Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > july 2003

Filter by week: 1 2 3 4 5

Delegation of IIS administration
Posted by Ash Dey at 7/31/2003 11:23:01 PM
Is there any way, I can create a windows security group and then delegate to manage the IIS admin without giving the complete server administration right? I am aware that, the IIS oprator group is unable to create virtual directory i.e. by design. I want the security group members shoul...more >>


Script access - IIS 6
Posted by Mark Hildreth at 7/31/2003 10:59:19 PM
I am trying to execute a python script on IIS 6 as follows: Anonymous access http://cvstest/viewcvs and http://cvstest/viewcvs/viewcvs.cgi Both of the above work. I have made viewcvs.cgi a default page for the directory. Authenticated access: Removed anonymous access, added ACL for user gr...more >>

How do You access data from IIS on another server
Posted by Dermott Renner at 7/31/2003 4:24:30 PM
IUSR_Computername gives users anonymous access to the web site. What gives IIS or the IIS service or ASP pages on the web server the access to say FoxPro or Access data on another server (files are not SQL Server so not interested in how SQL does it) Thanks Dermott...more >>

Strange W3svc log entries
Posted by Frank at 7/31/2003 3:24:12 PM
Hello all, I am getting very strange log entries on one of my web servers they look like this Get, /Default.ida,xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx Does anyone know what could be causing this. IS it a virus or a sign of intrusion? Tha...more >>

URL Scan on OWA
Posted by Björn Johansson at 7/31/2003 11:28:41 AM
Hello, I've set up a OWA (front end) on our DMZ. The recommended template for OWA is used on URLScan. The problem is that it blocks URLs containing "&" and ".." signs. This is very disturbing for our users because many emails contains .. and "&" and ".." signs in subject line. Is there a...more >>

HTTP TRACE Support
Posted by Richard at 7/31/2003 9:11:21 AM
I have an issue with "HTTP Trace Support" being enabled. I have found documents that state "Use URL Scan" to fix the problem. I do not want to use URL Scan due to the fact that it caused more problems then it fixed. I keep running into the refrence of "RFC 2516" regarding "HTTP Trace Suppo...more >>

Frontpage search feature do not work after installing URLSCAN
Posted by STL at 7/31/2003 1:00:48 AM
I have just install URLSCAN in my win2k server. I have used the frontpage website search component in my website. This component uses the indexing service. When I tried to access the page http://testsvr/myweb/v4static/searchlt.idq I get this error msg: HTTP 401.3 - Access denied by ACL on r...more >>

Pornographic Pop-Ups
Posted by Dianna Miller at 7/30/2003 9:06:56 PM
Please!!!! Can some one help me stop these pornographic pop-ups from plastering my screen 4, 6, 8, or more at a time? I have young children and there is no excuse for them to have to see these uncontrolable pictures that just come up out of no where. One picture is bad enough, but I can...more >>



Correct Domain User/Pass/Domain credentials rejected
Posted by - at 7/30/2003 6:27:09 PM
Hello, I have several clients of two web based systems who are being prompted with a popup for their name and password for a website. This is fine since it was configured in this way. The problem is that they (and on some machines myself) put in the proper credentials Username - Password - D...more >>

Cannot generate CSR for Gibraltar region using IIS. Alternative CSR generating mechanisms?
Posted by JeanValjean at 7/30/2003 6:05:29 PM
HI I am trying to generate a CSR for a server to be hosted in Gibraltar. If I try to generate a certificate signing request using IIS5, I find that in the field for specifying the Country/Area code there is no entry for Gibraltar (GI). It is only possible to add a area code from this list. ...more >>

Trying to Get SSL and IIS to work using Microsoft CA
Posted by Keven at 7/30/2003 2:24:56 PM
Please help me to get SSL to work on a standalone PC (Non Domain). I created a web page using CGI that does file upload. I wanted to make this secure so that names and passwords are not sent in the clear. I installed Certificate server locally on the box. I went into IIS and said use ...more >>

Strange 401.1 Errors
Posted by NetAdmin NO[at]SPAM liginsurance.com at 7/30/2003 2:01:43 PM
I am trying to have users use their standard windows login information to login to a website. However, For certain members I get a 401.1 error page. It seems to be linked to the user because it happens because of the user logged on to the computer. As in, if I put in an administrative usernam...more >>

