all groups > iis security > october 2004 > threads for october 8 - 14, 2004
Filter by week: 1 2 3 4 5
Windows 2003 server - FTP connection using Fetch(Mac) problem
Posted by Snappy at 10/14/2004 11:57:03 PM
Hi guys,
I have a box running Windows 2003 Server (with ISA 2000 server).
Some of the collegues that want to connect have MAC PCs.
They receive a conection error.
I use WS_FTP & Internet explorer to connect without any problems.
I checked with Passive & active FTP but did not get it..
... more >>
How to test a SSL website?
Posted by Joachim Engel at 10/14/2004 4:57:29 PM
Hi,
we want to test a SSL Web-Application
without buying a certificate.
Is that possible? What is to do?
Kind regards
Joachim Engel.
... more >>
IIS 6 CreateObject premissions issue
Posted by Matthew Nichols at 10/14/2004 4:56:15 PM
First off I apologize for the crucial piece of information I will
doubtlessly leave out (don't know what it is but I am sure there will be
something) or the completely obvious answer that I have missed.
We have a system that has been running on Windows 2000 Server composed of
SQL / COM+ / A... more >>
Authenticate against all trusted domains... in IIS 6?
Posted by tec-jon at 10/14/2004 9:37:04 AM
I have a parent/child domain that I would like to have a basic authentication
website on. They are both 2003 native domains. We would like our users to not
have to use UPN or domain\user login formats. We have done a bit of research
and came across the following article:
http://support.micros... more >>
Remove FTP Anonymous Login Prompt
Posted by StevieD at 10/14/2004 3:47:02 AM
We login to our FTP site via Internet Explorer, using account usernames &
passwords to login. When I go to open the files in the directory I'm
prompted with an FTP login prompt, either logging on as anonymous or a user.
How do I remove this prompt ? Because once I'm authenticated using my F... more >>
Anonymous Access denied
Posted by Nejmos Saqeb at 10/13/2004 3:53:54 PM
Hi,
I have site hosted under IIS 5.0 running on Windows 2000 Server w/SP4. The
site has a anonymous access allowed and "Everyone" access from ACL. Some of
the users are able to access the site whereas some dont.
What may be wrong?
Regards
Nejmos Saqeb
nejmos.saqib@softech.us
... more >>
Generate OWN SSL w/XP Pro
Posted by Linking at 10/13/2004 2:27:41 PM
Hello,
I understand I need to first go through and request the certificate and save
it to my hard drive. From there, it gets shaky. I've tried using my
computer name in the browser, adding on the /certsrv at the end, but the
Certificate Server does not come up. I looked in the "Add/Remov... more >>
SSL Client Authentication
Posted by Mark W. at 10/13/2004 2:24:36 PM
I'm trying to establish SSL connectivity with an IIS server that requires
client authentication. I noticed in the SSL handshake that the
certificate_authorities component of the handshake is empty. Based on the
way I read the SSL protocol, I was expecting that this field would contain a
... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
create own certificate for SSL
Posted by John Smith at 10/13/2004 12:20:44 PM
Hi there,
Pretty simple question, I want to setup a mail server at home, and would
like to install a certificate on it for security. But, i dont want to buy
one, as its only really for me, and afew friends. Is there a way to create
your own certificates for IIS? im wanting to play around wi... more >>
SSL Security
Posted by Ishmealm at 10/13/2004 9:34:15 AM
Hi,
This is just a question and not a problem. I have a site
that has an SSL cert. Under this site I probably have 50-
60 virtual directories. At the site level I do not have
SSL enabled, I do this at a directory label. I noticed
the other day that even directories that I have not
enabled ... more >>
URLScan v2.5
Posted by zaheer mohammad at 10/13/2004 8:41:05 AM
How can I use multiple different urlscan.ini files for different web
instances.
I can do a wildcard application mapping at a websites level or
selectively attached a urlscan extension at site-by-site, but I am still
dealing with the same configuration setting file.
Can I associate individu... more >>
IP Restrictions Greyed Out
Posted by Mike C at 10/12/2004 6:55:06 PM
Working with someone remotely on IIS 5.0 server. Cannot get server to
connect from off the LAN. IP routing, firewall, etc etc seems right. Asked
user to check IP Restrictions to see if IIS is dropping packets on purpose.
Button to edit Restrictions is greyed out.
On related note, is t... more >>
pwd changed, but old one still works for 30 minutes
Posted by Matt Norton at 10/12/2004 1:02:46 PM
Any idea on how I can force a password change (IIS 5.0 on Win2k Standalone
Server) to take place immediately? Right now I have my site set so that
people can change their own windows password (I use windows accounts,
authenticated over SSL), but the old pwd still works for between 5 and 30
minu... more >>
NTLM auth fails with websites using four part FQDN Host Header nam
Posted by dwenwa NO[at]SPAM companyabc.com at 10/12/2004 6:49:10 AM
Hi,
I have encountered a unique problem with IIS6, Integrated Authentication
(IWA) and Host Headers. I manage a web farm of two production servers behind
a content switch that host ASP.NET applications. I have a particular
situation where NTLM authentication fails where the URL is
"http... more >>
Canonicalization issue in Microsoft IIS web server with ASP.NET
Posted by Paul Cyr at 10/12/2004 5:29:10 AM
I can't believe this newsgroup is not discussing this vunerability. This is a
major flaw and we need a patch from Microsoft ASAP. This affects many
Microsoft products.
