all groups > iis security > november 2004 > threads for november 15 - 21, 2004
Filter by week: 1 2 3 4 5
Exclude and Include Content
Posted by Ham at 11/21/2004 11:59:03 PM
I am a sharepoint newbie. I am doing a new installation; I set my web site to
Basic Authentication so I could utilize SSL. With Basic Authentication set,
my "crawls" fail with the following error:
The content source <spss://10.10.10.5/site$$$people> cannot be accessed.
Context: https://10.... more >>
HTTPS working (I think) but Security lock not showing in IE
Posted by Kirk Graves at 11/19/2004 5:57:08 PM
I have an IIS 6 Server that I have just inherited (the system admin just
left the company). I have a directory that needs to be SSL protected. I
have the Certificate installed (it was done before I took over), and I can
require the directory only be accessed through SSL. My problem is that one... more >>
HTTP working (I think) but Security lock not showing in IE
Posted by Kirk Graves at 11/19/2004 4:56:01 PM
I have an IIS 6 Server that I have just inherited (the system admin just
left the company). I have a directory that needs to be SSL protected. I
have the Certificate installed (it was done before I took over), and I can
require the directory only be accessed through SSL. My problem is that ... more >>
Integrated Windows authentication - off site
Posted by remster NO[at]SPAM gmail.com at 11/19/2004 1:37:45 PM
I've set up IIS on a Windows 2003 server to use Integrated Windows
authentication. This works the way I expect it to on site - users who
are logged into our domain can reach the website no problem.
What I'm having an issue with (of sorts) is users off site. Using IE6
they are forced to log in... more >>
Strange auth denial with IE Integrated Security and IIS; but not Firefox, Netscape
Posted by Kevin C at 11/19/2004 1:17:06 PM
I am having a rather weird error occur when trying to connect to my web
applications. Here is the scenario:
- There is a application pool that I have created to host my web apps
- The App pool is running under a domain account
- Anonymous access is off and WindowsAuth is on
- t... more >>
HELP!!!! Fresh install of XP Pro but IIS 5.1 won't run.
Posted by slapsquidgebosh NO[at]SPAM hotmail.com at 11/19/2004 11:20:15 AM
Hello All,
IIS used to work fine but then I rebuilt my machine with XP Pro
(2002). I thought some setting were altered by installing Baseline
Security Analyser or perhaps the IIS lockdown tool. Today I've given
up, and reinstalled XP Pro (2002). I then installed IIS and all the
sub-components... more >>
Help Deploying RMS
Posted by jay.chadderwala NO[at]SPAM emsure.com at 11/19/2004 3:15:26 AM
Hi
I have installed windows 2003 std & IIS+asp.net & MSMQ on one machine.
I havenot installed RMS on this machine. ( domain member). I am
afraid of doing that....
I have win2k server with AD and It works as DNS server as well.(domain
controller)
I havenot installed sql 2000.... Which v... more >>
Error Using Perfmon after IISLockdown with URLScan
Posted by Ralf at 11/19/2004 1:09:08 AM
Hello,
we use IISLockdown with urlscan to protect our IIS 5.0.
But now every time we start perfmon (Total Processor use) we get an error
The configuration information of the performance library
"C:\WINNT\system32\w3ctrs.dll" for the "W3SVC" service does not match the
trusted performance ... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Anonymous Access to aspx pages
Posted by GRT at 11/18/2004 1:30:31 PM
IIS 6 Windows 2003
All was working fine (serving up aspx pages, etc.)
I ran the Site Adminsitartor and did Check Server Health and did Tighten
Security.
Now everytime an anonymous user loads an aspx page in browser it asks for
credentials.
I have Anonymous and Windows Integrated checked ... more >>
You are not authorized to view this page
Posted by t at 11/18/2004 12:08:28 PM
Hi All,
I am getting this error when I try to browse a web site installed on =
II6, although it asks for password and user ID, and I am providing =
domain admin ID and password, but it keep prompt for ID and password =
then gives this error message.
the web site has been set to use Anonymous ... more >>
Random 401.2 Error in ASP.NET app
Posted by john_murray_sp NO[at]SPAM hotmail.com at 11/18/2004 8:04:11 AM
I am getting this error at random in my ASP.NET app (i.e. at different
times on different pages):
You are not authorized to view this page
You do not have permission to view this directory or page using the
credentials you supplied.
