all groups > iis security > september 2003 > threads for september 8 - 14, 2003
Filter by week: 1 2 3 4 5
Securing IIS 5.0
Posted by Rob at 9/14/2003 5:28:58 PM
I am running Windows 2000 Server with IIS 5.0 and I used
the instructions on a document named secure IIS 5.0
checklist to stop a problem with a spammer that I had.
These procedures corrected the problem but now I can't
get into my website without entering a user name and
password. This c... more >>
Using client certificates in ASP
Posted by languy at 9/14/2003 3:51:39 PM
Hi there,
I have an ASP page, which have to connect to an SSL server that
requires a
client certificate, but I get the following error:
Erroror Type:
msxml3.dll (0x80072F0C)
A certificate is required to complete client authentication
/test/test.asp, line 34
Here goes my code:
const DQ... more >>
[IIS 6] A summary of my strange situation
Posted by Massimo at 9/14/2003 1:47:26 PM
Here's a summary of the troubles I'm experiencing, of which I've been talked
in a previous thread. Now I'm posting again explaining all about my
security-related configuration, so maybe someone can help me out of this.
Here's the full story. I wanted to have my websites on another drive than
the... more >>
Microsoft patch 822925
Posted by Christy at 9/13/2003 11:36:24 AM
I have the Millenninum edition and my computer downloads
the cumulative patch for Internet Explorer 6 #822925 over
and over again. I install it over and over and it
continues to download and install. I don't notice
anything else happening that I would suspect that I have a
virus. Can an... more >>
Redirecting to same server
Posted by David Crystal at 9/12/2003 11:18:05 PM
I have a web interface for a document management system running on IIS5. It
installed itself under the Default Web Site. We have employed an SSL
certificate and now users must preface the URL with 'https' rather than
'http'. Is there any way to automatically redirect users to the same
website ... more >>
Unpsecified Error with ODBC Connections
Posted by David Lozzi at 9/12/2003 3:52:02 PM
This happens a lot to my databases. I store them at the root of my
developing files, i.e. c:\My Projects\Proj1\database.mdb. Randomly, the
security settings on this database will drop to the basic secutiry, myself
and SYSTEM. I need IUSR on it so I can access it through my ASP pages... I
get err... more >>
Client Certificates
Posted by Darren at 9/12/2003 12:28:13 PM
I have a web site running on IIS 5.0. I am using
certificates to authorize the users for the secure part
of the site. I have four workstations that when I go to
install the client certificates from the CA, I get this
message:
The Certificate cannot be installed because of a problem
wi... more >>
Group Policy effects on IIS 5
Posted by tzone at 9/12/2003 9:29:00 AM
I'm having problems getting a Form (ASP script) to run on
our website. Getting this error message- "HTTP 500
Internal server error". Here is the catch if I use a
domain admin account in IIS for the anonymous web account
it works fine??? Also it didn't work with the default
Anonymous Web Us... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
IIS lockdown 2.1 unattended installation
Posted by k_bashir NO[at]SPAM yahoo.com at 9/12/2003 8:42:29 AM
How do u put the custom iislockd.ini on the command line. What
parameter u have to use for iislockd.exe so that it looks at the
custome iislockd.ini for quiet installation.
i have read the runlockdunattended.doc but some how i am missing in
terms of parameters to run it in unattended.... more >>
IIS 5.0-6.0 Virtual Directory Permissions Issue
Posted by raoul NO[at]SPAM keinetworks.com at 9/12/2003 8:15:04 AM
Hi,
I'm trying to upgrade from a server 2000 domain to a non-domain server
2003 environment but IIS is holding me back.
