all groups > iis security > september 2003 > threads for september 1 - 7, 2003
Filter by week: 1 2 3 4 5
XP Pro - NTFS Inheritance Question/Pblm
Posted by Arnold Shore at 9/7/2003 9:02:50 PM
I'm up a tree: the physical directory and subfolders of an ASP app of mine
are stuck on READ-ONLY - refuses to change. This system is at SP#1. (The
app works fine on another machine, a FAT-32 XP system.)
I've RTFM. The properties/security tab on the physical folder involved
shows ONLY sh... more >>
Website getting raped for all of its pages..
Posted by Bindair Dundat at 9/7/2003 6:55:23 PM
Actually I found a section of my logs that describes what I am
concerned about... View at the end of this email... you can see that
come from the same class B, however they are from different computers,
different programs, and different operating systems even. (even though
imagine that tha... more >>
Security Breach Hotmail
Posted by g at 9/7/2003 6:02:27 PM
Hotmail account hacked into by someone who used a hackers
program to break the password. How do I disable the
hotmail and msn account as this person is using them to
impersonate and has left a folder in the hotmail account
and leaves us threatening messages. Appreciate any help
on this ... more >>
Logon
Posted by Sean at 9/7/2003 1:31:46 PM
When I try to log on to my IIS web server out of IE 6.0
and i enter my Win Xp Pro user name and passeord I get an
error that I do not have logon creditientals. HOw do I
gain theses?... more >>
running URLscan for second time
Posted by Raigo at 9/7/2003 1:24:32 PM
I installed IISLocdowntool and URLscan, what came with
it. I set up my permissions etc. Meanwhile I had to
uninstall IIS, then reinstall it. Now I have IIS up and
running again, but can't figure out how to run URLscan
again.
I did search and have directory "urlscan" with
urlscan.dll , ur... more >>
Forcing SSL on pages
Posted by Joseph at 9/6/2003 11:27:14 PM
Microsoft Knowledge Base Article - 239875
I have been reading about this article and am a little
confused can anyone give me a hand- please?
1. Which way should I access the root of my web to put
the file ForceSSL.inc?
2. How should the script that is supposed to be at the
top of the page... more >>
401.3 Access denied by ACL
Posted by vasi at 9/6/2003 5:13:50 PM
I use IE 6.0
I am unable to access the website that I've been visiting
quite often. I get a pop up connection box asking me to
enter credentials (login and pwd)!
Pls help! Is there any IE settings to modify?
Thanks... more >>
connecting to IIS via Directway
Posted by Ernesto Muniz at 9/5/2003 9:12:46 PM
I have had my IIS server running with basic authentication
for some time now with users connecting via the Internet
with no problems until I signed up one of my user with
Direcway (Satellite Internet access) - This user is able
to browse the internet with no problems until he tries to
conn... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
ActiveX not able to run due to security
Posted by Elizabeth McCabe at 9/5/2003 7:51:29 PM
I am getting a message that my security settings are
preventing the running of ActiveX. I am assuming this is
why I cannot open jpg photos even from my files.
PhotoSuite opens but nothing appears. Also when I scan
with Norton AntiVirus the final report is a blank screen.
When Microsoft upd... more >>
User accounts
Posted by Peter Hall at 9/5/2003 4:39:44 PM
How can I set up user accounts to access an HTTP site,
hosted on my IIS server, without them being able to log
on to my machine locally?
I'm using XP pro and I'd like to give a few people
passwords to access some files, but their names appear as
login options when I start my machine up.... more >>
IWAM_Machinename permissions
Posted by Christopher Pragash at 9/5/2003 4:15:48 PM
Hello all,
I have an ASP web site which accesses middleware objects built using VB.NET.
