Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008


all groups > iis security > september 2003 > threads for september 8 - 14, 2003

Filter by week: 1 2 3 4 5

Securing IIS 5.0
Posted by Rob at 9/14/2003 5:28:58 PM
I am running Windows 2000 Server with IIS 5.0 and I used the instructions on a document named secure IIS 5.0 checklist to stop a problem with a spammer that I had. These procedures corrected the problem but now I can't get into my website without entering a user name and password. This c...more >>

Using client certificates in ASP
Posted by languy at 9/14/2003 3:51:39 PM
Hi there, I have an ASP page, which have to connect to an SSL server that requires a client certificate, but I get the following error: Erroror Type: msxml3.dll (0x80072F0C) A certificate is required to complete client authentication /test/test.asp, line 34 Here goes my code: const DQ...more >>

[IIS 6] A summary of my strange situation
Posted by Massimo at 9/14/2003 1:47:26 PM
Here's a summary of the troubles I'm experiencing, of which I've been talked in a previous thread. Now I'm posting again explaining all about my security-related configuration, so maybe someone can help me out of this. Here's the full story. I wanted to have my websites on another drive than the...more >>

Microsoft patch 822925
Posted by Christy at 9/13/2003 11:36:24 AM
I have the Millenninum edition and my computer downloads the cumulative patch for Internet Explorer 6 #822925 over and over again. I install it over and over and it continues to download and install. I don't notice anything else happening that I would suspect that I have a virus. Can an...more >>

Redirecting to same server
Posted by David Crystal at 9/12/2003 11:18:05 PM
I have a web interface for a document management system running on IIS5. It installed itself under the Default Web Site. We have employed an SSL certificate and now users must preface the URL with 'https' rather than 'http'. Is there any way to automatically redirect users to the same website ...more >>

Unpsecified Error with ODBC Connections
Posted by David Lozzi at 9/12/2003 3:52:02 PM
This happens a lot to my databases. I store them at the root of my developing files, i.e. c:\My Projects\Proj1\database.mdb. Randomly, the security settings on this database will drop to the basic secutiry, myself and SYSTEM. I need IUSR on it so I can access it through my ASP pages... I get err...more >>

Client Certificates
Posted by Darren at 9/12/2003 12:28:13 PM
I have a web site running on IIS 5.0. I am using certificates to authorize the users for the secure part of the site. I have four workstations that when I go to install the client certificates from the CA, I get this message: The Certificate cannot be installed because of a problem wi...more >>

Group Policy effects on IIS 5
Posted by tzone at 9/12/2003 9:29:00 AM
I'm having problems getting a Form (ASP script) to run on our website. Getting this error message- "HTTP 500 Internal server error". Here is the catch if I use a domain admin account in IIS for the anonymous web account it works fine??? Also it didn't work with the default Anonymous Web Us...more >>



IIS lockdown 2.1 unattended installation
Posted by k_bashir NO[at]SPAM yahoo.com at 9/12/2003 8:42:29 AM
How do u put the custom iislockd.ini on the command line. What parameter u have to use for iislockd.exe so that it looks at the custome iislockd.ini for quiet installation. i have read the runlockdunattended.doc but some how i am missing in terms of parameters to run it in unattended....more >>

IIS 5.0-6.0 Virtual Directory Permissions Issue
Posted by raoul NO[at]SPAM keinetworks.com at 9/12/2003 8:15:04 AM
Hi, I'm trying to upgrade from a server 2000 domain to a non-domain server 2003 environment but IIS is holding me back. It seems that when I create a virtual directory on another server users cannot see the files. If I have a domain this is no problem. I have tried changing all security/p...more >>

[Windows 2003] [IIS 6] A strange access problem
Posted by Massimo at 9/12/2003 12:22:37 AM
I have a very strange problem with a Windows 2003 webserver. The machine is part of a (2003) domain which we'll call "mydomain.com", and DNS is so configured: frontend.mydomain.com -> 192.168.42.20 www -> frontend.mydomain.com test -> frontend.mydomain.com The webserver is running two site...more >>

FTP folder and permission setup questions.
Posted by Sara at 9/11/2003 11:10:18 PM
I have a FTP server at my Nt4.0 SBE, and IIS 4.0 on it. I now want to setup different folder for different company to download or upload the files to those unique folder, but I dont' want those company to see each other folder on my FTP site. Is that anyway can setup a structure on my FTP ...more >>

virus blockers
Posted by richard at 9/11/2003 8:53:47 PM
I downloaded Antology virus blocker but now have doubts about them. Does anyone know of them, & if so, are they a trusted program?...more >>

reserch
Posted by maria oates at 9/11/2003 7:03:23 PM
I wanted to know what was last weeks events that happend in microsofts software that allowed worms and viruses to enter into the system. I am writing a paper on it for school. I would be more than happy to know if there was an artical from last week that i can referance so that it would ...more >>