It seems that when I create a virtual directory on another server
users cannot see the files. If I have a domain this is no problem. I
have tried changing all security/p... more >>
[Windows 2003] [IIS 6] A strange access problem
Posted by Massimo at 9/12/2003 12:22:37 AM
I have a very strange problem with a Windows 2003 webserver. The machine is
part of a (2003) domain which we'll call "mydomain.com", and DNS is so
configured:
frontend.mydomain.com -> 192.168.42.20
www -> frontend.mydomain.com
test -> frontend.mydomain.com
The webserver is running two site... more >>
FTP folder and permission setup questions.
Posted by Sara at 9/11/2003 11:10:18 PM
I have a FTP server at my Nt4.0 SBE, and IIS 4.0 on it.
I now want to setup different folder for different
company to download or upload the files to those unique
folder, but I dont' want those company to see each other
folder on my FTP site. Is that anyway can setup a
structure on my FTP ... more >>
virus blockers
Posted by richard at 9/11/2003 8:53:47 PM
I downloaded Antology virus blocker but now have doubts
about them. Does anyone know of them, & if so, are they a
trusted program?... more >>
reserch
Posted by maria oates at 9/11/2003 7:03:23 PM
I wanted to know what was last weeks events that happend
in microsofts software that allowed worms and viruses to
enter into the system. I am writing a paper on it for
school. I would be more than happy to know if there was
an artical from last week that i can referance so that it
would ... more >>
Certificate Services
Posted by Shirley at 9/11/2003 5:46:04 PM
I have set up a couple of webdav folders and would like
the users to use SSL to keep there passwords encryped. We
are a small university and of such a small use of a
certificate I would rather generate my own, especially
since it will mainly be used by only a few faculty. I know
I need to ... more >>
New hack attempt showing in log - anyone seen this one?
Posted by Karen at 9/11/2003 5:35:37 PM
I've discovered a new hack that isn't 404'ing when they
dir my drives. I don't know if they are succeeding in
some way, as they are not getting a 404. They try to copy
cmd.exe to cmd2.exe, but it doesn't look like that worked
(cmd2.exe not on the machine anywhere). I don't have all
th... more >>
Web sites on IIS
Posted by jyoti at 9/11/2003 4:58:52 PM
I am developing an web site. When user request for the
site, i like to find out if the request is coming from
inside our organization or out side our organization.
Within the organization means within the domain. We have
ip ranges within the organization. I will be using asp
and IIS 5.0.
... more >>
IIS 5.0 banner
Posted by Ferdie at 9/11/2003 3:54:01 PM
Can someone point me to a link that shows how to change the IIS banner?
Thanks,
Ferdie
... more >>
SSL on specific pages unsuccessful
Posted by joseph at 9/11/2003 1:51:31 PM
Hello,
I wanted to know if anyone could assist me in the
operation of getting certain pages to be secured by SSL
and then back to HTTP when leaving. I have been trying
for about 3days now and I did read all the articles
before posting but no luck.
I have tried to change the 404.3 error ... more >>
IP address restrictions
Posted by Raigo at 9/11/2003 11:08:42 AM
In IIS security tab, it is possible to deny certain IP
numbers. Is there a way to import these values from some
database?
For example at the moment, I read daily IIS logfiles and
have every day several IP numers what try things what are
restricted by URLScan (running cmd.exe etc.). Every... more >>
Need to audit / document file and directory security
Posted by jpuls NO[at]SPAM sentinel.com at 9/11/2003 9:58:21 AM
I have a web site with a few hundred pages, mainly active server
pages, set up in a tree structure. Some of the files and directories
allow anonymous access, some use integrated Windows authentication,
some are set up for both.
I'm looking for a tool which will work its way through all of thes... more >>
downloads
Posted by ken conway at 9/11/2003 9:36:31 AM
when installing download such as windows automatic update
should i turn off firewall and anti virus... more >>
Privileges to run CGIs
Posted by fredrik.martzen NO[at]SPAM ibs.se at 9/11/2003 9:14:45 AM
Hi
I have a webapplication running on Windows Server 2003, IIS 6.0, with
CGI-dlls combined with ASP.Net components. I use ASP.Net to access
files on a IBM iSeries server (IFS). I had no problems running my app
on a Windows 2000 Server with IIS 5.0.
