all groups > iis security > july 2003 > threads for july 22 - 28, 2003
Filter by week: 1 2 3 4 5
Problem with authentication
Posted by Marlene A. Roman at 7/28/2003 7:45:09 PM
I have a Web Application(written using Visual Interdev) installed on Windows
2000 Advanced Server. The application is set up to use Integrated Windows
Authentication ONLY, and I'm also accesing a SQL Server Database installed
in the same computer. I have an entry(MYWEBAPP) on the DSN SERVER poin... more >>
How can I set "remote_user" in ISAPI filter/Extension?
Posted by lqqchen at 7/28/2003 4:04:50 PM
Dear All,
Our application need to modify the "remote_user" in an ISAPI
filter/Extension for IIS.
Our findings are:
1. IIS doesn't allow any modification on the "remote_user" field
directly.
2. We learned from newsgroup discussions that by setting
HTTP_AUTHORIZATION header ... more >>
CGI Script permissions
Posted by Mike Garner at 7/28/2003 3:51:57 PM
I've been tasked with the job of migrating an iPlanet Web
Server to IIS 6.0. I wrote nearly all of the CGI on the
server so I've got a pretty good handle on what its
trying to do. There are several scripts that provide web-
based utilities, to read directories, set permissions,
etc. within... more >>
content advisor
Posted by sheila at 7/28/2003 1:53:02 PM
need help!!
while online someone accessed by computer and changed the
settings. They activated the content advisor and added a
password, I can only get on the net via netscape and I am
seeking a fix for my Internet explorer... more >>
Additional http Requests for Deafult Home Page
Posted by Betty Chan at 7/28/2003 1:37:17 PM
Hi Everybody,
I administrator a intranet web site. I found that there
are IE 6 (on Windows 98 or 2000) that sending out extra
requests for default home page. These extra requests are
transparent to the users, but seen on the IIS log. e.g.
14:41:31 xxx.20.135.181 - GET /queries/loginDlog.cfm ... more >>
ASP ERROR: error '8002801d' -> Library not registered. : my Active Server Pages are not so active.
Posted by pottercarl NO[at]SPAM hotmail.com at 7/28/2003 1:07:31 PM
I've got two IIS servers. One public and one staging. On the public
server the ASP code works fine however on the staging server I've
started getting this error recently:
error '8002801d'
Library not registered.
/default.asp, line 4
There is nothing in the code to indicate what the ... more >>
restricting intranet access
Posted by Bobby at 7/28/2003 10:55:25 AM
I'm running IIS5 on Win2000 server, and I'm attempting to
internally restrict access to a particular intranet site
using internal domain names.
I've set the IP Address Restrictions to "Deny Access" and
populated the list with domain names that I want to access
the site, but all my users (... more >>
FTP and passive FTP port ranges
Posted by Steve at 7/28/2003 10:42:13 AM
Is it possible, via some registry key or something, to
give IIS a range of assignable ports when the FTP client
sets the FTP session to be passive.
I'd setting up some stateless packet filters for a server
and would prefer to not allow incoming connections from
the entire unassigned port ... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Integrated Windows Authentication with Separate Server
Posted by howard at 7/28/2003 8:39:42 AM
Is there a way to configure ASP.NET with IIS on one server
and SQL on another server, using Integrated Windows
Authentication, without using Impersonation, and not
embedding any passwords in config files or anywhere
else on the systems?
It runs out of the box this way with IIS and SQL on ... more >>
IE Security Information warning at email login
Posted by Daniel at 7/28/2003 6:56:36 AM
When I try to log in to access my Comcast email, I get an
IE Security Information box that says "This page contains
both secure and nonsecure items. Do you want to display
the nonsecure items?" I then have to log in manually each
time, because automatic signin seems to have got disabled
at... more >>
Disabling Port 135
Posted by Budi at 7/28/2003 2:38:25 AM
how to disable port 135 please... step by step guidance?
thank you.... more >>
Disclosing Internal IP Address
Posted by Rudianto at 7/28/2003 2:18:31 AM
Hi all:
I wanted to disclose my internal IP address. I cant find
article Q218180 any help for me.
