Susan at 12/11/2003 6:46:07 AM
Cannot access secure sites -- keep getting 'page not
available' message.... more >>
basic question - intranet/internet
Posted by KJ at 12/11/2003 6:01:20 AM
I'm new to the networking end of things.
What is involved in making an intranet webapp available
to the internet?
And what is involved in making an internet webapp an
intranet app only?
When making a intranet webapp available to the internet,
what kind of hardware changes are needed? I ass... more >>
Granting IP Addresses in IIS
Posted by skc at 12/11/2003 1:28:24 AM
Running Windows 2000 Server. I need to grant IP addresses
from our client, as their IP addresses have changed. The
client now has a IP range, and quite a few of them - I
need help on how to enter them into the Granted list:
E.g.
Scope [x.x.x.0] Site_Name - x.x.x.10 - x.x.x.129
Scop... more >>
Safari can't handle non-anonymous type schemes
Posted by Chris F at 12/11/2003 12:09:55 AM
OK, I have a site in IIS 6.0 that I removed the anonymous access to for now.
I just don't want the general public looking at the site while it's under
development, not even a splash page. So, I took the anonymous access off
(via the properties window), which in turn, removed IUSR_SERVER from the
... more >>
HTTP Error 403.15
Posted by RTML at 12/10/2003 11:48:33 PM
Hi,
I am having error 403.15 when multiple users try to call
the website.
Configuration:
-User authentication via ADSI (different Server with the
WebServer)
-Upon authenticated, the default page will be called from
the WebServer
Checking from Microsoft website, this error is related to ... more >>
IIS Isolation Mode
Posted by Amol Naik at 12/10/2003 8:56:08 PM
HI,
We have been building an application for IIS 5.0. But now we want to move to IIS 6.0. We tried to install using the same scripts that we had used for IIS 5.0. It seems to install fine.
There were some changes in the scripts that we have done .. like the virtual directory getting created... more >>
IIS5, FTP from behind router?
Posted by Rob Mayo at 12/10/2003 6:45:57 PM
I have a cable (broadband) for an ISP. I have a Linksys cable modem that
gets an IP automatically from my ISP (xxx.xxx.xxx.xxx) and sends it to my
Linksys Wireless router. Behind the router, I have 2 pcs. Both are Windows
2000 Professional, IIS5, with ftp installed. They both get their IP
addres... more >>
Security for delegation in a domain
Posted by Sven at 12/10/2003 1:21:08 PM
I want to create an object on a web server running windows 2003(IIS6)in a domain from an ActiveX-DLL(prnadmin.dll) from the Resource Kit, which lists the shared printers on a third server. It works properly under NT4 an Windows 2000 Servers. If I want to list the printers on a Windows 2003 Server it... more >>
Error Processing a Renewed Certificate
Posted by ccn NO[at]SPAM tpgl.com at 12/10/2003 12:48:03 PM
Hello All,
I have been searching everywhere for some leads on the following
error:
We have a stand-alone Windows 2000 CA. We are using SSL for OWA. The
certificate we created in 2002 has expired. I am trying to renew the
certificate but I keep getting the following error:
Your reques... more >>
MInimum priviledges required for Managing IIS
Posted by neverknow at 12/10/2003 7:18:28 AM
Hi,
I am looking to give developers enough priviledges to
manage their IIS, doing routine tasks as creating
virtuals, setting authentication parameters etc, without
giving them local ADmini rights on the workstation. Can
this be done ? If yes, how ?
Also, I want them to be able to debu... more >>
security
Posted by Hasnain at 12/10/2003 1:24:52 AM
I want password of
nazimali780171@hotmail.com... more >>
homepage
Posted by george at 12/9/2003 9:44:47 PM
frequently, my home page is changed to "www.cool-
search.net" without my permission. is this a virus /
worm. how can i get this out so i dont have to keep
going to "internet options" to change it back.
anyone?... more >>
Windows 2003 Small Business Server & IIS Security
Posted by Robert Waite at 12/9/2003 9:31:39 PM
David Wang on 12/03/03 in this forum gave an excellent blueprint on securing
IIS 6.0 in Windows 2003 Small Business Server (SBS). He, and others, said it
is a bad idea to idea to host Public Web Sites on SBS.
So my question is: What would be the network
configuration/settings/blueprint for hav... more >>
Integrated windows authentication won't work
Posted by David Gagné at 12/9/2003 9:25:17 PM
Hi,
I'm running windows 2000 server. I have an IIS web site with Anonymous
access that works fine. I want to set the security to "Integrated Windows
authentication" for one folder inside this web site. When I clear the "Allow
Anonymous" and check the "Integrated Windows authentication" box, for ... more >>
SSL Wildcard Certificate Replacement
Posted by Steve at 12/9/2003 8:09:45 PM
I have 2 web sites for a single domain. One is for my
www site and the other is for all other subdomains. I
initially installed a SSL certificate for the www site
and it expires on 12/12. I purchased a 1 year wildcard
certificate to cover the www and all other subdomains. I
installed t... more >>
Internet Connection Firewall with Multiple IP's for IIS
Posted by Tom at 12/9/2003 4:12:04 PM
When I switch on the Internet Connection Firewall, it
will only allow port 80 access to IIS on ONE IP address.