I created a local user account with the s... more >>
Changing the index.htm through FTP basic authentication
Posted by Chris Sussman at 9/11/2003 6:03:50 AM
I am sure this answer is simple and staring me in the
face. However, I have yet to find it. I am running IIS on
a Windows 2003 server. I have web sites hosted on this
server allowing access through FTP basic authentication.
The users are able to get to the web directory through an
FTP clie... more >>
IIS 6.0 CGI Application and Security problem
Posted by Oleksander Panchuk at 9/11/2003 1:42:47 AM
We tried to migrate from the Linux platform to the
Windows. We used perl scripts for public access: quizzes
and etc. But now, after migrate, Windows Server demands
the authentication when user try to exec any CGI script.
Why?
Thanks, for your answer.... more >>
Last Network Security Patch
Posted by Chris at 9/10/2003 8:04:04 PM
I received an email with "Last Network Security Patch" in
the subject. It has an attachment and says it is from
Microsoft Corporation Internet Security Division
<irvepgs_608521@support.msdn.com>. The email says it is
a security patch. Is this really for MS or is this a
virus?
Thanks... more >>
IIS Logs
Posted by Joseph at 9/10/2003 7:38:48 PM
I was viewing my logs and saw this and do not know what
it is. Does anyone else know?
150 winnt/system32/cmd.exe requested
Thanks
Joseph... more >>
critical updates
Posted by bridget at 9/10/2003 6:29:20 PM
I have been attempting to download the critical updates
for 5 days.... it stalls and fails. it stops at the last
security download for winddows xp 819696. tried to e-
mail microsoft... what a joke. i am frustrated and do
not know how to proceed.... more >>
microsoft exployer
Posted by Joy at 9/10/2003 6:13:24 PM
I am not sure I am in the correct place or not, but I
downloaded microsoft exployer over my already internet
explorer and now I do not get a security scan, the
pictures are foggy nothing works like it use too. How can
I uninstall internet explorer and reinstall it so I can
have my email a... more >>
Hey windows lusers, if M$ is so secure, why does it hide behind LINUX?
Posted by Evil_penguin at 9/10/2003 5:41:35 PM
It's funny how billy can brag and ramble on and on about the =0A=
securiy of winblows and how much daddy LINUX stinks, but if =0A=
that's the case, why did M$ had to hide behing LINUX during the =0A=
last DDoS? =0A=
=0A=
Hey, you're entiled to know: =0A=
http://news.zdnet.co.uk/software/linu... more >>
Peculiar problem accessing remote share.
Posted by B. B. at 9/10/2003 1:08:16 PM
Any help on this matter is appreciated.
Given:
* Win2k server w/ IIS v5.0 (stand-alone workgroup)
* Another Win2k server with shares. Also stand-alone
workgroup.
The problem is NOT with the permission on the file-
sharing server.
Here is what I have narrowed it down to:
* If ... more >>
Microsoft.exe
Posted by Greg Olgin at 9/10/2003 12:43:24 PM
Folks,
This is the second day in a row I have received this in my
e-mail. It has 13 different viruses packed into it. Is
there any way that it can be stopped from being set all
over the place?... more >>
CGI Executable and IIS 6
Posted by Ronald van der Pas at 9/10/2003 12:27:40 PM
Hi,
We recently upgraded to W2003 and IIS6.
In our sites we use cgi executables. They write in some directories. Under
IIS 5 that was no problem, but under IIS 6 we seem to have no write-acces.
Although the userrights for IUSER_xxx are correct.
What can be wrong?