How do I do it if I have the following scenario.
I have changed and renamed my default Inetpub directory to
E:\Proview\.
Also, I have deleted the particular file needed, i.e.
adminscrip... more >>
IIS Web Server security
Posted by hanno at 7/27/2003 11:58:47 AM
Hi all,
Does anyone knows if i will be able to strengthen my
internet security if i add an iis web server on top of my
existing iis web server where my applications resides??
Thanks.
Pls give me some url references if possible.... more >>
agravating popups with no close option
Posted by Terry S. at 7/27/2003 11:16:56 AM
While surfing i often am confronted with ads that
monopolize the entire window with no way to close them
and continue my activity. What in the world can I do to
stop this. Also is there a cost free safe way to
eliminate the "message alert popups that appear
continuously on my screen in mul... more >>
SSL on intranet
Posted by dspent at 7/27/2003 2:22:34 AM
Hello all...
How do I issue/configure and install my own SSL Certificate in .Net server
for use with my intranet....
Basically I use this server as a testing server for my web development
projects and am developing an application that will
require SSL.....so there is no reason to purchase a... more >>
mn100 router file sharing on icq
Posted by michael at 7/27/2003 1:29:19 AM
how do i configure the prots on the router to allow file
transfer on icq? the user on the other side is not in a
network. ... more >>
Integrated Authentication using Kerberos with Fallback to Basic Authentication
Posted by Eric Chamberlain at 7/26/2003 10:49:25 AM
Is there a way to configure IIS 6 to first try Integrated Authentication via
Kerberos only and if that fails, to fall back to basic authentication? I
have some applications that need Kerberos proxy and fail if NTLM is used.
--
Eric Chamberlain, CISSP
... more >>
desperately need help
Posted by rosa jimenez at 7/25/2003 10:55:32 PM
Hello there, I desperately need help here.I cannot enter
to my mail, any of them(yahoo 'n hotmail).The servers
continue telling me that my "cookies" are disable.I found
out what cookies were, but, actually, I don't really
care.I just want to know how to enable them and get into
my mail!!!!... more >>
IIS security (allow iis to control password) problem.
Posted by wahoo at 7/25/2003 6:42:47 PM
I created a new IUSR_person with a password.
I have anonymous access checked & I enter the IUSR_person password.
I need to have [allow IIS to control password] unchecked.
But when I do, I get the login prompt on the website.
Why do I get the login prompt?
... more >>
passwords
Posted by don waggoner at 7/25/2003 5:14:18 PM
anyone know how to change your password on outlook express... more >>
SSL Help
Posted by Sean at 7/25/2003 3:57:50 PM
My SSL stopped working and I have received the following
error.
The SSL server credential's certificate does not have a
private key information property attached to it. This most
often occurs when a certificate is backed up incorrectly
and then later restored. This message can also indicat... more >>
FTP Anonymous Authentication
Posted by Rob Wilson at 7/25/2003 12:01:09 PM
I have a PC that has tons of junk on it from people FTP-ing into it. So =
of the directories cant be deleted. How can I get ride of those directorie=
s to clean up the PC. I have already disabled anonymous authentication.... more >>
IIS Won't Start
Posted by Kenny at 7/25/2003 11:41:43 AM
Can someone please explain to me why I can get every other
win2k machines IIS started on my win2k network but, the
primary domain controllers IIS won't! I would appreciate
any feed back on this!
Kenny... more >>
Blocking pornography
Posted by Janet at 7/25/2003 11:23:49 AM
Need help on how to stop pornography from poping up on the
pc. I can't even let my kids use the computer. I have
Internet Explorer 6 for windows 98.... more >>
Update existing security certificate
Posted by Tom at 7/25/2003 9:19:25 AM
I need to get a new Security Certificate for a web server.
The info in the existing cert is out of date and the only
options are to 'renew' and 'remove' the cert. Can I create
a certreq on a DIFFERENT IIS server, then replace the the
existing one? Any info would be greatly appreciated.
