Groups | Blog | Home
all groups > iis security > september 2003 >

iis security : Securing IIS 5.0


Rob
9/14/2003 5:28:58 PM
I am running Windows 2000 Server with IIS 5.0 and I used
the instructions on a document named secure IIS 5.0
checklist to stop a problem with a spammer that I had.
These procedures corrected the problem but now I can't
get into my website without entering a user name and
password. This creates a big problem because the site is
used for my business and my customers or potential
customers need to access my website without a password.
Is there a way to allow users to enter my website without
a password and not downgrade the way I secured Windows
2000 and IIS 5.0 so I don't encounter Spammer problems
again. Also I am using a web client for email access and
after I ligin into my site and put in the URl for the
webmail I get the login screen and I login only to see a
screen the is no longer available. This screen did work
before I locked down my server. The webpage is a .asp (I
think) Did I disable some type of .asp mappings or
Paul Lynch
9/15/2003 10:42:09 AM
Rob,

Read these KB articles for more advice on authentication mechanisms in
IIS5 :

HOW TO: Configure IIS 5.0 Web Site Authentication in Windows 2000
http://support.microsoft.com/?id=310344

HOW TO: View or Change Authentication Methods in IIS
http://support.microsoft.com/?id=301457

INFO: How IIS Authenticates Browser Clients
http://support.microsoft.com/?id=264921


Regards,

Paul Lynch
Leythos
9/15/2003 11:47:15 AM
In article <060301c37b20$5a9f38e0$a001280a@phx.gbl>,
robertzarko@comcast.net says...
[quoted text, click to view]

It sounds like you have two problems:

1) You locked down the SITE so that Anonymous users can't use it in a
effort to stop someone from using your SMTP service.

2) Your SMTP service was open, allowing relaying.

You can configure the SMTP service so that it doesn't allow relaying,
without having to remove anonymous access to the website.

Read up on securing IIS SMTP service from open relaying.

--
--
spamfree999@rrohio.com
Bernard
9/15/2003 5:48:32 PM
what did you actually do to the server ?
iislock down ? and what do you choose in the option ?

if you get a prompt when browsing the site, most likely
the anonymous user (iusr) doesn't has READ permission
on the files.

If you do run lock down tools, I suggest you re-run it to undo
changes, then run it again, this time choose the correct
template.

--
Regards,
Bernard Cheah
http://support.microsoft.com/
Please respond to newsgroups only ...


[quoted text, click to view]

AddThis Social Bookmark Button