Groups | Blog | Home


Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
all groups > iis security > november 2004 > threads for november 15 - 21, 2004

Filter by week: 1 2 3 4 5

Exclude and Include Content
Posted by Ham at 11/21/2004 11:59:03 PM
I am a sharepoint newbie. I am doing a new installation; I set my web site to Basic Authentication so I could utilize SSL. With Basic Authentication set, my "crawls" fail with the following error: The content source <spss://10.10.10.5/site$$$people> cannot be accessed. Context: https://10....more >>


HTTPS working (I think) but Security lock not showing in IE
Posted by Kirk Graves at 11/19/2004 5:57:08 PM
I have an IIS 6 Server that I have just inherited (the system admin just left the company). I have a directory that needs to be SSL protected. I have the Certificate installed (it was done before I took over), and I can require the directory only be accessed through SSL. My problem is that one...more >>

HTTP working (I think) but Security lock not showing in IE
Posted by Kirk Graves at 11/19/2004 4:56:01 PM
I have an IIS 6 Server that I have just inherited (the system admin just left the company). I have a directory that needs to be SSL protected. I have the Certificate installed (it was done before I took over), and I can require the directory only be accessed through SSL. My problem is that ...more >>

Integrated Windows authentication - off site
Posted by remster NO[at]SPAM gmail.com at 11/19/2004 1:37:45 PM
I've set up IIS on a Windows 2003 server to use Integrated Windows authentication. This works the way I expect it to on site - users who are logged into our domain can reach the website no problem. What I'm having an issue with (of sorts) is users off site. Using IE6 they are forced to log in...more >>

Strange auth denial with IE Integrated Security and IIS; but not Firefox, Netscape
Posted by Kevin C at 11/19/2004 1:17:06 PM
I am having a rather weird error occur when trying to connect to my web applications. Here is the scenario: - There is a application pool that I have created to host my web apps - The App pool is running under a domain account - Anonymous access is off and WindowsAuth is on - t...more >>

HELP!!!! Fresh install of XP Pro but IIS 5.1 won't run.
Posted by slapsquidgebosh NO[at]SPAM hotmail.com at 11/19/2004 11:20:15 AM
Hello All, IIS used to work fine but then I rebuilt my machine with XP Pro (2002). I thought some setting were altered by installing Baseline Security Analyser or perhaps the IIS lockdown tool. Today I've given up, and reinstalled XP Pro (2002). I then installed IIS and all the sub-components...more >>

Help Deploying RMS
Posted by jay.chadderwala NO[at]SPAM emsure.com at 11/19/2004 3:15:26 AM
Hi I have installed windows 2003 std & IIS+asp.net & MSMQ on one machine. I havenot installed RMS on this machine. ( domain member). I am afraid of doing that.... I have win2k server with AD and It works as DNS server as well.(domain controller) I havenot installed sql 2000.... Which v...more >>

Error Using Perfmon after IISLockdown with URLScan
Posted by Ralf at 11/19/2004 1:09:08 AM
Hello, we use IISLockdown with urlscan to protect our IIS 5.0. But now every time we start perfmon (Total Processor use) we get an error The configuration information of the performance library "C:\WINNT\system32\w3ctrs.dll" for the "W3SVC" service does not match the trusted performance ...more >>



Anonymous Access to aspx pages
Posted by GRT at 11/18/2004 1:30:31 PM
IIS 6 Windows 2003 All was working fine (serving up aspx pages, etc.) I ran the Site Adminsitartor and did Check Server Health and did Tighten Security. Now everytime an anonymous user loads an aspx page in browser it asks for credentials. I have Anonymous and Windows Integrated checked ...more >>

You are not authorized to view this page
Posted by t at 11/18/2004 12:08:28 PM
Hi All, I am getting this error when I try to browse a web site installed on = II6, although it asks for password and user ID, and I am providing = domain admin ID and password, but it keep prompt for ID and password = then gives this error message. the web site has been set to use Anonymous ...more >>

Random 401.2 Error in ASP.NET app
Posted by john_murray_sp NO[at]SPAM hotmail.com at 11/18/2004 8:04:11 AM
I am getting this error at random in my ASP.NET app (i.e. at different times on different pages): You are not authorized to view this page You do not have permission to view this directory or page using the credentials you supplied. HTTP 401.2 - Unauthorized: Logon failed due to server conf...more >>

Only web viewable to the Internet
Posted by vncntj NO[at]SPAM hotmail.com at 11/18/2004 6:59:26 AM
My problem is this. I have a folder with all of my webpages in them and you can view it through the web. BUT, if you type in the name of other folder... like our demo folder you can view all of it's contents. How can i make one folder visible to the Internet, while still maintain the other de...more >>

Problem installing a certificate authority...
Posted by andrew.mccall NO[at]SPAM gmail.com at 11/18/2004 3:15:10 AM
Hi Folks, I am trying to install a certificate authority (CA) to a fairly locked down Windows 2003 server that also runs IIS6. I have used various guides to securing the server, and I think that one of the processes involved in securing the server is preventing me from installing and running...more >>

Server.CreateObject Access Error
Posted by Ernest at 11/17/2004 10:19:05 PM
Hello, I've recently loaded my machine with wWindows Server 2003. I have com opbjects that were created with VB6 compile on Win 2K. I've added the components to Component Services but when my .asp page does a Server.Create I'm getting the following error. "The call to Server.CreateObject fail...more >>