Greetings,
Ronald van d... more >>
Authentication issue
Posted by ALF at 9/10/2003 11:35:02 AM
Hi All,
Im having an issue with an intranet site we have. Users
in a different forest get a page cannot be displayed
error. The packets returned to the user are access
denied. The users can do a ping and a net view on the web
server without issue. In fact any request is fulfilled
axcept f... more >>
Require SSL settings slows connection to Web Server
Posted by Bruce Forbes at 9/10/2003 11:12:15 AM
We have a web site that we have the "Requires Secure
Channel" setting selected. I noticed it is very slow (20-
30 seconds) before you see the certificate request
window. When I remove teh SSL requirement for this site
and then open the browser, still using HTTPS, the window
pops up immedi... more >>
Configuring IWAM_MachineName for COM Interop
Posted by Christopher Pragash at 9/10/2003 9:48:18 AM
Hello all,
I'm trying to configure an ASP Web Application under IIS 5.0, 'Medium'
application protection for COM Interop. I guess the IWAM_Machinename has to
be explicitly granted Read/Write Permissions to some folders. Can anyone
please tell me what folders these are or where I could find som... more >>
Blocking popups
Posted by Annie L. at 9/10/2003 9:46:51 AM
I keep getting popups for pornography and other offensive
things and I don't want them on my computer! This started
today, and I want it to stop! I don't know how to block
these things. Please help!... more >>
user can logon with a blank account and password
Posted by m at 9/10/2003 6:51:42 AM
Hello,
We have an intranet website that allow for only employees
to logon and view the contents.
We enabled the SSL, and Logon with password and an
account, but somehow the when I test it I can logon
without typing any logon name or password, but if I type a
incorrect logon name then i... more >>
an unexpected error (0x1A8) occured while getting the certificate template list
Posted by Jon Munday at 9/10/2003 6:44:18 AM
When Requesting a server sertificate using a form I get
the following error:
An unexpected error (0x1A8) occured while getting the
certificate template list
Any Ideas ??
Thanks
Jon... more >>
IIS6 Hosting - Level Of Effort
Posted by bill22310 NO[at]SPAM hotmail.com at 9/10/2003 6:36:45 AM
My wife and I are developing an online directory and calendaring
application for our church web site. We have lots of development
experience but no hosting experience. We are going to have about 2000
to 3000 high res jpeg and low res jpeg pics. This is about 3 to 4 gig
of data. This pushes us t... more >>
IIS and J2EE
Posted by Gareth at 9/10/2003 6:29:41 AM
I would urgently like to know if IIS can do the job of
apache Tomcat.
Any help would be much appreciated ... more >>
Admin rights required for .Net dvlpment...surely not?
Posted by Aaron at 9/9/2003 11:05:09 PM
I'm setting up an iis5 server in a university setting to allow .net project
creation from VS .Net. I have the 1.1 framework installed as well as fp
extensions 2002. Created a folder as an application in Internet Services mgr
& virtual directory which points to file system folder. In the frontpag... more >>
Autocomplete problem
Posted by CM at 9/9/2003 10:43:19 PM
I have a vendor web program host on my company web site,
it allows user input the UserID and Password to get into
their system. However, we found that client browser has
recorded the UserID and Password on their windows, it
should be input every time when access this program. Does
anyone k... more >>
dialog box for Integrated Windows Authentication
Posted by samson at 9/9/2003 7:28:55 PM
I have an Intranet app (asp.net) running on IIS5 and have
Integrated Windows Authentication turned on (all other
auth options are turned off). I'm trying to let users to
log in seamlessly, but it brings up a dialog box for
username, password, and domain name. And the interesting
thing is... more >>
Outlook Express
Posted by Vivian Nash at 9/9/2003 6:09:04 PM
I probably do not have the right group so if you can
direct me in the proper channel I would appreciate it. My
problem is that Outlook Express deletes every attachment
that is sent to me and some of them are important and I DO
NOT want deleted. Who do I contact and how can I get it
stopp... more >>
Is there a way to set differing permissions on folders within a ftpsite
Posted by Doyle Collings at 9/9/2003 4:13:00 PM
It appears that I can only set the permissions for the whole ftp site. I would like to give individual user access to each folder. Am I asking to much?
