Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > july 2003 > threads for july 29 - 31, 2003

Filter by week: 1 2 3 4 5

Delegation of IIS administration
Posted by Ash Dey at 7/31/2003 11:23:01 PM
Is there any way, I can create a windows security group and then delegate to manage the IIS admin without giving the complete server administration right? I am aware that, the IIS oprator group is unable to create virtual directory i.e. by design. I want the security group members shoul...more >>


Script access - IIS 6
Posted by Mark Hildreth at 7/31/2003 10:59:19 PM
I am trying to execute a python script on IIS 6 as follows: Anonymous access http://cvstest/viewcvs and http://cvstest/viewcvs/viewcvs.cgi Both of the above work. I have made viewcvs.cgi a default page for the directory. Authenticated access: Removed anonymous access, added ACL for user gr...more >>

How do You access data from IIS on another server
Posted by Dermott Renner at 7/31/2003 4:24:30 PM
IUSR_Computername gives users anonymous access to the web site. What gives IIS or the IIS service or ASP pages on the web server the access to say FoxPro or Access data on another server (files are not SQL Server so not interested in how SQL does it) Thanks Dermott...more >>

Strange W3svc log entries
Posted by Frank at 7/31/2003 3:24:12 PM
Hello all, I am getting very strange log entries on one of my web servers they look like this Get, /Default.ida,xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx Does anyone know what could be causing this. IS it a virus or a sign of intrusion? Tha...more >>

URL Scan on OWA
Posted by Björn Johansson at 7/31/2003 11:28:41 AM
Hello, I've set up a OWA (front end) on our DMZ. The recommended template for OWA is used on URLScan. The problem is that it blocks URLs containing "&" and ".." signs. This is very disturbing for our users because many emails contains .. and "&" and ".." signs in subject line. Is there a...more >>

HTTP TRACE Support
Posted by Richard at 7/31/2003 9:11:21 AM
I have an issue with "HTTP Trace Support" being enabled. I have found documents that state "Use URL Scan" to fix the problem. I do not want to use URL Scan due to the fact that it caused more problems then it fixed. I keep running into the refrence of "RFC 2516" regarding "HTTP Trace Suppo...more >>

Frontpage search feature do not work after installing URLSCAN
Posted by STL at 7/31/2003 1:00:48 AM
I have just install URLSCAN in my win2k server. I have used the frontpage website search component in my website. This component uses the indexing service. When I tried to access the page http://testsvr/myweb/v4static/searchlt.idq I get this error msg: HTTP 401.3 - Access denied by ACL on r...more >>

Pornographic Pop-Ups
Posted by Dianna Miller at 7/30/2003 9:06:56 PM
Please!!!! Can some one help me stop these pornographic pop-ups from plastering my screen 4, 6, 8, or more at a time? I have young children and there is no excuse for them to have to see these uncontrolable pictures that just come up out of no where. One picture is bad enough, but I can...more >>



Correct Domain User/Pass/Domain credentials rejected
Posted by - at 7/30/2003 6:27:09 PM
Hello, I have several clients of two web based systems who are being prompted with a popup for their name and password for a website. This is fine since it was configured in this way. The problem is that they (and on some machines myself) put in the proper credentials Username - Password - D...more >>

Cannot generate CSR for Gibraltar region using IIS. Alternative CSR generating mechanisms?
Posted by JeanValjean at 7/30/2003 6:05:29 PM
HI I am trying to generate a CSR for a server to be hosted in Gibraltar. If I try to generate a certificate signing request using IIS5, I find that in the field for specifying the Country/Area code there is no entry for Gibraltar (GI). It is only possible to add a area code from this list. ...more >>

Trying to Get SSL and IIS to work using Microsoft CA
Posted by Keven at 7/30/2003 2:24:56 PM
Please help me to get SSL to work on a standalone PC (Non Domain). I created a web page using CGI that does file upload. I wanted to make this secure so that names and passwords are not sent in the clear. I installed Certificate server locally on the box. I went into IIS and said use ...more >>

Strange 401.1 Errors
Posted by NetAdmin NO[at]SPAM liginsurance.com at 7/30/2003 2:01:43 PM
I am trying to have users use their standard windows login information to login to a website. However, For certain members I get a 401.1 error page. It seems to be linked to the user because it happens because of the user logged on to the computer. As in, if I put in an administrative usernam...more >>

IIS 6.0 Default Security...
Posted by Ben Millspaugh at 7/30/2003 12:53:24 PM
I have used IIS for years and am in the process of moving my websites to IIS 6.0 (new servers, not upgrades). I would like to lock down the security, but I don't want to lock it down so much that the system can no longer process the files. I also see that Windows Server 2003 & IIS 6.0 ad...more >>