Certificate Services
Posted by Shirley at 9/11/2003 5:46:04 PM
I have set up a couple of webdav folders and would like the users to use SSL to keep there passwords encryped. We are a small university and of such a small use of a certificate I would rather generate my own, especially since it will mainly be used by only a few faculty. I know I need to ...more >>

New hack attempt showing in log - anyone seen this one?
Posted by Karen at 9/11/2003 5:35:37 PM
I've discovered a new hack that isn't 404'ing when they dir my drives. I don't know if they are succeeding in some way, as they are not getting a 404. They try to copy cmd.exe to cmd2.exe, but it doesn't look like that worked (cmd2.exe not on the machine anywhere). I don't have all th...more >>

Web sites on IIS
Posted by jyoti at 9/11/2003 4:58:52 PM
I am developing an web site. When user request for the site, i like to find out if the request is coming from inside our organization or out side our organization. Within the organization means within the domain. We have ip ranges within the organization. I will be using asp and IIS 5.0. ...more >>

IIS 5.0 banner
Posted by Ferdie at 9/11/2003 3:54:01 PM
Can someone point me to a link that shows how to change the IIS banner? Thanks, Ferdie ...more >>

SSL on specific pages unsuccessful
Posted by joseph at 9/11/2003 1:51:31 PM
Hello, I wanted to know if anyone could assist me in the operation of getting certain pages to be secured by SSL and then back to HTTP when leaving. I have been trying for about 3days now and I did read all the articles before posting but no luck. I have tried to change the 404.3 error ...more >>

IP address restrictions
Posted by Raigo at 9/11/2003 11:08:42 AM
In IIS security tab, it is possible to deny certain IP numbers. Is there a way to import these values from some database? For example at the moment, I read daily IIS logfiles and have every day several IP numers what try things what are restricted by URLScan (running cmd.exe etc.). Every...more >>

Need to audit / document file and directory security
Posted by jpuls NO[at]SPAM sentinel.com at 9/11/2003 9:58:21 AM
I have a web site with a few hundred pages, mainly active server pages, set up in a tree structure. Some of the files and directories allow anonymous access, some use integrated Windows authentication, some are set up for both. I'm looking for a tool which will work its way through all of thes...more >>

downloads
Posted by ken conway at 9/11/2003 9:36:31 AM
when installing download such as windows automatic update should i turn off firewall and anti virus...more >>

Privileges to run CGIs
Posted by fredrik.martzen NO[at]SPAM ibs.se at 9/11/2003 9:14:45 AM
Hi I have a webapplication running on Windows Server 2003, IIS 6.0, with CGI-dlls combined with ASP.Net components. I use ASP.Net to access files on a IBM iSeries server (IFS). I had no problems running my app on a Windows 2000 Server with IIS 5.0. I created a local user account with the s...more >>

Changing the index.htm through FTP basic authentication
Posted by Chris Sussman at 9/11/2003 6:03:50 AM
I am sure this answer is simple and staring me in the face. However, I have yet to find it. I am running IIS on a Windows 2003 server. I have web sites hosted on this server allowing access through FTP basic authentication. The users are able to get to the web directory through an FTP clie...more >>

IIS 6.0 CGI Application and Security problem
Posted by Oleksander Panchuk at 9/11/2003 1:42:47 AM
We tried to migrate from the Linux platform to the Windows. We used perl scripts for public access: quizzes and etc. But now, after migrate, Windows Server demands the authentication when user try to exec any CGI script. Why? Thanks, for your answer....more >>

Last Network Security Patch
Posted by Chris at 9/10/2003 8:04:04 PM
I received an email with "Last Network Security Patch" in the subject. It has an attachment and says it is from Microsoft Corporation Internet Security Division <irvepgs_608521@support.msdn.com>. The email says it is a security patch. Is this really for MS or is this a virus? Thanks...more >>