IIS w3SVC1
Posted by rafee alias at 11/17/2004 7:09:48 PM
my https |web services for exchange seem to stop responding , which i doono wat cause it .. when i check event viewer log file it give the this error: IIS Logging for W3SVC1 has been shutdown because a disk full error has been encountered i already check all drive and there are enuf spac...more >>

SSL Port 443 disappears after server restart
Posted by Allan Tee at 11/17/2004 4:34:03 PM
Windows 2000 SP3 with latest patches installed Exchange 2000 SP3 using SSL for OWA users We created another web site in IIS and installed a Verisign certificate to enable us to use SSL for our users. Problem is every after server restart, we have to type 443 in the SSL Port textbox of that p...more >>

IIS6 in a DMZ with Win2K AD and Non MS Firewalls
Posted by Nick at 11/17/2004 9:05:07 AM
Hello all, I have been trawling round the net most of today and I am struggling to come up with an agreed best practice for securing an IIS6 server that is based in a DMZ, with a Win2K Active Directory. I have several concerns: What are peoples views on best practice for Firewalls (non...more >>

Basic Auth - Role Based security
Posted by Alan Harling at 11/17/2004 8:28:51 AM
I am having a problem with role-based security in an ASP.NET = application. Backgound info:=20 Web Server - IIS 6.0, Win2K3 Basic Auth Domain - W2K When I browse to the web site I get the login dialog. I type in my = useid/password and I get authenticated fine. The next ...more >>

How to get iusr and iwam name?
Posted by alfred.sehmueller NO[at]SPAM gmx.de at 11/17/2004 7:52:23 AM
Hello, for a setup script that grants NTFS-Permissions to a folder I need the name of the iusr and iwam accounts. Many machines get renamed after IIS is installed so a simple string addition of iusr + machine name often fails. Is there a way to identifiy the iusr and iwam accounts? Thank...more >>

IIS 6.0 FTP Authentication
Posted by David Raskino at 11/17/2004 6:29:01 AM
I experienced something strange this morning: I have two Windows 2003 servers A and B. Server A is an FTP server running IIS 6.0, and server be is an ordinary file server. Both servers have a local account called user1. Both local users also have same passwords. I have a virtual directory o...more >>

IIS Securityleak uploading big files
Posted by Ralf at 11/17/2004 4:45:02 AM
Hello, we provide a .net application on IIS 5.0. At the moment theres a diskussion with one of our customers about a securityleak in IIS in case uploading big files. Does anybody know something about such a leak. Ralf...more >>

Best way to secure FTP IIS 5.0 Win2K
Posted by Jo Winchester at 11/17/2004 3:24:02 AM
We are reviewing network security and file transfers on our internal network. We need to transfer files to & from Unix servers to Windows servers, and have decided that FTP is our best approach. Can anyone advise what is the best method of authentication from a security point of view? Anonymo...more >>

FTP Server configuration problems
Posted by jozeluis NO[at]SPAM telefonica.net at 11/16/2004 7:28:49 AM
Hi! I have a W2K3 with IIS 6. I've configure the FTP server with the next structure: e:\globalFTP\localuser\user1 e:\globalFTP\localuser\user2 e:\globalFTP\localuser\user3 Anonymous access disable; Isolation mode; I have three folders for the web pages; one for each user: e:\WEBs...more >>

2 Questions - IIS6 Novice
Posted by Gary at 11/16/2004 4:59:03 AM
1. Users can view a Word .doc file by clicking a link. Occasionally the following is displayed in the IIS Log when users try to access the file: GET /_vti_inf.html - - xxx.xxx.xx.xx HTTP/1.1 Mozilla/2.0+(compatible;+MS+FrontPage+4.0) POST /_vti_bin/shtml.exe/_vti_rpc - - xxx.xxx.xx.xx HTTP...more >>

Denny SYNCHRONIZE to IUSR_%COMPUTERNAME% causes remote access to prompt for username
Posted by Luis Garcia at 11/15/2004 5:27:24 PM
Hi, I have IIS 6 installed and runnning. I try to denny write access to the user IUSR_%COMPUTERNAME% in the root directory using the xcacls.vbs tool: cscript xcacls.vbs d:\inetpub\wwwroot /E /D IUSR_%COMPUTERNAME%:W The following rigths are dennied: SYNCHRONIZE FILE_WRITE_DATA FILE_APPE...more >>

Client certificates: security vulnerability?
Posted by Max Metral at 11/15/2004 4:55:14 PM
So I have an application that uses client certificates on smart cards. The problem is that if you "login" to a web site using the cert, and then pull the smart card, the session stays valid, for a long time. I think I understand what's happening, namely that the SSL session has been negoti...more >>

User can not download activex control updates.
Posted by Scottwn at 11/15/2004 11:24:05 AM
I have been receiving complaints from users that they can not get activex control updates. This seems to be the case for normal users, users with admin or power users can download updates without a problem. Did I miss something or can't domain/local users download activex updates? How does...more >>

Integrated Windows Authentication - Different results on different machines
Posted by James Leech at 11/15/2004 10:40:39 AM
Hi there, I am building an intranect/extranet for which I am using my SBS2000 server as a test bed. I took the asp files and database along to the customers on friday to do some pre-emptive testing on their SBS2000 server and found that I get a login prompt appear which I don't get when I b...more >>

KRB_AP_ERR_MODIFIED
Posted by Jörgen at 11/15/2004 2:47:12 AM
The error below occurs periodically when running a webapplication (.net). The server is a Windows 2003 and the clients run Windows XP. It is a intranet with Windows integrated authentication. "The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/pasp1h1.forsmark.se....more >>


DevelopmentNow Blog