IIS 6.0 Default Security...
Posted by Ben Millspaugh at 7/30/2003 12:53:24 PM
I have used IIS for years and am in the process of moving my websites to IIS 6.0 (new servers, not upgrades). I would like to lock down the security, but I don't want to lock it down so much that the system can no longer process the files. I also see that Windows Server 2003 & IIS 6.0 ad...more >>

Bogus or real?
Posted by Louis Davidson at 7/30/2003 10:25:53 AM
Microsoft Customer this is the latest version of security update, the "July 2003, Cumulative Patch" update which eliminates all known security vulnerabilities affecting Internet Explorer, Outlook and Outlook Express as well as five newly=20 discovered vulnerabilities. Install now to pr...more >>

Hacking into firewall
Posted by Ajitesh Pathak at 7/30/2003 5:43:41 AM
Hi There, How can I hack the security in the office and try and access the sites which we are denied access into?? Ajitesh...more >>

MSPOP-UP MESSAGE SERVICE <KILLER POP-UPS>
Posted by Moses and Elija at 7/30/2003 2:16:33 AM
*******GREETINGS************** We are writing to tell you about the problems of "Abuse" with their Message Service> I didn't mind before or when I first started recieve these messages because I didn't know what it was. I didn't know what popup message was.. but gave me message of: Your comp...more >>

RPC/DCOM Worm Released
Posted by paul_lynch67 NO[at]SPAM hotmail.com at 7/30/2003 2:09:24 AM
Hello, This is a quick heads-up to let you know that there have been 'sightings' of a new worm which seeks to exploit the latest vulnerability in all versions of Windows. More details here : http://grc.com/default.htm http://vil.nai.com/vil/content/v_100516.htm Patch available here : ...more >>

Browser Warning Message
Posted by Itopa at 7/30/2003 2:01:25 AM
I have install the certificate on my certificate server and enabled the ssl port. Now when i access my webpages, the browser gives me warning that the CA is not the one trusted by my browser Yes or No if I would like to go ahead. What can i do to suppress this message from coming up on ...more >>

Passing credentials
Posted by Kumarajothi C at 7/30/2003 1:16:15 AM
Hi, I have two web sites (site A and Site B) on the same IIS server. Site B is set with 'Basic Authentication' mode. Site A doesnt have basic authentication enable. From site A I programmatically get the user name and password to validate the user and redirect the user to Site B. Her...more >>

Installing SSL on a web site
Posted by keven at 7/29/2003 4:36:34 PM
Hello. I installed a local CA on my web site using the Microsoft ca server. This is a stand alone box. I then had it apply the ca certificate from the local server. I can view the certificate. The problem is if I enable require ssl then try to https: the web page i get page can't be v...more >>

URL SCan still having issues ...
Posted by Todd at 7/29/2003 1:22:45 PM
Hey everyone, Thanks for all your support but, I did what some of you told me and edited my urlscn.ini and IIS still loges the rejected requests, it dosn't log like the whole string but it does still log them, Is there anyway to make it so IIS will not log any rejected requests that urlSCa...more >>

User NT Authentication
Posted by Guy Peay at 7/29/2003 11:31:34 AM
Hello I am an ASP developer working on NT 4.0 platform with IIS 4.0 server. I am trying to do security from the brower by calling the "GetTokenInformation" to get the NT authentication token to ensure that the user has logged in. My question is is this possible through scripting (javas...more >>

IIS 5.0 Cumulative Patches
Posted by Barry Hastings at 7/29/2003 10:33:05 AM
We have just installed Windows 2000 Server and IIS 5.0 for a new web server. I noticed in checking for security patches that there are two for IIS that are called "cumulative", Q301625 from MS01-044, and Q811114, from MS03-018. Do I need to install the earlier one first, or does the one ...more >>

Programmatically ban IPs within IIS 5.0 and W2k
Posted by Scott at 7/29/2003 10:03:23 AM
Does anyone know how to programmtically ban IPs within IIS 5.0 and W2k? I have a process that parsers my IIS logs looking for malicious activity. I want to be able to programmtically add the IP address of the malicious requestor to the denied/blocked list. Thanks......more >>