IIS Logs
Posted by Joseph at 9/10/2003 7:38:48 PM
I was viewing my logs and saw this and do not know what it is. Does anyone else know? 150 winnt/system32/cmd.exe requested Thanks Joseph...more >>

critical updates
Posted by bridget at 9/10/2003 6:29:20 PM
I have been attempting to download the critical updates for 5 days.... it stalls and fails. it stops at the last security download for winddows xp 819696. tried to e- mail microsoft... what a joke. i am frustrated and do not know how to proceed....more >>

microsoft exployer
Posted by Joy at 9/10/2003 6:13:24 PM
I am not sure I am in the correct place or not, but I downloaded microsoft exployer over my already internet explorer and now I do not get a security scan, the pictures are foggy nothing works like it use too. How can I uninstall internet explorer and reinstall it so I can have my email a...more >>

Hey windows lusers, if M$ is so secure, why does it hide behind LINUX?
Posted by Evil_penguin at 9/10/2003 5:41:35 PM
It's funny how billy can brag and ramble on and on about the =0A= securiy of winblows and how much daddy LINUX stinks, but if =0A= that's the case, why did M$ had to hide behing LINUX during the =0A= last DDoS? =0A= =0A= Hey, you're entiled to know: =0A= http://news.zdnet.co.uk/software/linu...more >>

Peculiar problem accessing remote share.
Posted by B. B. at 9/10/2003 1:08:16 PM
Any help on this matter is appreciated. Given: * Win2k server w/ IIS v5.0 (stand-alone workgroup) * Another Win2k server with shares. Also stand-alone workgroup. The problem is NOT with the permission on the file- sharing server. Here is what I have narrowed it down to: * If ...more >>

Microsoft.exe
Posted by Greg Olgin at 9/10/2003 12:43:24 PM
Folks, This is the second day in a row I have received this in my e-mail. It has 13 different viruses packed into it. Is there any way that it can be stopped from being set all over the place?...more >>

CGI Executable and IIS 6
Posted by Ronald van der Pas at 9/10/2003 12:27:40 PM
Hi, We recently upgraded to W2003 and IIS6. In our sites we use cgi executables. They write in some directories. Under IIS 5 that was no problem, but under IIS 6 we seem to have no write-acces. Although the userrights for IUSER_xxx are correct. What can be wrong? Greetings, Ronald van d...more >>

Authentication issue
Posted by ALF at 9/10/2003 11:35:02 AM
Hi All, Im having an issue with an intranet site we have. Users in a different forest get a page cannot be displayed error. The packets returned to the user are access denied. The users can do a ping and a net view on the web server without issue. In fact any request is fulfilled axcept f...more >>

Require SSL settings slows connection to Web Server
Posted by Bruce Forbes at 9/10/2003 11:12:15 AM
We have a web site that we have the "Requires Secure Channel" setting selected. I noticed it is very slow (20- 30 seconds) before you see the certificate request window. When I remove teh SSL requirement for this site and then open the browser, still using HTTPS, the window pops up immedi...more >>

Configuring IWAM_MachineName for COM Interop
Posted by Christopher Pragash at 9/10/2003 9:48:18 AM
Hello all, I'm trying to configure an ASP Web Application under IIS 5.0, 'Medium' application protection for COM Interop. I guess the IWAM_Machinename has to be explicitly granted Read/Write Permissions to some folders. Can anyone please tell me what folders these are or where I could find som...more >>

Blocking popups
Posted by Annie L. at 9/10/2003 9:46:51 AM
I keep getting popups for pornography and other offensive things and I don't want them on my computer! This started today, and I want it to stop! I don't know how to block these things. Please help!...more >>

user can logon with a blank account and password
Posted by m at 9/10/2003 6:51:42 AM
Hello, We have an intranet website that allow for only employees to logon and view the contents. We enabled the SSL, and Logon with password and an account, but somehow the when I test it I can logon without typing any logon name or password, but if I type a incorrect logon name then i...more >>

an unexpected error (0x1A8) occured while getting the certificate template list
Posted by Jon Munday at 9/10/2003 6:44:18 AM
When Requesting a server sertificate using a form I get the following error: An unexpected error (0x1A8) occured while getting the certificate template list Any Ideas ?? Thanks Jon...more >>

IIS6 Hosting - Level Of Effort
Posted by bill22310 NO[at]SPAM hotmail.com at 9/10/2003 6:36:45 AM
My wife and I are developing an online directory and calendaring application for our church web site. We have lots of development experience but no hosting experience. We are going to have about 2000 to 3000 high res jpeg and low res jpeg pics. This is about 3 to 4 gig of data. This pushes us t...more >>

IIS and J2EE
Posted by Gareth at 9/10/2003 6:29:41 AM
I would urgently like to know if IIS can do the job of apache Tomcat. Any help would be much appreciated ...more >>

