Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008


all groups > iis security > october 2004

Filter by week: 1 2 3 4 5

Website Access for Internet User to Manage Their Content
Posted by bits on glass at 10/31/2004 4:12:12 PM
I need to find a good reference for setting up access for content owners whose content I want to place on a Windows 2003 server / IIS 6.0 which would be in a standalone configuration on my perimeter network. I want to set up multiple sites using a different IP per site. Each site would have ...more >>

Remove Content-Location header in IIS 6.0
Posted by Jacob Lane, MCP at 10/30/2004 6:07:55 PM
All, [ For background with the security concern surrounding the Content-Location tag in the HTTP header in multiple flavors of IIS, read: http://support.microsoft.com/?id=218180. ] As the article above indicates, there are ways to alter this tag in IIS 4.0 and 5.0 but until recently, the...more >>

IIS 6.0 can't serve multiple .bat files - 404 error
Posted by Steve Ricketts at 10/30/2004 9:41:22 AM
We have an application that creates potentially 1,000's of unique .bat files in a Virtual Directory based on user and site information. When the .asp is called, the File Scripting Object creates a .bat file based on information about the user and places it in the physical location referenced by ...more >>

Exchange with ISA
Posted by bengt at 10/30/2004 2:33:02 AM
Microsoft recommends a scenario where you put ISA server in a DMZ and publish OWA from an Exchange Front-end server on the inside. Looking at it strictly from a security point of view, is there any diffence in publishing the Back-end server instead and skip the Front-end server? I meen if you ...more >>

Exchange OWA with ISA
Posted by bej at 10/30/2004 2:32:01 AM
Microsoft recommends a scenario where you put ISA server in a DMZ and publish OWA from an Exchange Front-end server on the inside. Looking at it strictly from a security point of view, is there any diffence in publishing the Back-end server instead and skip the Front-end server? I meen if you ...more >>

problem with SSL certificate
Posted by Vassilis at 10/29/2004 4:41:43 PM
w2k3, exchange2k3 sp1 So far i was using a certificate with wrong common name from an other authority. OWA SSL was working fine but in order for RPC to work i needed a certificate with the same common name as the DNS name. So from another win2k3 server with a certification authority installed ...more >>

Redirecting users to Https
Posted by hpets3526 NO[at]SPAM yahoo.com at 10/29/2004 12:58:19 PM
I am redirecting users to a secure channel using a simple page containing a meta refresh tag. I am using this page as a custom error page for the secure channel error so when users type www.anything.com they get the error which automatically redirects them to the right page using https. I have ...more >>

Loosing Windows Auth Credentials Over Multiple Web Services
Posted by Ciaran McAuliffe at 10/28/2004 9:43:02 AM
Hey, I am not to sure if this is the right group so please excuse me if it is not. I have a bit of a tricky problem, here is a quick overview. I have a website which connects to a webservice, this web service is a front for access to the Reporting Services Web Service, the middle web servic...more >>



How to move the Inetpub folder into different drive
Posted by S RAMESH at 10/28/2004 3:15:04 AM
Hi friend, I'm using Windows 2000 Advanced Server. And IIS Service enabled with SMTP, FTP and WWW. Some security reason I need to move Inetpub folder into different driver on the server..Can you please guide me to resolve my below query?, 1) What is the secure way to move the Inetpub fo...more >>

How to move the Inetpub folder to different directory
Posted by S RAMESH at 10/28/2004 3:09:09 AM
Hi friend, I'm using Windows 2000 Advanced Server and IIS Service enabled (SMTP, FTP and WWW). Suddenly I found C: driver occupied more space and FTP & Mailroot folder occuped lot of files...! Some spam E-mails and other files...! Again and again files loaded even I delete the file in the...more >>

HTTP 401.3 - Access denied by ACL on resource .exe
Posted by Mary at 10/27/2004 5:57:34 PM
I have a problem with my cluster server (windows 2000) that host an IIS virtual server. In the autentication method I set the anonimous ad I set a domani user who is member of local administrator group. When I try to call a .exe application from a browser, the server prompts me for credential...more >>

DLLHOST!!!
Posted by Carlos Henrique at 10/27/2004 5:10:42 PM
The DLLHOST.EXE on my IIS 5.0 is usung almost 1GB of mamory.... and it is increasing. Is it normal?? What is happening on mu server??? Helpe me Carlos Henrique Rio de Janeiro - BRASIL ...more >>