The web site runs under the 'Medium' Application Protection level. I get
some Access denied error messages and hence I used FileMon utility to
monitor file access. The dllhost.exe that is spawned as a seper... more >>
IIS CRL Checking
Posted by Jackson Lancaster at 9/5/2003 1:55:16 PM
Can anyone explain (in some detail) how IIS checks CRL's for client PKI
certs. The articles I have seen state that IIS uses the CRL CDP to verify
client certificates. Is this true that IIS will use http or ldap (live) to
verify a cert against a CRL. I have also read that IIS caches the CRL's
... more >>
deleting search the web history on MSN
Posted by charley at 9/5/2003 12:50:36 PM
How do I delete history on MSN where it says search the
web. I double click and the history can't be erased... more >>
I clean it several times but she still find it. HELP!
Posted by Jackcin at 9/5/2003 11:30:02 AM
PLEASE someone help me, I use 3 different programs to
clean up all the places I know of where internet activity
and content like cookies, temp files, cache and fav's
documents, history, Reg, URL and search but some where my
computer has some sort of activity log file that my wife
pulls up ... more >>
IE 5.5 sp2
Posted by Clark at 9/5/2003 11:03:59 AM
Hope somebody can help. I can't get into www.paypal.com. I
get a Internet Explorer error window that says "Cannot
display this page, check your settings." Does anyone know
what settings I need to change. It's the only web site I
can't get into. Please reply to my email address.
thanks.... more >>
xrenoder redirection
Posted by corb at 9/5/2003 9:59:07 AM
What is it and how do you get rid of it ?
My system is windows X P.
PLEASE HELP!
Corb ... more >>
IIS log file - PROPFIND
Posted by Greg at 9/5/2003 8:44:17 AM
I notice from time-to-time that I get out of the ordinary
entries in my log file. Check out the lines below, I'm
always used to seeing the "GET" function but what is
the "PROPFIND"?
You'll notice all the hack attempts and then the odd one
on the last line.
Help?
------
01:51:28 68.... more >>
Certificate services won't start
Posted by m at 9/5/2003 5:52:24 AM
Hello,
I got the below error message in my event viewer of the
webserver box.
This error is under Application event
"Certificate Services did not start: Could not build CA
certificate chain for Houston Associates, Inc.. Cannot
find object or property. 0x80092004 (-2146885628)."
This ... more >>
Certificate services won't start.
Posted by M at 9/5/2003 5:51:23 AM
Hello,
I got the below error message in my event viewer of the
webserver box.
This error is under Application event
"Certificate Services did not start: Could not build CA
certificate chain for Houston Associates, Inc.. Cannot
find object or property. 0x80092004 (-2146885628)."
This ... more >>
Enable WebDav in IIS 6?
Posted by Dave Crabbe at 9/4/2003 6:38:21 PM
Seems like a pretty basic question but I have the Windows SharePoint beta 2
and IIS 6 on my Win2k3 server and I want to create web folders. Seems easy
but doesn't work. I can't get any access to the web share.
Does one need to globally enable WebDav on the IIS 6 server? and if so, how?
(I have... more >>
Can IIS Log username from client certificate?
Posted by Ohaya at 9/4/2003 5:24:15 PM
Hi,
I'm running IIS under Win2003 Server, and have "client authentication
required" enabled but with mapping from the client cert to the Windows
username NOT enabled.
Is there any way to have IIS log the username from the client's
certificate logged to the IIS log file, without the user h... more >>
Errors
Posted by John Willis at 9/4/2003 2:30:18 PM
Gentlemen: My windows XP program keeps shutting down and
it comes up: C\windows\Minidump\Mini090303-01dmp and
C\DOCUME^1John^1JOHN\Locals^1\Temp\wer3temp.cir00
\systemmdate.xmj. How do I get these out of my system?
These errors keep shutting me down. John Willis... more >>
IIS 5.0 password protected website problem
Posted by Steve Holland at 9/4/2003 10:01:38 AM
Hi all,
We are experiencing a strange problem with all websites we password protect.
We have a win2k/IIS5 server which we host test versions of websites we
develop. All of the sites are password protected, using folder security. We
removed IUSR account and added a locally created user, in IIS,... more >>
Trust between Windows 2003 and NT 4.0 domains
Posted by Leo at 9/4/2003 5:07:05 AM
Hi,
I have the following situaton:
A one way outgoing trust exists between a Windows
Enterprise Server 2003 domain [A] and a Windows NT 4.0
Enterprise Server Domain [B].