Event Analysis: By sending a specially crafted URL, application level
authentication can be bypassed, potentially exposing ... more >>
iRemoving Anonymous FTP from directory prevents write access by an
Posted by David Quinn at 10/12/2004 3:43:09 AM
Hi
We are using IIS 6.0 and have a slight problem. When we remove anonymous
ftp access from web directory, it prevents anyone writing to the directory.
The only way we seem to be able to get write access for anyone is to
re-enable anonymous ftp. Any suggestions?
Thanks
Dave Quinn.... more >>
Removing Anonymous FTP from directory prevents write access by any
Posted by Dave Quinn at 10/12/2004 3:41:03 AM
Hi
We are using IIS 6.0 and have a slight problem. When we remove anonymous
ftp access from web directory, it prevents anyone writing to the directory.
The only way we seem to be able to get write access for anyone is to
re-enable anonymous ftp. Any suggestions?
Thanks
Dave Quinn.... more >>
Problem after iislockdown tool and urlscan
Posted by at 10/11/2004 12:54:07 PM
Hi i have installed IIS Lockdown tool and Urlscan and after i have unistall
both!
Now when i try to access to some page of my webserver a error appared :
HTTP Error 403
403.1 Forbidden: Execute Access Forbidden
This error can be caused if you try to execute a CGI, ISAPI, or other
executa... more >>
Connect to IIS from another Pc
Posted by Pupo at 10/11/2004 11:53:07 AM
Hi
I want to connect from all my Pc (Windows Xp pro Sp1/Sp2) to iis of my new
server. I open iis controll panel and on local computer i select connect...
and write server name.
Before i was able to view all folder now if i try to connect to my new
server only domain administrator are able to vi... more >>
Password protecting emails
Posted by Don at 10/11/2004 11:23:03 AM
I was asked by the government to password protect our email. When I looked
into this it said to have security certificate in IIS installed. What I am
looking for is to setup our exchange server 2000 so that the users on the
network can send password protected email. Does anyone know of where t... more >>
Security Certificate
Posted by Don at 10/11/2004 8:42:19 AM
I was asked to password protect our email and they
supplied us with a password. Is there any place on the web
that has step by step instructions on how to set this up.
I have IIS running and also the certificate services but
am not sure as what to exactly look for.
Thanks,
Don... more >>
IIS5 FS permissions.
Posted by rusga at 10/9/2004 1:56:46 PM
Hi,
I would like to know if there's any list of files/directories used by IIS5
that require IUSR_host and IWAM_host FS access permissions for IIS to work
properly.
I want to apply the folowing permissions on C:
Administrators = full-control.
System = full-control.
IdleUser = re... more >>
Exploit: Jped of Death
Posted by Nancy at 10/9/2004 7:10:28 AM
I have MSN - Windows Xp/SP 2 Problem: I can't get
some of my web sites. I have tried everything. MSN has
tried to help and can't find problem. They have gone
though every step they can find. Does any on have any
ideas? Web sites I can't get southeasttexas.com &
gefcu.org. I ha... more >>
Modify HTTP header before pass to IIS
Posted by saminathan at 10/9/2004 4:38:45 AM
we are developing web based application using ASP.
one of our client told that they can able to modify the
HTTP informations send from clint browser using
intermediate tool and send it to IIS server.
They feel that user can do such Vulnerable security issues
with datas.
Is it possible...?
... more >>
SSL renewal on IIS6.0
Posted by Sai at 10/8/2004 3:18:44 PM
I have 4 webservers with load balancer for single
website.(Windows 2003)
Last time I have used import/export facility of IIS to
install the same ceritificate on all the 4 servers, can I
do like this??
Now it is the time for renewal of the SSL on all the 4 web
servers.
can I generate the... more >>
IIS 6 Authentication Problem - Not Happening
Posted by JoeH at 10/8/2004 2:59:41 PM
I have an intranet web site running on IIS 6 where users
are given access through the FrontPage Server Extensions
2002 admin web tool.
The root site and most subsites have the same permissions
with anonymous browse access. Few subsites use unique
permissions. Users logged on with NT Dom... more >>
Allowing IIS to respond only when using a specific URL
Posted by Jean-François Lavigne at 10/8/2004 9:25:07 AM
Greetings to all IIS experts,
Is there a way to prevent IIS from answering any request except those sent
to a specific URL?
I have a Web service installed on IIS and I would like the server to
completely ignore any request not sent directly to the web service. When
scanning the ports of... more >>
IIS 5 and PHP = 401.1
Posted by Alan at 10/8/2004 7:59:11 AM
I am new to servers and am having a problem getting PHP installed on a
Windows 2000 IIS 5. When I try to view a PHP document I am challenged
with a login dialog (username,password and domain). If I enter admin
credentials all works fine. I want this to be a public webserver - no
long on r... more >>
Basic Authentication in url with @ in username
Posted by ldesmons NO[at]SPAM hotmail.com at 10/8/2004 3:33:40 AM
Hi,
I try to connect to an IIS server requiring basic authentication. My
username is an email , so it contains a '@' of course.
Everyhting is fine as long as I fill my username and password in the
message box popping.
But when I try to connect directly by entering this type of url:
http://myem... more >>
|