W3C Log Format
Posted by Carlos Henrique at 10/27/2004 4:51:24 PM
Hi people, I set the log format of my IIS 5 Server, and the time of the logs are GMT, but here in Brasil is GMT-3!! How can I correct it?? Can set anything on the log format to change it? I dont want to use MS IIS log format. All my logs are with 3 hours wrong!! Help me!! Carlos Henriqu...more >>

IE prompts for username, Mozilla does not!
Posted by Mark at 10/27/2004 1:00:39 PM
Hi - having just setup a new server, with SSL - and a new virtual directory with a site sitting behind it (in .net) - I find when accessing the site using IE, I am prompted with a popup box asking for the username and password - if I use Firefox or Mozilla - I can freely use the site. Is ther...more >>

Basic Auth Requires Logon Credentials
Posted by SCukier at 10/27/2004 12:25:01 PM
I have enabled Basic Authentication yet when a user visits the web-site logon credentials are still required. Any assistance would be appreciated. Thanks -- SC...more >>

Granting Permissions to Manage Virtual Directories
Posted by at 10/27/2004 9:23:35 AM
Hello, I'd like to connect to a remote server and add/configure virtual directories in IIS using the Computer Management MMC snap-in. Are there certain [minimum] permissions that my systems administrator could assign my Windows domain account to accomplish this without giving me Administrat...more >>

IIS6 - Virtual Directory to URL share, authentication problems.
Posted by Bob Eadie at 10/26/2004 7:05:56 PM
I have IIS6 running on a Win2003 box within a mixed Win2000/Win2003 domain. I have set up a Virtual Directory set up to a remote share, and selected 'pass users credentials' to authenticate, as some users have more access than others to various folders within the share. Anonymous is also sele...more >>

IIS 5.0 not accepting multipart/form-data
Posted by CrazzyWebMonkey at 10/26/2004 3:15:04 PM
I have 3 IIS server set up (Development, Test, and Production), and each of them behave differently when submitting a multipart/form-data form. The Development server (using http://localhost/) works just fine, the file is uploaded, and the rest of the fields are set just fine. The Test ser...more >>

Mac & Unix permissions
Posted by Chris at 10/26/2004 1:21:02 PM
I have ftp running with anon logins disabled. When I log in from the outside of our network I can post files fine using msdos machines. When I log in from the outside with unix or mac machines, I get read only and cannot post files. There has to be a simple permission setting that I am not ...more >>

Problem with SSL using IIS5
Posted by gc at 10/26/2004 11:43:14 AM
I created certificate and installed it on my server. I can using browser to access the web server using HTTPS. But when I tried to use my app to access my web server I got following message: "alert (Level fatal, Description: Bad Certificate" I guess this is because that my certificate is not t...more >>

Parent Paths
Posted by news.microsoft.com at 10/26/2004 11:26:16 AM
If I've enabled Parent Paths (PP) in IIS, but have installed the URL Filter and disallowed ".." and "../" within links, am I covered from the vulnerabilities of PP's? This allows me to use PP's in #Include statements, but doesn't allow visitors to use PP's in their links to access directories ...more >>

fld file
Posted by Narongsak M. at 10/26/2004 11:19:51 AM
Hi all, How to open file type .fld? Please help ...more >>

IIS6 - Anonymous Login browsing of website not working..
Posted by Graham Tapscott at 10/26/2004 10:15:04 AM
Seen alot asked about this problem but very few answers. Have an IIS6 webserver that is bringing up a dialog box when users try to access any webpage. If I cancel out I get HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials. Internet Information Services (IIS) ...more >>

What happened to good old proxy server?
Posted by Brian at 10/26/2004 8:29:02 AM
we recently upgraded to Server '03, and I am having a heck of a time finding where to set up proxy settings for authorization and site content limitation. Also want to log, by user, where and when they go out. Any ideas? Please???!!! -- Brian Deleone Paramedic\IT Slave North Mecklenbur...more >>

IIS 6.0 Security - NTFS, Terminal & Windows Integrated
Posted by Amihai Bareket at 10/25/2004 8:25:30 PM
I'm having a problem when trying to configure security for web sites on IIS 6.0, which will be accessed from Internet Explorer through Windows Server 2003 Terminal Services. This is what I've done - Created a security groups on Active Directory (Win2k3 - Domain local) Created a Directory and ...more >>