A trusts B
A global group on B containing all users from B is added
to a local group on A. This local group has ... more >>
IIS 6.0, multiple ssl sites, most wont answer
Posted by Andy at 9/3/2003 3:34:11 PM
I'm trying to run multiple sites on a cluster of
webservers. Most of the sites use SSL. I have the
certificates installed, and a port number of 443
specified.
However, only some of the sites will answer requests for
https://sitename, while others return simply a dns error.
Clean inst... more >>
Changing secure certificate issuers with IIS 5 - please help!
Posted by Julian Gudsell at 9/3/2003 1:37:18 PM
I have a number of sites that have secure certs due to
expire shortly. I want to use a different issueing
authority for the new certs. Advice I have had suggests I
have to remove the existing cert. and then generate a new
CSR. This means the sites will have no certificate during
the renewa... more >>
503 user cannot log in
Posted by Javier Poot at 9/3/2003 12:08:59 PM
Hi,
I'm working on win 2003 server and IIS 6.0
how can I connect an ftp user without password??
I get the error:
503 user cannot log in
but if I give him a password and try to connect, it works
fine.
I think that is a IIS security issue but I don't know how
to disable it.
Thanks.... more >>
Active directory control of SQL/WEB users security
Posted by John Warren at 9/3/2003 8:58:24 AM
We are looking at what to use to control users security
through WEB apps connected to a SQL2K data base. Different
users will have different ability to access data in the DB.
We were thinking about using Active Directory for the user
database. WEB apps would require access to information in... more >>
SSL for internal application
Posted by Steven at 9/3/2003 8:28:30 AM
Would like to setup SSL internally for an HR application,
but would like to set it up without a third party
certificate. It there a way to generate a certificate like
apache for an intranet application?... more >>
spam adds
Posted by Tim Hoolihan at 9/3/2003 7:34:25 AM
My computer will popup ads via C;\windows\system32
\srvhost.com from sites like
byebyeads.com,againstfat.com,messagedestroyer.net,messages
top.com,and endads to name a few. Is there any way to
stop this? My McAfee firewall stops the flow of data but,
I still have to close numerous windows. ... more >>
forgotten password for Outlook Express
Posted by Charleen Reid at 9/2/2003 7:32:02 PM
When I tried to check for new mail this evening the
computer asked me for sign-in information; i.e., my E-mail
addres and passwordd. I do not remember the password, nor
do I remember ever creating one. Please help me. How do
I find my password, or create a new one?... more >>
Finding the WEP Key in Windows XP
Posted by Candace at 9/2/2003 6:23:48 PM
Here's my question:
How do I find the WEP key in Windows XP? I have tried
and tried and cannot located it on my computer. I am
trying to set up a wireless network with another computer
in my house and I am using a Microsoft Wireless Adapter.
In order to complete installation, I must ty... more >>
IUSER_SERVER Member of the administrators group ?
Posted by Robbo at 9/2/2003 4:54:17 PM
Hello. After doing a baseline security analysis, I found that the IUSER
account is a member of the local admins group..
I have asp.net installed and running on the webserver.
I do not want to disrupt anything running on the server, what should I do to
correct this, I definatally do not w... more >>
401 evp warning
Posted by jim at 9/2/2003 3:40:33 PM
When I click on my explorer icon, the first page that pops
up is a "401 EVP WARNING" message. The message is
designed to look authentic and be very scary. It states
that key words for porn have been detected on your
computor. It states that we are being watched and when
the last time we... more >>
password cannot be saved
Posted by C. Jergenson at 9/2/2003 2:05:40 PM
"Save Password" box in Outlook Express does not seem to be
working. I downloaded Knowledge Base Article 815229 which
explains how to make changes to the Registry for Windows
XP. Step #5 in the "Resolution" says to go to the
Security Menu...where is the Security Menu?