How can I allow access to the other WebSites that are
configured with different IP addresses (on the same
network adapter) ?
I start to think that it is not possible to use multipl... more >>
anonymous password
Posted by peter at 12/9/2003 10:34:02 AM
does anybody know wath this means:
The registry key for IIS subauthenticator is not
configured correctly on local machine, the anonymous
password sync feature is disabled.
i cant find anything of it on support.microsoft.com or
eventid.net
thanks
peter ... more >>
IIS Stops responding
Posted by Hector Bonilla at 12/9/2003 8:55:22 AM
Dear Microsoft People,
The server we have is running an application that uses
IIS, at some time IIS stops responding unexpectedly and
returns to the user a violation access and IIS gets down,
is not a big issue, as I restart IIS manually and the
dialogue between client and server restarts... more >>
Domain Authentication
Posted by Patriot at 12/9/2003 8:17:11 AM
I have created a virtual directory and used VB.NET and ASP.NET for my web
app and it works great. My question is; can I secure this application to
where only domain admins can open the site? Thank you...
... more >>
SSL and certificates
Posted by Kevin at 12/9/2003 6:30:00 AM
Are client certificates necessary for SSL or just server
certificates?
The Microsoft help for setting up SSL takes you through
creating a server root certificate and another server
certificate and then installing each on all of the
clients. But other documentation that I have read
sugg... more >>
SSL & non-secure items
Posted by Gareth James at 12/9/2003 1:37:14 AM
Hi,
I have setup a website running via IIS that is secured via
SSL. When I try to access the page, a dialog window
appears saying that there are secure and non-secure items
on the page and whether I want to display the non-secure
items. The question is that when I click on No, the
padlo... more >>
Integrated Windows authentication
Posted by ms90933 at 12/8/2003 11:51:46 PM
I used the "Integrated Windows authentication" on IIS 5.0
But when I use IE to connect the IIS, still get a dialog
for password. Why ?
Any advise will be appricated... more >>
Secure IIS FTP
Posted by Jason Lee at 12/8/2003 11:19:23 PM
Does anyone know of a (preferably free) product that
provides secure ftp ability for IIS FTP? Something similar
to SafeTP <http://safetp.cs.berkeley.edu/>. I would use
SafeTP but the client doesn't work on Windows XP, I'm not
sure about its 2003 Server compatibilty, and there are
publized ... more >>
unauthorized default browser
Posted by Alice at 12/8/2003 6:54:07 PM
I have an unauthorized default browser on my internet
explorer, all attempts to get rid of it have failed.
HELP... more >>
site asks for user name/pw for anonymous login
Posted by Gilbert at 12/8/2003 3:52:54 PM
I'm running IIS 5.1 and when I try to get to the site by
using the IP address and I click on a specific link
(which points to a .htm file) it brings up an
authentication menu. I checked the ACL and the file has
the same security attributes as all the other files. It
didn't do this before... more >>
IIS 5.1 and FTP access errors
Posted by Ken Torri at 12/8/2003 2:21:22 PM
I have IIS 5.1 and FTP services active on a Windows XP
Professional system. I am getting "FTP Folder Errors"
when trying to access an FTP folder through a firewall.
Access works fine via local lan using "localhost" or lan
computername as the host name. Port 21 is opened up on my
firewall... more >>
Redirect to SSL for entire ASP.NET application
Posted by Stephen Walch at 12/8/2003 12:33:06 PM
I wish to enforce SSL for an entire ASP.NET application (including the
custom authentication page and all other pages). To achieve this, I am
using the "Require SSL" on the Virtual Directory in IIS. This works, but
when users hit the non-SSL version of the page (http:/...) they get an ugly
err... more >>
Security
Posted by Rex at 12/8/2003 9:36:09 AM
I am having trouble with securing my web site. It is a
Corporate web and I need to know how to stop someone from
editing it in front page. If I turn off authoring that
stops that but I have .XLS spread sheets that need to be
able to be saved and with authoring off I can't. I have
tried all... more >>
Unauthorized / Service Unavailable ??
Posted by Barry Fitzgerald at 12/8/2003 7:15:39 AM
I have a new web server (win2003) that is part of a new domain (win2003)
that was just set up a couple of weeks ago. Everything except the web
server seems to be acting properly. There is a default.htm page set up on
the default web site and also a .NET app in a virtual directory. The site
wo... more >>
authentication/login scheme
Posted by Kevin at 12/8/2003 6:41:09 AM
I am a developer, not an administrator and want to ask
you guys for advice on designing a login/authentication
scheme for a new .Net C# product.
-The product will run on customers' intranets. (The
website may be accessed remotely but we are not ruling
out forcing them to go through a VPN... more >>
|