Server.CreateObject Access Error
Posted by Naveen at 10/25/2004 1:11:05 PM
Hi, I upgraded my PC to windows 2003. And I have this issue i can not create the object I am getting the Access permission error. I was reading some articals and i found that I need to grant access to the Iuser_Macname but I am not using the ananymous access. I have basic authentication ...more >>

Can I run IIS and Symantec/Norton Internet Security 2005 on the same machine?
Posted by groups NO[at]SPAM harrisconsultinggroup.com at 10/25/2004 1:06:16 PM
This is a reworked-repost of what I posted yesterday, plus some extra info that I have gained in the last 24 hours with the help of Ken (Thank you). The problem is that I have just installed Symantec/Norton Internet Security 2005 and it has locked up my web services. I have tried to switch ...more >>

How does changing the machine name affect SSL certificates?
Posted by Stu at 10/24/2004 10:43:51 PM
Hi, I am having mail server problems that (apparently) require me to change the name of the machine to a fully qualified domain name. I have a number of sites using SSL certificates - will these be affected if I change the name of the computer hosting them? Thanks in advance, Stu ...more >>

Installed Symantec/Norton Internet Security 2005 and can no longer run IIS
Posted by groups NO[at]SPAM harrisconsultinggroup.com at 10/24/2004 2:12:34 PM
Please help... I have just installed Symantec/Norton Internet Security 2005 and it has locked up my web services, specifically, I cannot start IIS (from Administrative tools). When I attempt to look at any local web site (http://localhost...) IE shows in the status bar that it is trying to...more >>

"Hidden" HTTP 401 Errors
Posted by Eric Kassan at 10/23/2004 10:34:47 AM
My Windows-security based (no-anonymous-access) website (IIS 5, Windows 2000) appears to work fine- no user complaints about lack of access. But when I review my web logs, I see many, many 401 errors where, apparently the browser did not send the authentication information. When the browser ...more >>

Internal server error 500
Posted by gc at 10/22/2004 2:53:31 PM
Can anybody tell me what cause this problem? HTTP 500 - Internal server error Internet Explorer Thanks. GC ...more >>

IUSR Account from another machine Logging into my server
Posted by KramerCat at 10/22/2004 2:33:11 PM
Hello, The IUSR account from another machine is logging into 3 different servers. Is this right? How does this happen? All three logons occurred at the exact same time. Thank you, Kramer...more >>

500.100 Error
Posted by Everton at 10/22/2004 1:09:03 PM
I am running this page on a win2000 server its a survey application. Lately, i've not been able to run some asp applications on this server and keep getting this type of error? ANy ideas of where to look. THis is one error. The page cannot be displayed There is a problem with the page ...more >>

Authentication question
Posted by Nikolay Petrov at 10/22/2004 9:36:26 AM
Can I authenticate users of my ASP .NET apps, using their windows credentials, but using a SQL db. Let me explain a little more. I have an Windows XP station where i run my ASP .NET apps. I wish users to authenticate them using their current windows usernames and passwords. I have stored my u...more >>

How enable "Server Certificate..." button on "Directory Security"
Posted by Stan Reckard at 10/22/2004 9:07:01 AM
I am using Windows 2000 (not Server) as my development machine. I want to use ASP.NET to communicate with a C++/gSOAP 2.7 server via SSL that requires client certificates. I run both client and server on my development box. How can I enable the "Server Certificate..." button on the "Directo...more >>

SSL Problem
Posted by JoJoBinkus at 10/22/2004 6:53:05 AM
Hi, I recently installed an SSL certificate (from Thawte) on an IIS6 box with 1 default web site. Although the cert works, on -some- users PC's they receive a "CLIENT AUTHENTICATION" pop-up dialog box asking them to select their cert they want to use...and there are no certs listed for t...more >>

Renaming a Server/ IIS Question
Posted by JoJoBinkus at 10/22/2004 6:47:04 AM
I have a windows 2003 server. Its running IIS6. I recently renamed it from OLDSERVERNAME to NEWSERVERNAME... But I noticed in the users/groups area that the IIS anonymous user is still named: IUSR_OLDSERVERNAME Will this cause any problems? Should I fix it? If so, what's the right way ...more >>

w2003 IIS permissions, wheres best?
Posted by JD at 10/21/2004 6:55:42 PM
Im using "host headers" to run multiple websites and Frontpage to author. Frontpage creates a sub-folder in Default Websites but I also create a new website for the host header which appears on the same dir level as Default Website in IIS. Q. If I want to restrict access to authenticated use...more >>

http 401.1
Posted by Fred at 10/21/2004 5:49:02 PM
Just installed windows update to windows server 2003. Can no longer access web pages without 401.1 error. Using IUSR_server as my internet guest account. Have set Enable Anonymous Access Under directory security. IUSR has read access. NTFS security is set to Read and Execute. But Still n...more >>