Possible permission Issue
Posted by Tony at 7/29/2003 9:30:14 AM
I have a user that is using a program called Cinderella to generate java pages. The server that we use is IIS 6 with FPSE. This is the error message that I receive when I look at the java console: java.io.FileNotFoundException: http://www.optics.arizona.edu/jcwyant/Geometry/Optics.cdy jav...more >>

security/access question
Posted by Chris at 7/29/2003 9:24:41 AM
I have a bunch of IPs that are denied access to my server. For the most part it works but..... there are one or two IPs that are still able to have access to my system. I've double checked the logs and then reentered them in the denied list but they still are being allowed access. This is a win...more >>

DNS server & Intranet site renaming
Posted by BijuThomas at 7/29/2003 1:20:03 AM
I have asked a query to this group some time back. With the help of this group I am able to solve the problem partially. can any one help me in solving this problem. My Question & Steps taken is given below. My Question was---------------I am hosting a intranet server on a windows 2000 se...more >>

Problem with authentication
Posted by Marlene A. Roman at 7/28/2003 7:45:09 PM
I have a Web Application(written using Visual Interdev) installed on Windows 2000 Advanced Server. The application is set up to use Integrated Windows Authentication ONLY, and I'm also accesing a SQL Server Database installed in the same computer. I have an entry(MYWEBAPP) on the DSN SERVER poin...more >>

How can I set "remote_user" in ISAPI filter/Extension?
Posted by lqqchen at 7/28/2003 4:04:50 PM
Dear All, Our application need to modify the "remote_user" in an ISAPI filter/Extension for IIS. Our findings are: 1. IIS doesn't allow any modification on the "remote_user" field directly. 2. We learned from newsgroup discussions that by setting HTTP_AUTHORIZATION header ...more >>

CGI Script permissions
Posted by Mike Garner at 7/28/2003 3:51:57 PM
I've been tasked with the job of migrating an iPlanet Web Server to IIS 6.0. I wrote nearly all of the CGI on the server so I've got a pretty good handle on what its trying to do. There are several scripts that provide web- based utilities, to read directories, set permissions, etc. within...more >>

content advisor
Posted by sheila at 7/28/2003 1:53:02 PM
need help!! while online someone accessed by computer and changed the settings. They activated the content advisor and added a password, I can only get on the net via netscape and I am seeking a fix for my Internet explorer...more >>

Additional http Requests for Deafult Home Page
Posted by Betty Chan at 7/28/2003 1:37:17 PM
Hi Everybody, I administrator a intranet web site. I found that there are IE 6 (on Windows 98 or 2000) that sending out extra requests for default home page. These extra requests are transparent to the users, but seen on the IIS log. e.g. 14:41:31 xxx.20.135.181 - GET /queries/loginDlog.cfm ...more >>

ASP ERROR: error '8002801d' -> Library not registered. : my Active Server Pages are not so active.
Posted by pottercarl NO[at]SPAM hotmail.com at 7/28/2003 1:07:31 PM
I've got two IIS servers. One public and one staging. On the public server the ASP code works fine however on the staging server I've started getting this error recently: error '8002801d' Library not registered. /default.asp, line 4 There is nothing in the code to indicate what the ...more >>

restricting intranet access
Posted by Bobby at 7/28/2003 10:55:25 AM
I'm running IIS5 on Win2000 server, and I'm attempting to internally restrict access to a particular intranet site using internal domain names. I've set the IP Address Restrictions to "Deny Access" and populated the list with domain names that I want to access the site, but all my users (...more >>

FTP and passive FTP port ranges
Posted by Steve at 7/28/2003 10:42:13 AM
Is it possible, via some registry key or something, to give IIS a range of assignable ports when the FTP client sets the FTP session to be passive. I'd setting up some stateless packet filters for a server and would prefer to not allow incoming connections from the entire unassigned port ...more >>