Bogus or real?
Posted by Louis Davidson at 7/30/2003 10:25:53 AM
Microsoft Customer this is the latest version of security update, the "July 2003, Cumulative Patch" update which eliminates all known security vulnerabilities affecting Internet Explorer, Outlook and Outlook Express as well as five newly=20 discovered vulnerabilities. Install now to pr...more >>

Hacking into firewall
Posted by Ajitesh Pathak at 7/30/2003 5:43:41 AM
Hi There, How can I hack the security in the office and try and access the sites which we are denied access into?? Ajitesh...more >>

MSPOP-UP MESSAGE SERVICE <KILLER POP-UPS>
Posted by Moses and Elija at 7/30/2003 2:16:33 AM
*******GREETINGS************** We are writing to tell you about the problems of "Abuse" with their Message Service> I didn't mind before or when I first started recieve these messages because I didn't know what it was. I didn't know what popup message was.. but gave me message of: Your comp...more >>

RPC/DCOM Worm Released
Posted by paul_lynch67 NO[at]SPAM hotmail.com at 7/30/2003 2:09:24 AM
Hello, This is a quick heads-up to let you know that there have been 'sightings' of a new worm which seeks to exploit the latest vulnerability in all versions of Windows. More details here : http://grc.com/default.htm http://vil.nai.com/vil/content/v_100516.htm Patch available here : ...more >>

Browser Warning Message
Posted by Itopa at 7/30/2003 2:01:25 AM
I have install the certificate on my certificate server and enabled the ssl port. Now when i access my webpages, the browser gives me warning that the CA is not the one trusted by my browser Yes or No if I would like to go ahead. What can i do to suppress this message from coming up on ...more >>

Passing credentials
Posted by Kumarajothi C at 7/30/2003 1:16:15 AM
Hi, I have two web sites (site A and Site B) on the same IIS server. Site B is set with 'Basic Authentication' mode. Site A doesnt have basic authentication enable. From site A I programmatically get the user name and password to validate the user and redirect the user to Site B. Her...more >>

Installing SSL on a web site
Posted by keven at 7/29/2003 4:36:34 PM
Hello. I installed a local CA on my web site using the Microsoft ca server. This is a stand alone box. I then had it apply the ca certificate from the local server. I can view the certificate. The problem is if I enable require ssl then try to https: the web page i get page can't be v...more >>

URL SCan still having issues ...
Posted by Todd at 7/29/2003 1:22:45 PM
Hey everyone, Thanks for all your support but, I did what some of you told me and edited my urlscn.ini and IIS still loges the rejected requests, it dosn't log like the whole string but it does still log them, Is there anyway to make it so IIS will not log any rejected requests that urlSCa...more >>

User NT Authentication
Posted by Guy Peay at 7/29/2003 11:31:34 AM
Hello I am an ASP developer working on NT 4.0 platform with IIS 4.0 server. I am trying to do security from the brower by calling the "GetTokenInformation" to get the NT authentication token to ensure that the user has logged in. My question is is this possible through scripting (javas...more >>

IIS 5.0 Cumulative Patches
Posted by Barry Hastings at 7/29/2003 10:33:05 AM
We have just installed Windows 2000 Server and IIS 5.0 for a new web server. I noticed in checking for security patches that there are two for IIS that are called "cumulative", Q301625 from MS01-044, and Q811114, from MS03-018. Do I need to install the earlier one first, or does the one ...more >>

Programmatically ban IPs within IIS 5.0 and W2k
Posted by Scott at 7/29/2003 10:03:23 AM
Does anyone know how to programmtically ban IPs within IIS 5.0 and W2k? I have a process that parsers my IIS logs looking for malicious activity. I want to be able to programmtically add the IP address of the malicious requestor to the denied/blocked list. Thanks......more >>

Possible permission Issue
Posted by Tony at 7/29/2003 9:30:14 AM
I have a user that is using a program called Cinderella to generate java pages. The server that we use is IIS 6 with FPSE. This is the error message that I receive when I look at the java console: java.io.FileNotFoundException: http://www.optics.arizona.edu/jcwyant/Geometry/Optics.cdy jav...more >>

security/access question
Posted by Chris at 7/29/2003 9:24:41 AM
I have a bunch of IPs that are denied access to my server. For the most part it works but..... there are one or two IPs that are still able to have access to my system. I've double checked the logs and then reentered them in the denied list but they still are being allowed access. This is a win...more >>

DNS server & Intranet site renaming
Posted by BijuThomas at 7/29/2003 1:20:03 AM
I have asked a query to this group some time back. With the help of this group I am able to solve the problem partially. can any one help me in solving this problem. My Question & Steps taken is given below. My Question was---------------I am hosting a intranet server on a windows 2000 se...more >>


DevelopmentNow Blog