Admin rights required for .Net dvlpment...surely not?
Posted by Aaron at 9/9/2003 11:05:09 PM
I'm setting up an iis5 server in a university setting to allow .net project creation from VS .Net. I have the 1.1 framework installed as well as fp extensions 2002. Created a folder as an application in Internet Services mgr & virtual directory which points to file system folder. In the frontpag...more >>

Autocomplete problem
Posted by CM at 9/9/2003 10:43:19 PM
I have a vendor web program host on my company web site, it allows user input the UserID and Password to get into their system. However, we found that client browser has recorded the UserID and Password on their windows, it should be input every time when access this program. Does anyone k...more >>

dialog box for Integrated Windows Authentication
Posted by samson at 9/9/2003 7:28:55 PM
I have an Intranet app (asp.net) running on IIS5 and have Integrated Windows Authentication turned on (all other auth options are turned off). I'm trying to let users to log in seamlessly, but it brings up a dialog box for username, password, and domain name. And the interesting thing is...more >>

Outlook Express
Posted by Vivian Nash at 9/9/2003 6:09:04 PM
I probably do not have the right group so if you can direct me in the proper channel I would appreciate it. My problem is that Outlook Express deletes every attachment that is sent to me and some of them are important and I DO NOT want deleted. Who do I contact and how can I get it stopp...more >>

Is there a way to set differing permissions on folders within a ftpsite
Posted by Doyle Collings at 9/9/2003 4:13:00 PM
It appears that I can only set the permissions for the whole ftp site. I would like to give individual user access to each folder. Am I asking to much? Doyle Collings Network Administrator City of Logan dcollings@loganutah.org...more >>

Win2000 Certificate Services Problem
Posted by Amanda at 9/9/2003 2:20:37 PM
I am trying to implement a certificate infrastructure for VPN connections using L2TP/IPSEC VPN connections. I got this working successfully on a Windows 2003 server in a test environment. On my live network I installed Certificate Services on my Windows 2000 SBS server as an Enterprise Authori...more >>

Internet Information Service (IIS)
Posted by Soheil at 9/9/2003 11:41:44 AM
I hope u can help me. I would like to test ASP websites and therefore I neet the Internet Information Service feature from Win XP. The problem is that I have Win XP Home Edition. Is there any way to upgrade this feature called Internet Information Service to my Win XP Home Edition system? ...more >>

Internet Information Service (IIS)
Posted by Soheil at 9/9/2003 11:41:37 AM
I hope u can help me. I would like to test ASP websites and therefore I neet the Internet Information Service feature from Win XP. The problem is that I have Win XP Home Edition. Is there any way to upgrade this feature called Internet Information Service to my Win XP Home Edition system? ...more >>

SMTP Security
Posted by Rob at 9/9/2003 8:50:39 AM
I am running Windows 2000 Server and using Workgroup Mail for my mail server. I had a spammer use my server thorugh my SMTP. I locked down open relay in Workgroup mail but the spammmer is going through my SMTP on IIS. I would like to know how to properly lock down my server so I can sen...more >>

Is there a way to "hide" sender's addresses on emails
Posted by Liza at 9/9/2003 8:14:21 AM
I ofeten send emails to large groups of people. Is there a way I can "hide " their email addreses on the email? I am not able to "group" them since this list may change many times daily....more >>

default IIS 6 uses no IUSR
Posted by Dan Foxley at 9/9/2003 7:37:59 AM
Howdy, I find that IIS 6.0 doesn't have IUSR (Read) on the 'wwwroot' directory, but IIS_WPG group (which doesn't include IUSR), but the web content still displays for Anonymous Access. Is this impersonation? Is this correct? Dan Foxley ...more >>

World wide web and FTP service stops working
Posted by Nenad at 9/9/2003 6:52:07 AM
EVENT ID: 7023 These two services are getting terminated unexpectingly several times a day (sometimes hundreds). I have installed SP3 but this problem still occures. I am forced to reboot machine almost every day. Does anyone have idea what might be wrong? IIS patches are installed (planty...more >>

authentication problem
Posted by Akhlaq Khan at 9/8/2003 9:01:38 PM
I have IIS 5.0 on win2k server machine which is part of a domain. everything was working fine untill today the domain users started experiencing accessing the web server. an "authentication" window pops up and asks them to authenticate to the web server, if they cancel it "HTTP 401.1 - Unauthori...more >>