Doyle Collings
Network Administrator
City of Logan
dcollings@loganutah.org... more >>
Win2000 Certificate Services Problem
Posted by Amanda at 9/9/2003 2:20:37 PM
I am trying to implement a certificate infrastructure for VPN connections
using L2TP/IPSEC VPN connections. I got this working successfully on a
Windows 2003 server in a test environment.
On my live network I installed Certificate Services on my Windows 2000 SBS
server as an Enterprise Authori... more >>
Internet Information Service (IIS)
Posted by Soheil at 9/9/2003 11:41:44 AM
I hope u can help me. I would like to test ASP websites
and therefore I neet the Internet Information Service
feature from Win XP. The problem is that I have Win XP
Home Edition. Is there any way to upgrade this feature
called Internet Information Service to my Win XP Home
Edition system?
... more >>
Internet Information Service (IIS)
Posted by Soheil at 9/9/2003 11:41:37 AM
I hope u can help me. I would like to test ASP websites
and therefore I neet the Internet Information Service
feature from Win XP. The problem is that I have Win XP
Home Edition. Is there any way to upgrade this feature
called Internet Information Service to my Win XP Home
Edition system?
... more >>
SMTP Security
Posted by Rob at 9/9/2003 8:50:39 AM
I am running Windows 2000 Server and using Workgroup Mail
for my mail server. I had a spammer use my server
thorugh my SMTP. I locked down open relay in Workgroup
mail but the spammmer is going through my SMTP on IIS. I
would like to know how to properly lock down my server so
I can sen... more >>
Is there a way to "hide" sender's addresses on emails
Posted by Liza at 9/9/2003 8:14:21 AM
I ofeten send emails to large groups of people. Is there
a way I can "hide " their email addreses on the email? I
am not able to "group" them since this list may change
many times daily.... more >>
default IIS 6 uses no IUSR
Posted by Dan Foxley at 9/9/2003 7:37:59 AM
Howdy,
I find that IIS 6.0 doesn't have IUSR (Read) on the 'wwwroot' directory, but
IIS_WPG group (which doesn't include IUSR), but the web content still
displays for Anonymous Access. Is this impersonation? Is this correct?
Dan Foxley
... more >>
World wide web and FTP service stops working
Posted by Nenad at 9/9/2003 6:52:07 AM
EVENT ID: 7023
These two services are getting terminated unexpectingly
several times a day (sometimes hundreds). I have installed
SP3 but this problem still occures. I am forced to reboot
machine almost every day.
Does anyone have idea what might be wrong? IIS patches are
installed (planty... more >>
authentication problem
Posted by Akhlaq Khan at 9/8/2003 9:01:38 PM
I have IIS 5.0 on win2k server machine which is part of a domain. everything
was working fine untill today the domain users started experiencing
accessing the web server. an "authentication" window pops up and asks them
to authenticate to the web server, if they cancel it "HTTP 401.1 -
Unauthori... more >>
IIS6 Web Server Certificate Wizard Not Running
Posted by Eric Pratt at 9/8/2003 7:31:53 PM
When I click on Server Certificate under any site...new or old...the Web
Server Certificate Wizard does not start. Nothing Happens at all.
I have been trying to figure this out for way too long. I have no idea what
the problem could be.
This is a Windows 2003 Standard Server.
Does anyone ... more >>
Issuing a server certificate to enable SSL in WinXP
Posted by Michael Hill at 9/8/2003 7:25:36 PM
Hello everyone,
I'm a totally newbie to certificate and SSL.
I'd like to host a website using IIS 5 through the HTTPS
protocol, which means I need to have a server certificate
generated.
But as far as I know, WinXP does not have Certificate
Service that can issue a certicate although I ca... more >>
Automatic opening of webpage when i start the computer.
