Groups | Blog | Home


Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008


all groups > iis security > october 2004 > threads for october 8 - 14, 2004

Filter by week: 1 2 3 4 5

Windows 2003 server - FTP connection using Fetch(Mac) problem
Posted by Snappy at 10/14/2004 11:57:03 PM
Hi guys, I have a box running Windows 2003 Server (with ISA 2000 server). Some of the collegues that want to connect have MAC PCs. They receive a conection error. I use WS_FTP & Internet explorer to connect without any problems. I checked with Passive & active FTP but did not get it.. ...more >>

How to test a SSL website?
Posted by Joachim Engel at 10/14/2004 4:57:29 PM
Hi, we want to test a SSL Web-Application without buying a certificate. Is that possible? What is to do? Kind regards Joachim Engel. ...more >>

IIS 6 CreateObject premissions issue
Posted by Matthew Nichols at 10/14/2004 4:56:15 PM
First off I apologize for the crucial piece of information I will doubtlessly leave out (don't know what it is but I am sure there will be something) or the completely obvious answer that I have missed. We have a system that has been running on Windows 2000 Server composed of SQL / COM+ / A...more >>

Authenticate against all trusted domains... in IIS 6?
Posted by tec-jon at 10/14/2004 9:37:04 AM
I have a parent/child domain that I would like to have a basic authentication website on. They are both 2003 native domains. We would like our users to not have to use UPN or domain\user login formats. We have done a bit of research and came across the following article: http://support.micros...more >>

Remove FTP Anonymous Login Prompt
Posted by StevieD at 10/14/2004 3:47:02 AM
We login to our FTP site via Internet Explorer, using account usernames & passwords to login. When I go to open the files in the directory I'm prompted with an FTP login prompt, either logging on as anonymous or a user. How do I remove this prompt ? Because once I'm authenticated using my F...more >>

Anonymous Access denied
Posted by Nejmos Saqeb at 10/13/2004 3:53:54 PM
Hi, I have site hosted under IIS 5.0 running on Windows 2000 Server w/SP4. The site has a anonymous access allowed and "Everyone" access from ACL. Some of the users are able to access the site whereas some dont. What may be wrong? Regards Nejmos Saqeb nejmos.saqib@softech.us ...more >>

Generate OWN SSL w/XP Pro
Posted by Linking at 10/13/2004 2:27:41 PM
Hello, I understand I need to first go through and request the certificate and save it to my hard drive. From there, it gets shaky. I've tried using my computer name in the browser, adding on the /certsrv at the end, but the Certificate Server does not come up. I looked in the "Add/Remov...more >>

SSL Client Authentication
Posted by Mark W. at 10/13/2004 2:24:36 PM
I'm trying to establish SSL connectivity with an IIS server that requires client authentication. I noticed in the SSL handshake that the certificate_authorities component of the handshake is empty. Based on the way I read the SSL protocol, I was expecting that this field would contain a ...more >>



create own certificate for SSL
Posted by John Smith at 10/13/2004 12:20:44 PM
Hi there, Pretty simple question, I want to setup a mail server at home, and would like to install a certificate on it for security. But, i dont want to buy one, as its only really for me, and afew friends. Is there a way to create your own certificates for IIS? im wanting to play around wi...more >>

SSL Security
Posted by Ishmealm at 10/13/2004 9:34:15 AM
Hi, This is just a question and not a problem. I have a site that has an SSL cert. Under this site I probably have 50- 60 virtual directories. At the site level I do not have SSL enabled, I do this at a directory label. I noticed the other day that even directories that I have not enabled ...more >>

URLScan v2.5
Posted by zaheer mohammad at 10/13/2004 8:41:05 AM
How can I use multiple different urlscan.ini files for different web instances. I can do a wildcard application mapping at a websites level or selectively attached a urlscan extension at site-by-site, but I am still dealing with the same configuration setting file. Can I associate individu...more >>

IP Restrictions Greyed Out
Posted by Mike C at 10/12/2004 6:55:06 PM
Working with someone remotely on IIS 5.0 server. Cannot get server to connect from off the LAN. IP routing, firewall, etc etc seems right. Asked user to check IP Restrictions to see if IIS is dropping packets on purpose. Button to edit Restrictions is greyed out. On related note, is t...more >>

pwd changed, but old one still works for 30 minutes
Posted by Matt Norton at 10/12/2004 1:02:46 PM
Any idea on how I can force a password change (IIS 5.0 on Win2k Standalone Server) to take place immediately? Right now I have my site set so that people can change their own windows password (I use windows accounts, authenticated over SSL), but the old pwd still works for between 5 and 30 minu...more >>

NTLM auth fails with websites using four part FQDN Host Header nam
Posted by dwenwa NO[at]SPAM companyabc.com at 10/12/2004 6:49:10 AM
Hi, I have encountered a unique problem with IIS6, Integrated Authentication (IWA) and Host Headers. I manage a web farm of two production servers behind a content switch that host ASP.NET applications. I have a particular situation where NTLM authentication fails where the URL is "http...more >>