IIS 6.0 exe/dll download from /bin directory
Posted by marko at 10/21/2004 4:07:10 PM
I have added MIME types for .exe and .dll's that are placed in one virtual directory. It is called /bin (it has nothing to do with ASP.NET applications). I just want to enable *downloads* of exe and dll files from that directory, and I can't. From other directories there are no problems, but fro...more >>

Impersonate NETWORK SERVICE?
Posted by feelthebreeze NO[at]SPAM gmail.com at 10/20/2004 6:47:59 PM
Hi, I have an app pool running as a domain user but I need to make a certain call in the context of NT AUTHORITY\NETWORK SERVICE. I've tried using LogonUser() but I'm not sure if it's possible. Is there anyway to temporarily change from a domain account to the network service account? Th...more >>

Problem with Server certificate for SSL from MCS 2.0
Posted by Gearhead at 10/20/2004 12:39:07 PM
I just setup a webserver using IIS 5.0 on W2k SP4 to test SSL. I deployed the SSL succesfully, but when I try to browse the site from IE I get a Security Alert popup which states: "The security certificate was issued by a company you have not chosen to trust. View the certificate to determi...more >>

Opening VSS database from ASP
Posted by vs0562 at 10/20/2004 12:27:03 PM
We have 2 VSS databases. First is located on the same server as IIS and second is on another machine. While I can open the first one from the ASP using the following script: oVSSDb.Open <srcinipath>, <UID>, <password> trying the same thing on the second throws the following error: Error Typ...more >>

Problem accepting server certificate made with MCS 2.0
Posted by Gearhead at 10/20/2004 12:13:06 PM
I just setup a test webserver with SSL using a server certificate from Microsoft Certificate Services. When I browse the site in IE, I get a Security Alert that states: "The security certificate was issued by a company you have not chosen to trust. View the certificate to determine wheteher...more >>

Problem trusting server certificate from MCS 2.0
Posted by Gearhead at 10/20/2004 12:01:07 PM
I just setup SSL on a test webserver using IIS 5.0 running W2k SP4. Whenever I browse the site in IE, I get a Security alert stating "The security certificate was issued by a company that you have not chosen to trust. View the certificate to determine whether you want to trust the certifyin...more >>

HTTPS not working from some clients
Posted by Dom at 10/20/2004 11:07:04 AM
Hello ! I use Windows Server Certificates. Enabled the "require secure channel" option for a virtual directory. From some clients i can access the directory. A message pops up in IE, saying that the certificate wasn't issued by a trusted ca. Then I click yes and it works fine. O.K. so far. ...more >>

Changing .asp extension
Posted by P Jones at 10/20/2004 11:00:06 AM
Hi there, Can someone remind me how to make files with extensions other than .asp execute as .asp files do? I remember doing this by adding an entry to the registry years back, but I can't find the place to do this. Years back, by adding the extension to the registry I was able to make IIS...more >>

Certificates
Posted by JazzFan at 10/20/2004 10:23:02 AM
Is there a difference between the standard web client/server certificates and server-server certificates? Our customer has asked for server-server and wants to know if this is different from generating public/private keys in the standard way for web connections. Thanks...more >>

SQL, ASP .NET, VB .NET Authentication
Posted by Nikolay Petrov at 10/19/2004 4:29:08 PM
Is it possible to authenticate user using a SQL database, containing users and passwords? What I want to achive is: I have as SQL database containig data for my app. This database also contains usernames, passwords and rights which are specific for my app. Also I have a middle tier WebService...more >>

Multiple Identities for one site.
Posted by Kevin Antel at 10/19/2004 1:46:14 PM
We have an application running on one website. We want to co-brand it for multiple names. Is it possible to put multiple SSL identities on one site? ie: http://www.site1.com http://www.site2.com http://www.site3.com https://secure.site1.com https://secure.site2.com https://secure.site...more >>


DevelopmentNow Blog