To... more >>
Help me
Posted by Dhiraj at 7/25/2003 9:08:06 AM
Somebody hacked my password.. and my mailing ID is
rani_puja@hotmail.com
so please help me.. and i can give u necessary
information you guys want regarding this ID... more >>
Microsoft Messenger
Posted by Jamie at 7/25/2003 9:01:54 AM
Does anyone know how to turn off the Messenger service
that allows all the pop-ups?... more >>
Urgent solution needed please
Posted by khan at 7/25/2003 8:24:56 AM
I am running exchange 5.5 on windows 2000 member server
with all the latest service packs and updates.
I installed the Outlook web access (OWA) on the same
server for the internet users to get their emails.
Now since I changed the local administrator password and
restarting the server I coul... more >>
Messanger Spam
Posted by kyo at 7/25/2003 7:42:31 AM
Hi,
I think some people face this problem same as me. When i
connect to Internet, after every 15-20 minutes, a small
window appear with some adverts.Here is a sample of the
advert
"Hi, I'm janita and looking for a boy........."
I want to know that how to get rid of it and is anyone ... more >>
IIS/RPC causes account lock out.
Posted by doug at 7/25/2003 6:39:31 AM
I am seeing select users experiencing account lockouts
when running the IIS service on our active directory
network, any body seen this?... more >>
problems with internet explorer
Posted by Mancini at 7/25/2003 2:34:33 AM
When you open the history to internet explorer it says
that yesterday that I went to all of these -adult-
websites. Also in the history is all the places I really
did go. How can this happen? As you can imagine this is
creating a huge problem with me. I can't even figure out
how someth... more >>
Login prompt when you "Save As" an Excel document opened in IE
Posted by richard.harris NO[at]SPAM ericsson.com at 7/25/2003 1:21:56 AM
Hi
IIS 5
W2K Server SP4
Excel (office XP)
When users open an Excel file in IE and click "Save As" the web server
prompts for login credentials. A network sniff shows that the
author.dll file is causing the prompt, I would expect this if the user
did not have access to the web page, but m... more >>
Tripled ADO Connections
Posted by googlegroups NO[at]SPAM luveno.com at 7/24/2003 4:57:02 PM
The other day we turned off anonymous access in IIS 5.0 (leaving just
Integrated Security), and the number of ADO connections on our SQL
Server (7.0) tripled, taking out the SQL Server. We use SQL users in
our connection strings.
What happened?
TIA... more >>
Can't create cert request in IIS6
Posted by drreitma NO[at]SPAM iupui.edu at 7/24/2003 3:42:17 PM
Problem:
I have a Windows Server 2003 std. with SQL server 2000 std. I also
have Application Server running (IIS 6.0 w/ ASP.NET). When I try to
create a Certificate request for my website I get all the way though
the wizard up to the point were it gives me the summary. At this point
I click f... more >>
FTP Anonymous Authentication
Posted by Jenna at 7/24/2003 10:36:33 AM
Can anyone tell me the advantages/disadvantages to using
anonymous authentication on an FTP site?... more >>
Tripled ADO Connections
Posted by Ben at 7/24/2003 9:13:20 AM
The other day we turned off anonymous access in IIS 5.0
(leaving just
Integrated Security), and the number of ADO connections on
our SQL
Server (7.0) tripled, taking out the SQL Server. We use
SQL users in
our connection strings.
What happened?
TIA... more >>
IIS 5.0 and CGI scripts....
Posted by Jesse Verdin at 7/23/2003 8:13:31 PM
Hello,
I have a client that has a Web Designer that insists on using
the administrator account within the Authentication method under Directory
Security tab instead of the IUSR~Machine account. I think this is ridiculous
and should be researched more to figure out a different way to... more >>
IIS Admin Server terminated
Posted by zxc at 7/23/2003 8:05:50 PM
IIS Admin Server on WINDOWS 2000 terminated almost every
6 days.And there shows no reason.What can I do for it?... more >>
URLscan + FrontPage + Block HTTP Headers
Posted by FUD_wad at 7/23/2003 2:37:39 PM
I'd like to be able to block or modify the HTTP headers using URLscan 2.5,
it has the capability of removing the default and adding any replacement.