Canonicalization issue in Microsoft IIS web server with ASP.NET
Posted by Paul Cyr at 10/12/2004 5:29:10 AM
I can't believe this newsgroup is not discussing this vunerability. This is a major flaw and we need a patch from Microsoft ASAP. This affects many Microsoft products. Event Analysis: By sending a specially crafted URL, application level authentication can be bypassed, potentially exposing ...more >>

iRemoving Anonymous FTP from directory prevents write access by an
Posted by David Quinn at 10/12/2004 3:43:09 AM
Hi We are using IIS 6.0 and have a slight problem. When we remove anonymous ftp access from web directory, it prevents anyone writing to the directory. The only way we seem to be able to get write access for anyone is to re-enable anonymous ftp. Any suggestions? Thanks Dave Quinn....more >>

Removing Anonymous FTP from directory prevents write access by any
Posted by Dave Quinn at 10/12/2004 3:41:03 AM
Hi We are using IIS 6.0 and have a slight problem. When we remove anonymous ftp access from web directory, it prevents anyone writing to the directory. The only way we seem to be able to get write access for anyone is to re-enable anonymous ftp. Any suggestions? Thanks Dave Quinn....more >>

Problem after iislockdown tool and urlscan
Posted by at 10/11/2004 12:54:07 PM
Hi i have installed IIS Lockdown tool and Urlscan and after i have unistall both! Now when i try to access to some page of my webserver a error appared : HTTP Error 403 403.1 Forbidden: Execute Access Forbidden This error can be caused if you try to execute a CGI, ISAPI, or other executa...more >>

Connect to IIS from another Pc
Posted by Pupo at 10/11/2004 11:53:07 AM
Hi I want to connect from all my Pc (Windows Xp pro Sp1/Sp2) to iis of my new server. I open iis controll panel and on local computer i select connect... and write server name. Before i was able to view all folder now if i try to connect to my new server only domain administrator are able to vi...more >>

Password protecting emails
Posted by Don at 10/11/2004 11:23:03 AM
I was asked by the government to password protect our email. When I looked into this it said to have security certificate in IIS installed. What I am looking for is to setup our exchange server 2000 so that the users on the network can send password protected email. Does anyone know of where t...more >>

Security Certificate
Posted by Don at 10/11/2004 8:42:19 AM
I was asked to password protect our email and they supplied us with a password. Is there any place on the web that has step by step instructions on how to set this up. I have IIS running and also the certificate services but am not sure as what to exactly look for. Thanks, Don...more >>

IIS5 FS permissions.
Posted by rusga at 10/9/2004 1:56:46 PM
Hi, I would like to know if there's any list of files/directories used by IIS5 that require IUSR_host and IWAM_host FS access permissions for IIS to work properly. I want to apply the folowing permissions on C: Administrators = full-control. System = full-control. IdleUser = re...more >>

Exploit: Jped of Death
Posted by Nancy at 10/9/2004 7:10:28 AM
I have MSN - Windows Xp/SP 2 Problem: I can't get some of my web sites. I have tried everything. MSN has tried to help and can't find problem. They have gone though every step they can find. Does any on have any ideas? Web sites I can't get southeasttexas.com & gefcu.org. I ha...more >>

Modify HTTP header before pass to IIS
Posted by saminathan at 10/9/2004 4:38:45 AM
we are developing web based application using ASP. one of our client told that they can able to modify the HTTP informations send from clint browser using intermediate tool and send it to IIS server. They feel that user can do such Vulnerable security issues with datas. Is it possible...? ...more >>

SSL renewal on IIS6.0
Posted by Sai at 10/8/2004 3:18:44 PM
I have 4 webservers with load balancer for single website.(Windows 2003) Last time I have used import/export facility of IIS to install the same ceritificate on all the 4 servers, can I do like this?? Now it is the time for renewal of the SSL on all the 4 web servers. can I generate the...more >>

IIS 6 Authentication Problem - Not Happening
Posted by JoeH at 10/8/2004 2:59:41 PM
I have an intranet web site running on IIS 6 where users are given access through the FrontPage Server Extensions 2002 admin web tool. The root site and most subsites have the same permissions with anonymous browse access. Few subsites use unique permissions. Users logged on with NT Dom...more >>

Allowing IIS to respond only when using a specific URL
Posted by Jean-François Lavigne at 10/8/2004 9:25:07 AM
Greetings to all IIS experts, Is there a way to prevent IIS from answering any request except those sent to a specific URL? I have a Web service installed on IIS and I would like the server to completely ignore any request not sent directly to the web service. When scanning the ports of...more >>

IIS 5 and PHP = 401.1
Posted by Alan at 10/8/2004 7:59:11 AM
I am new to servers and am having a problem getting PHP installed on a Windows 2000 IIS 5. When I try to view a PHP document I am challenged with a login dialog (username,password and domain). If I enter admin credentials all works fine. I want this to be a public webserver - no long on r...more >>

Basic Authentication in url with @ in username
Posted by ldesmons NO[at]SPAM hotmail.com at 10/8/2004 3:33:40 AM
Hi, I try to connect to an IIS server requiring basic authentication. My username is an email , so it contains a '@' of course. Everyhting is fine as long as I fill my username and password in the message box popping. But when I try to connect directly by entering this type of url: http://myem...more >>


DevelopmentNow Blog