I would really appre... more >>
IIS Administration
Posted by matt. at 9/2/2003 12:36:10 PM
We have an IIS server running on an NT4 BDC. We have a
developer who needs to run the IIS admin as well as
start/stop the IIS service. Any way to do this without
making him a domain admin? would not want to do that.
thanks
Matt... more >>
Content Password
Posted by Biker53 at 9/2/2003 11:51:32 AM
Somehow now every web page on IE 6, including MSN, brings
up Pop-up Window 'Content Advisor' requiring me to log in
password to continue - I cannot set disable because I can't
recall/remeber setting up pasword to proceed...,
How can I change/Delete the password in this prompt??????
I'm using Wi... more >>
IIS SSL and Multiple Ports
Posted by Steve Hough at 9/2/2003 9:40:08 AM
I am running multiple websites on my test Windows Advanced
Server IIS 5.0 by using the same IP and multiple ports.
I am having problems when I am testing SSL. If the
website runs on Port 80 the test certificate (14 day
trial) runs fine, but will not run under a specified port.
We cannot... more >>
IIS6.0 Error 70 Permission denied
Posted by Luis at 9/2/2003 9:26:46 AM
I have a site that show folders and files on internet
explorer browser, this site is running normally in IIS4.0,
but when I copy the files, NTFS permissions, site
configuration to IIS6.0 it does not works. If I want that
this site works I need to add the userid to the
server/administrators... more >>
web server always though smtp send e-mail to other people
Posted by kof ynnad at 9/2/2003 9:23:20 AM
Hihi,
I don't know why my web server always thougth smtp send e-
mail to some specific IP addresses.
I install IIS 4.0 but not include SMTP service.
And I get this from the log of my firewall.
My isp warn me don't send spam mail to some specific IP
address.
So, I block the smtp s... more >>
INSTANT MESSAGES
Posted by JugglingAct1 at 9/2/2003 7:38:40 AM
Can a Lay-Person access Instant Messenger Transcripts or
request such from Microsoft?... more >>
e-mail from Microsoft
Posted by Don Chaput at 9/2/2003 7:27:43 AM
I keep getting a e-mail form Microsoft with an
attachment. I know that Microsoft does not send e-mails.
Therefore the attachment is a virus and they just keep on
coming, every day. I called my server and they said that
they can not stop it at their end. Is it possible for me
to stop it a... more >>
Getting attacked on port(s) 53, 139, 445 & 1433???
Posted by Jeff at 9/2/2003 7:22:15 AM
Recently I've been getting attacked from somewhere and I
can't figure out where, or what ports this attack is
coming from. We host a web application that accesses a
SQL Server to retrieve it's information. I have a
NetScreen NS50 firewall, and it doesnt' seem to tell me
the source IP add... more >>
URL Scan and Unknown Sessions - Repost
Posted by Anthony Bouch at 9/1/2003 5:13:48 PM
Hi - below is the original post. I've just seen a huge jump in activity for
this problem. Date and times aren't included but they're coming every minute
at fairly regular intervals - well over a thousand a day now - this will
eventually bring our system down if we can't solve this one.
Can any... more >>
403.6 Forbidden: IP address rejected - Error - URGENT please Help
Posted by Martin at 9/1/2003 9:33:49 AM
I am receiving this 403.6 Forbidden error even though their a no
restrictions set on the server. Has my metabase been corrupted? I am running
iis4 on NT4 sp6a SRP. This appeared after I tried to allow reverse DNS
lookups in iis.
Thank You
... more >>
HOW TO Harden the TCP/IP Stack Against Denial of Service Attacks in Windows 200
Posted by Raigo at 9/1/2003 2:22:04 AM
Windows 2000 Server SP 4, IIS 5.
I am setting up and securing a web server, based on
article
HOW TO: Harden the TCP/IP Stack Against Denial of Service
Attacks in Windows 2000
http://support.microsoft.com/default.aspx?scid=kb;en-
us;Q315669&sd=tech
I was successfully able to change r... more >>
|