IIS6 Web Server Certificate Wizard Not Running
Posted by Eric Pratt at 9/8/2003 7:31:53 PM
When I click on Server Certificate under any site...new or old...the Web Server Certificate Wizard does not start. Nothing Happens at all. I have been trying to figure this out for way too long. I have no idea what the problem could be. This is a Windows 2003 Standard Server. Does anyone ...more >>

Issuing a server certificate to enable SSL in WinXP
Posted by Michael Hill at 9/8/2003 7:25:36 PM
Hello everyone, I'm a totally newbie to certificate and SSL. I'd like to host a website using IIS 5 through the HTTPS protocol, which means I need to have a server certificate generated. But as far as I know, WinXP does not have Certificate Service that can issue a certicate although I ca...more >>

Automatic opening of webpage when i start the computer.
Posted by Benny at 9/8/2003 5:12:38 PM
May I know how to stop is problem. There's a opening of this webpage sometime when i start the computer how to stop is? Thanks...more >>

Adding Web Service Extension to IIS6
Posted by rory.plaire NO[at]SPAM co.benton.or.us at 9/8/2003 4:55:19 PM
Hi, I can't seem to find how to do this... From a post on this group on July 22nd: > For example, find iisext.vbs in the System32 directory, and it will show you > how to add/remove/modify Web Service Extensions (i.e. allow ISAPI DLL to > execute). (http://groups.google.com/groups?hl=en&...more >>

RSA Security Tokens
Posted by A.M at 9/8/2003 3:04:48 PM
Hi, Is there any alternative or similar product for RSA security tokens/ Ace server ? Their product is good but expensive. Any help would be appreciated, Ali ...more >>

Import a SSL backup key (.pfx)
Posted by Steven at 9/8/2003 2:53:41 PM
Hi there, I am trying to create a VB script to re-create many web sites on an IIS server. My problem is for those secure sites. I need to import the pfx key first and then assign it to a web site. Is there anybody knows how to do it programmatically? Maybe ADSI or WMI? Thanks in advanc...more >>

Netscape can't view
Posted by matt at 9/8/2003 12:30:12 PM
Hello, I locked permissions for one html page in a web site. I took out the iusr_servername and put in a newly created user. Using IE you can enter the credentials of the new user and view the page. Netscape doesn't allow the user to log in. It says authentication failed and doesn't show t...more >>

Best hardware benefits for SSL Web Server
Posted by John Clayton at 9/8/2003 12:22:23 PM
Hi All, I currently run Windows 2003 and Exchange 2003 on an AMD AthlonXP 2000+ w/ 512MB RAM and on a 512Kbps SDSL connection. The secure Outlook Web Access can sometimes be pretty poky, so I was looking to upgrade the system. There are only a handfull of users in the AD, and only a few...more >>

Restricting access to portions of website
Posted by Doug Bitter at 9/8/2003 10:49:04 AM
I have the following Windows 2000 Service Pack 3 IIS 5.0 We host an external website as an internal site for employees only. The security is set up so that when attempting to access the employee's site you must supply username and password which is working fine. The issue is that mana...more >>

401.3 Unauthorized: Unauthorized due to ACL on resource
Posted by michelle d. at 9/8/2003 10:37:29 AM
Please help! This error occurs to an asp page file in iis. HTTP Error 401 401.3 Unauthorized: Unauthorized due to ACL on resource This error indicates that the credentials passed by the client do not have access to the particular resource on the server. This resource could be either the ...more >>

Hacked... All default pages replaced on server
Posted by Mike Cox at 9/8/2003 9:15:05 AM
Hi, All the default pages on our webserver have been replaced. Something went through and dumped bogus index.asp, index.htm, .php, default.ht, etc... overwriting the legitimate default document. The bogus page is black with white writing on it "HACKED BY LA VIVORA" Remindes me a lot of code r...more >>

restrict IP addresses that can access web Intranet Web site
Posted by Callie Bowdish at 9/8/2003 7:23:26 AM
We are trying to restrict the IP address access on our IIS 5 web server that sits on Windows 2000 professional service pack 3. What is the best way to do this. When we go to the administration tools for directory secuirty the denied access area it is grayed out. How can we make this acti...more >>

Backup metabase.bin
Posted by karl at 9/8/2003 7:22:17 AM
Hello, Is there any script for schedulling metabase backup? Thank you!!...more >>

IIS delay
Posted by Johns William at 9/8/2003 2:36:46 AM
Our company is having a website which is accessed by clients for trading. The site was running fine. The threat from w32blaster.worm was so potential that we applied the patch. But after that, clients are complaining that the site is not accessible. So what i would like to know is that...more >>


DevelopmentNow Blog