That works fine, however when I do make changes the FP clients (2000 and
2002) no longer recognize the web site as being a valid, FPSE extended si... more >>
Passport auth. not working
Posted by Gordon at 7/23/2003 12:24:48 PM
Hi,
I've configured a virtual directory in IIS 6 on Win Svr
2003 Ent to use passport authentication. I then used the
wizard to associate my passport with my user account.
However, when I access the site, and then enter my
passport credentials at the passport page, I get an error
message... more >>
Securing FTP?
Posted by Keven at 7/23/2003 11:03:34 AM
Is there a way with IIS 5 or Windows 2003 IIS 6 to secure
FTP. I would like to do this with MS products and clients
so I don't have to distribute clients out to end users.
If this won't work is there a way to setup a HTTPS site
for file uploads and downloads for clients? Thanks for
your... more >>
Change Password Error number: -2147023569
Posted by Michael at 7/23/2003 9:49:18 AM
Hello,
I am getting the following error message when a user
tries to change their password.
First attempt to change password is successful.
Second attempt fails: Error number: -2147023569
Have searched MSDN with out success.
Thanks,
Michael
chiefdnd@hotmail.com
... more >>
Server Applicatin Unavailable
Posted by sl at 7/23/2003 6:59:35 AM
We run an applicatin, but we alwags get a page
saying "Server Applicatin Unavailable -- The web
application you are attempting to access on this web
server is currently unavailable. Please hit the "Refresh"
button in your web browser to retry your request.
Administrator Note: An error m... more >>
E-mail tracking
Posted by R diMaio at 7/23/2003 6:55:46 AM
Is there any truth to the program that Microsoft and Aol
are tracking e-mail forwards and paying $250. per 20?
R DiMaio... more >>
MSN Messenger Login Security
Posted by Sherry at 7/23/2003 6:29:40 AM
I downloaded MSN Messenger on my computer and chose to
have it ask me for my password at each login, as I share
the computer with others.
I also signed up for a .net passport, and since then, I
am automatically logged in to Messenger, which accesses
my email messages as well, without having... more >>
IIS services
Posted by jd at 7/23/2003 1:30:26 AM
One question, can IIS service be turn off by itself?
I experiance it today and the application was down. is
there any patch that i need to install to overcome this
problem?
anyway, thank you in advance.
rgds,
-taufik-... more >>
Directory Security
Posted by Michael C. Gates at 7/22/2003 10:49:33 PM
Ok, I thought I had everything set up correctly, but I don't.
1. I am hosting about 50 sites on the same Win 2000 Server Box.
2. Every instance on my server has it's own username with NO rights EXCEPT
their directory which is read/write.
I have to give "Users" rights to winnt\system32 in o... more >>
IIS and netware ...
Posted by Benny Ng at 7/22/2003 5:22:00 PM
Can anyone help me on a IIS on a Netware LAN issue ?
I am not sure which virtual directory authentification mode I should choose.
... more >>
IIS and SSL port
Posted by Justin Martin at 7/22/2003 3:59:51 PM
Hi, I transferred my settings from a production IIS server to a testing
server using IIS Export. The problem that I have is that it also transferred
the settings for my SSL port and IP address - these both point to my
production machine and I need them to point to the testing machine. Is there
a... more >>
Help !!!!!!! , is this an attack ?
Posted by YTS at 7/22/2003 3:34:05 PM
Hi
I got the following on the ?IIS log file
GET /default.ida
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u90... more >>
high security web template
Posted by tzone at 7/22/2003 2:31:16 PM
Would like to know where I can get the hisecweb.ini file
for IIS 5 servers? It's not on any of my servers.
Thanks ... more >>
XP and Norton PFirewall
Posted by Stephen at 7/22/2003 8:05:43 AM
I read that XP has a firewall. I also have installed
Norton Personal Firewall in my system. Can someone advise
me what is the effects when both of these are working. Or
should I disable XP's firewall? Will both programs
running together freeze up the computer?
I have limited knowledge... more >>
|