Integrated Windows Authentication with Separate Server
Posted by howard at 7/28/2003 8:39:42 AM
Is there a way to configure ASP.NET with IIS on one server and SQL on another server, using Integrated Windows Authentication, without using Impersonation, and not embedding any passwords in config files or anywhere else on the systems? It runs out of the box this way with IIS and SQL on ...more >>

IE Security Information warning at email login
Posted by Daniel at 7/28/2003 6:56:36 AM
When I try to log in to access my Comcast email, I get an IE Security Information box that says "This page contains both secure and nonsecure items. Do you want to display the nonsecure items?" I then have to log in manually each time, because automatic signin seems to have got disabled at...more >>

Disabling Port 135
Posted by Budi at 7/28/2003 2:38:25 AM
how to disable port 135 please... step by step guidance? thank you....more >>

Disclosing Internal IP Address
Posted by Rudianto at 7/28/2003 2:18:31 AM
Hi all: I wanted to disclose my internal IP address. I cant find article Q218180 any help for me. How do I do it if I have the following scenario. I have changed and renamed my default Inetpub directory to E:\Proview\. Also, I have deleted the particular file needed, i.e. adminscrip...more >>

IIS Web Server security
Posted by hanno at 7/27/2003 11:58:47 AM
Hi all, Does anyone knows if i will be able to strengthen my internet security if i add an iis web server on top of my existing iis web server where my applications resides?? Thanks. Pls give me some url references if possible....more >>

agravating popups with no close option
Posted by Terry S. at 7/27/2003 11:16:56 AM
While surfing i often am confronted with ads that monopolize the entire window with no way to close them and continue my activity. What in the world can I do to stop this. Also is there a cost free safe way to eliminate the "message alert popups that appear continuously on my screen in mul...more >>

SSL on intranet
Posted by dspent at 7/27/2003 2:22:34 AM
Hello all... How do I issue/configure and install my own SSL Certificate in .Net server for use with my intranet.... Basically I use this server as a testing server for my web development projects and am developing an application that will require SSL.....so there is no reason to purchase a...more >>

mn100 router file sharing on icq
Posted by michael at 7/27/2003 1:29:19 AM
how do i configure the prots on the router to allow file transfer on icq? the user on the other side is not in a network. ...more >>

Integrated Authentication using Kerberos with Fallback to Basic Authentication
Posted by Eric Chamberlain at 7/26/2003 10:49:25 AM
Is there a way to configure IIS 6 to first try Integrated Authentication via Kerberos only and if that fails, to fall back to basic authentication? I have some applications that need Kerberos proxy and fail if NTLM is used. -- Eric Chamberlain, CISSP ...more >>

desperately need help
Posted by rosa jimenez at 7/25/2003 10:55:32 PM
Hello there, I desperately need help here.I cannot enter to my mail, any of them(yahoo 'n hotmail).The servers continue telling me that my "cookies" are disable.I found out what cookies were, but, actually, I don't really care.I just want to know how to enable them and get into my mail!!!!...more >>

IIS security (allow iis to control password) problem.
Posted by wahoo at 7/25/2003 6:42:47 PM
I created a new IUSR_person with a password. I have anonymous access checked & I enter the IUSR_person password. I need to have [allow IIS to control password] unchecked. But when I do, I get the login prompt on the website. Why do I get the login prompt? ...more >>

passwords
Posted by don waggoner at 7/25/2003 5:14:18 PM
anyone know how to change your password on outlook express...more >>

SSL Help
Posted by Sean at 7/25/2003 3:57:50 PM
My SSL stopped working and I have received the following error. The SSL server credential's certificate does not have a private key information property attached to it. This most often occurs when a certificate is backed up incorrectly and then later restored. This message can also indicat...more >>

FTP Anonymous Authentication
Posted by Rob Wilson at 7/25/2003 12:01:09 PM
I have a PC that has tons of junk on it from people FTP-ing into it. So = of the directories cant be deleted. How can I get ride of those directorie= s to clean up the PC. I have already disabled anonymous authentication....more >>

IIS Won't Start
Posted by Kenny at 7/25/2003 11:41:43 AM
Can someone please explain to me why I can get every other win2k machines IIS started on my win2k network but, the primary domain controllers IIS won't! I would appreciate any feed back on this! Kenny...more >>


DevelopmentNow Blog