all groups > iis security > july 2003 > threads for july 29 - 31, 2003
Filter by week: 1 2 3 4 5
Delegation of IIS administration
Posted by Ash Dey at 7/31/2003 11:23:01 PM
Is there any way, I can create a windows security group
and then delegate to manage the IIS admin without giving
the complete server administration right?
I am aware that, the IIS oprator group is unable to
create virtual directory i.e. by design.
I want the security group members shoul... more >>
Script access - IIS 6
Posted by Mark Hildreth at 7/31/2003 10:59:19 PM
I am trying to execute a python script on IIS 6 as follows:
Anonymous access
http://cvstest/viewcvs and http://cvstest/viewcvs/viewcvs.cgi
Both of the above work. I have made viewcvs.cgi a default page for the
directory.
Authenticated access:
Removed anonymous access, added ACL for user gr... more >>
How do You access data from IIS on another server
Posted by Dermott Renner at 7/31/2003 4:24:30 PM
IUSR_Computername gives users anonymous access to the web
site. What gives IIS or the IIS service or ASP pages on
the web server the access to say FoxPro or Access data on
another server (files are not SQL Server so not
interested in how SQL does it)
Thanks
Dermott... more >>
Strange W3svc log entries
Posted by Frank at 7/31/2003 3:24:12 PM
Hello all,
I am getting very strange log entries on one of my web
servers they look like this
Get, /Default.ida,xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Does anyone know what could be causing this. IS it a virus
or a sign of intrusion?
Tha... more >>
URL Scan on OWA
Posted by Björn Johansson at 7/31/2003 11:28:41 AM
Hello,
I've set up a OWA (front end) on our DMZ. The recommended template for OWA
is used on URLScan.
The problem is that it blocks URLs containing "&" and ".." signs. This is
very disturbing for our users because many emails contains .. and "&" and
".." signs in subject line.
Is there a... more >>
HTTP TRACE Support
Posted by Richard at 7/31/2003 9:11:21 AM
I have an issue with "HTTP Trace Support" being enabled. I
have found documents that state "Use URL Scan" to fix the
problem. I do not want to use URL Scan due to the fact
that it caused more problems then it fixed. I keep running
into the refrence of "RFC 2516" regarding "HTTP Trace
Suppo... more >>
Frontpage search feature do not work after installing URLSCAN
Posted by STL at 7/31/2003 1:00:48 AM
I have just install URLSCAN in my win2k server.
I have used the frontpage website search component in my
website. This component uses the indexing service.
When I tried to access the page
http://testsvr/myweb/v4static/searchlt.idq
I get this error msg:
HTTP 401.3 - Access denied by ACL on r... more >>
Pornographic Pop-Ups
Posted by Dianna Miller at 7/30/2003 9:06:56 PM
Please!!!! Can some one help me stop these pornographic
pop-ups from plastering my screen 4, 6, 8, or more at a
time? I have young children and there is no excuse for
them to have to see these uncontrolable pictures that
just come up out of no where. One picture is bad enough,
but I can... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Correct Domain User/Pass/Domain credentials rejected
Posted by - at 7/30/2003 6:27:09 PM
Hello,
I have several clients of two web based systems who are being prompted with
a popup for their name and password for a website. This is fine since it
was configured in this way. The problem is that they (and on some machines
myself) put in the proper credentials Username - Password - D... more >>
Cannot generate CSR for Gibraltar region using IIS. Alternative CSR generating mechanisms?
Posted by JeanValjean at 7/30/2003 6:05:29 PM
HI
I am trying to generate a CSR for a server to be hosted in Gibraltar. If I
try to generate a certificate signing request using IIS5, I find that in the
field for specifying the Country/Area code there is no entry for Gibraltar
(GI). It is only possible to add a area code from this list.
... more >>
Trying to Get SSL and IIS to work using Microsoft CA
Posted by Keven at 7/30/2003 2:24:56 PM
Please help me to get SSL to work on a standalone PC (Non
Domain). I created a web page using CGI that does file
upload. I wanted to make this secure so that names and
passwords are not sent in the clear.
I installed Certificate server locally on the box.
I went into IIS and said use ... more >>
Strange 401.1 Errors
Posted by NetAdmin NO[at]SPAM liginsurance.com at 7/30/2003 2:01:43 PM
I am trying to have users use their standard windows login information
to login to a website. However, For certain members I get a 401.1
error page. It seems to be linked to the user because it happens
because of the user logged on to the computer. As in, if I put in an
administrative usernam... more >>
IIS 6.0 Default Security...
Posted by Ben Millspaugh at 7/30/2003 12:53:24 PM
I have used IIS for years and am in the process of moving
my websites to IIS 6.0 (new servers, not upgrades). I
would like to lock down the security, but I don't want to
lock it down so much that the system can no longer process
the files. I also see that Windows Server 2003 & IIS 6.0
ad... more >>
Bogus or real?