Posted by Benny at 9/8/2003 5:12:38 PM
May I know how to stop is problem. There's a opening of
this webpage sometime when i start the computer how to
stop is? Thanks... more >>
Adding Web Service Extension to IIS6
Posted by rory.plaire NO[at]SPAM co.benton.or.us at 9/8/2003 4:55:19 PM
Hi,
I can't seem to find how to do this... From a post on this group on
July 22nd:
> For example, find iisext.vbs in the System32 directory, and it will show you
> how to add/remove/modify Web Service Extensions (i.e. allow ISAPI DLL to
> execute).
(http://groups.google.com/groups?hl=en&... more >>
RSA Security Tokens
Posted by A.M at 9/8/2003 3:04:48 PM
Hi,
Is there any alternative or similar product for RSA security tokens/ Ace
server ?
Their product is good but expensive.
Any help would be appreciated,
Ali
... more >>
Import a SSL backup key (.pfx)
Posted by Steven at 9/8/2003 2:53:41 PM
Hi there,
I am trying to create a VB script to re-create many web
sites on an IIS server. My problem is for those secure
sites. I need to import the pfx key first and then assign
it to a web site. Is there anybody knows how to do it
programmatically? Maybe ADSI or WMI?
Thanks in advanc... more >>
Netscape can't view
Posted by matt at 9/8/2003 12:30:12 PM
Hello,
I locked permissions for one html page in a web site. I took out the
iusr_servername and put in a newly created user. Using IE you can enter the
credentials of the new user and view the page. Netscape doesn't allow the
user to log in. It says authentication failed and doesn't show t... more >>
Best hardware benefits for SSL Web Server
Posted by John Clayton at 9/8/2003 12:22:23 PM
Hi All,
I currently run Windows 2003 and Exchange 2003 on an AMD
AthlonXP 2000+ w/ 512MB RAM and on a 512Kbps SDSL
connection. The secure Outlook Web Access can sometimes
be pretty poky, so I was looking to upgrade the system.
There are only a handfull of users in the AD, and only a
few... more >>
Restricting access to portions of website
Posted by Doug Bitter at 9/8/2003 10:49:04 AM
I have the following
Windows 2000 Service Pack 3
IIS 5.0
We host an external website as an internal site for
employees only. The security is set up so that when
attempting to access the employee's site you must supply
username and password which is working fine. The issue is
that mana... more >>
401.3 Unauthorized: Unauthorized due to ACL on resource
Posted by michelle d. at 9/8/2003 10:37:29 AM
Please help!
This error occurs to an asp page file in iis.
HTTP Error 401
401.3 Unauthorized: Unauthorized due to ACL on resource
This error indicates that the credentials passed by the
client do not have access to the particular resource on
the server. This resource could be either the ... more >>
Hacked... All default pages replaced on server
Posted by Mike Cox at 9/8/2003 9:15:05 AM
Hi,
All the default pages on our webserver have been replaced. Something went
through and dumped bogus index.asp, index.htm, .php, default.ht, etc...
overwriting the legitimate default document. The bogus page is black with
white writing on it "HACKED BY LA VIVORA" Remindes me a lot of code r... more >>
restrict IP addresses that can access web Intranet Web site
Posted by Callie Bowdish at 9/8/2003 7:23:26 AM
We are trying to restrict the IP address access on our IIS
5 web server that sits on Windows 2000 professional
service pack 3. What is the best way to do this.
When we go to the administration tools for directory
secuirty the denied access area it is grayed out. How can
we make this acti... more >>
Backup metabase.bin
Posted by karl at 9/8/2003 7:22:17 AM
Hello,
Is there any script for schedulling metabase backup?
Thank you!!... more >>
IIS delay
Posted by Johns William at 9/8/2003 2:36:46 AM
Our company is having a website which is accessed by
clients for trading. The site was running fine. The threat
from w32blaster.worm was so potential that we applied the
patch. But after that, clients are complaining that the
site is not accessible. So what i would like to know is
that... more >>
|