Posted by Louis Davidson at 7/30/2003 10:25:53 AM
Microsoft Customer
this is the latest version of security update, the
"July 2003, Cumulative Patch" update which eliminates all
known security vulnerabilities affecting Internet Explorer,
Outlook and Outlook Express as well as five newly=20
discovered
vulnerabilities. Install now to pr... more >>
Hacking into firewall
Posted by Ajitesh Pathak at 7/30/2003 5:43:41 AM
Hi There,
How can I hack the security in the office and
try and access the sites which we are denied access into??
Ajitesh... more >>
MSPOP-UP MESSAGE SERVICE <KILLER POP-UPS>
Posted by Moses and Elija at 7/30/2003 2:16:33 AM
*******GREETINGS**************
We are writing to tell you about the problems of "Abuse"
with their Message Service> I didn't mind before or when
I first started recieve these messages because I didn't
know what it was. I didn't know what popup message was..
but gave me message of: Your comp... more >>
RPC/DCOM Worm Released
Posted by paul_lynch67 NO[at]SPAM hotmail.com at 7/30/2003 2:09:24 AM
Hello,
This is a quick heads-up to let you know that there have been
'sightings' of a new worm which seeks to exploit the latest
vulnerability in all versions of Windows.
More details here :
http://grc.com/default.htm
http://vil.nai.com/vil/content/v_100516.htm
Patch available here :
... more >>
Browser Warning Message
Posted by Itopa at 7/30/2003 2:01:25 AM
I have install the certificate on my certificate server
and enabled the ssl port. Now when i access my webpages,
the browser gives me warning that the CA is not the one
trusted by my browser Yes or No if I would like to go
ahead.
What can i do to suppress this message from coming up on
... more >>
Passing credentials
Posted by Kumarajothi C at 7/30/2003 1:16:15 AM
Hi,
I have two web sites (site A and Site B) on the same IIS
server. Site B is set with 'Basic Authentication' mode.
Site A doesnt have basic authentication enable.
From site A I programmatically get the user name and
password to validate the user and redirect the user to
Site B. Her... more >>
Installing SSL on a web site
Posted by keven at 7/29/2003 4:36:34 PM
Hello. I installed a local CA on my web site using the
Microsoft ca server. This is a stand alone box. I then
had it apply the ca certificate from the local server. I
can view the certificate. The problem is if I enable
require ssl then try to https: the web page i get page
can't be v... more >>
URL SCan still having issues ...
Posted by Todd at 7/29/2003 1:22:45 PM
Hey everyone,
Thanks for all your support but,
I did what some of you told me and edited my urlscn.ini
and IIS still loges the rejected requests, it dosn't log
like the whole string but it does still log them,
Is there anyway to make it so IIS will not log any
rejected requests that urlSCa... more >>
User NT Authentication
Posted by Guy Peay at 7/29/2003 11:31:34 AM
Hello
I am an ASP developer working on NT 4.0 platform with IIS
4.0 server. I am trying to do security from the brower by
calling the "GetTokenInformation" to get the NT
authentication token to ensure that the user has logged
in. My question is is this possible through scripting
(javas... more >>
IIS 5.0 Cumulative Patches
Posted by Barry Hastings at 7/29/2003 10:33:05 AM
We have just installed Windows 2000 Server and IIS 5.0 for
a new web server. I noticed in checking for security
patches that there are two for IIS that are
called "cumulative", Q301625 from MS01-044, and Q811114,
from MS03-018. Do I need to install the earlier one
first, or does the one ... more >>
Programmatically ban IPs within IIS 5.0 and W2k
Posted by Scott at 7/29/2003 10:03:23 AM
Does anyone know how to programmtically ban IPs within
IIS 5.0 and W2k?
I have a process that parsers my IIS logs looking for
malicious activity. I want to be able to programmtically
add the IP address of the malicious requestor to the
denied/blocked list.
Thanks...... more >>
Possible permission Issue
Posted by Tony at 7/29/2003 9:30:14 AM
I have a user that is using a program called Cinderella to generate java
pages. The server that we use is IIS 6 with FPSE. This is the error
message that I receive when I look at the java console:
java.io.FileNotFoundException:
http://www.optics.arizona.edu/jcwyant/Geometry/Optics.cdy
jav... more >>
security/access question
Posted by Chris at 7/29/2003 9:24:41 AM
I have a bunch of IPs that are denied access to my server. For the most part
it works but.....
there are one or two IPs that are still able to have access to my system.
I've double checked the logs and then reentered them in the denied list but
they still are being allowed access. This is a win... more >>
DNS server & Intranet site renaming
Posted by BijuThomas at 7/29/2003 1:20:03 AM
I have asked a query to this group some time back. With
the help of this group I am able to solve the problem
partially. can any one help me in solving this problem. My
Question & Steps taken is given below.
My Question was---------------I am hosting a intranet
server on a windows 2000 se... more >>
|