HTTP 401.2 - Unauthorized: Logon failed due to server conf... more >>
Only web viewable to the Internet
Posted by vncntj NO[at]SPAM hotmail.com at 11/18/2004 6:59:26 AM
My problem is this. I have a folder with all of my webpages in them
and you can view it through the web. BUT, if you type in the name of
other folder... like our demo folder you can view all of it's
contents. How can i make one folder visible to the Internet, while
still maintain the other de... more >>
Problem installing a certificate authority...
Posted by andrew.mccall NO[at]SPAM gmail.com at 11/18/2004 3:15:10 AM
Hi Folks,
I am trying to install a certificate authority (CA) to a fairly locked
down Windows 2003 server that also runs IIS6. I have used various
guides to securing the server, and I think that one of the processes
involved in securing the server is preventing me from installing and
running... more >>
Server.CreateObject Access Error
Posted by Ernest at 11/17/2004 10:19:05 PM
Hello, I've recently loaded my machine with wWindows Server 2003. I have
com opbjects that were created with VB6 compile on Win 2K. I've added the
components to Component Services but when my .asp page does a Server.Create
I'm getting the following error. "The call to Server.CreateObject fail... more >>
IIS w3SVC1
Posted by rafee alias at 11/17/2004 7:09:48 PM
my https |web services for exchange seem to stop responding , which i
doono wat cause it .. when i check event viewer log file it give the
this error:
IIS Logging for W3SVC1 has been shutdown because a disk full error has
been encountered
i already check all drive and there are enuf spac... more >>
SSL Port 443 disappears after server restart
Posted by Allan Tee at 11/17/2004 4:34:03 PM
Windows 2000 SP3 with latest patches installed
Exchange 2000 SP3 using SSL for OWA users
We created another web site in IIS and installed a Verisign certificate to
enable us to use SSL for our users. Problem is every after server restart, we
have to type 443 in the SSL Port textbox of that p... more >>
IIS6 in a DMZ with Win2K AD and Non MS Firewalls
Posted by Nick at 11/17/2004 9:05:07 AM
Hello all,
I have been trawling round the net most of today and I am struggling to come
up with an agreed best practice for securing an IIS6 server that is based in
a DMZ, with a Win2K Active Directory.
I have several concerns:
What are peoples views on best practice for Firewalls (non... more >>
Basic Auth - Role Based security
Posted by Alan Harling at 11/17/2004 8:28:51 AM
I am having a problem with role-based security in an ASP.NET =
application.
Backgound info:=20
Web Server - IIS 6.0, Win2K3
Basic Auth
Domain - W2K
When I browse to the web site I get the login dialog. I type in my =
useid/password and I get authenticated fine. The next ... more >>
How to get iusr and iwam name?
Posted by alfred.sehmueller NO[at]SPAM gmx.de at 11/17/2004 7:52:23 AM
Hello,
for a setup script that grants NTFS-Permissions to a folder I need the
name of the iusr and iwam accounts. Many machines get renamed after
IIS is installed so a simple string addition of iusr + machine name
often fails.
Is there a way to identifiy the iusr and iwam accounts?
Thank... more >>
IIS 6.0 FTP Authentication
Posted by David Raskino at 11/17/2004 6:29:01 AM
I experienced something strange this morning:
I have two Windows 2003 servers A and B. Server A is an FTP server running
IIS 6.0, and server be is an ordinary file server. Both servers have a local
account called user1. Both local users also have same passwords. I have a
virtual directory o... more >>
IIS Securityleak uploading big files
Posted by Ralf at 11/17/2004 4:45:02 AM
Hello,
we provide a .net application on IIS 5.0.
At the moment theres a diskussion with one of our customers about a
securityleak in IIS in case uploading big files.
Does anybody know something about such a leak.
Ralf... more >>
Best way to secure FTP IIS 5.0 Win2K
Posted by Jo Winchester at 11/17/2004 3:24:02 AM
We are reviewing network security and file transfers on our internal network.
We need to transfer files to & from Unix servers to Windows servers, and
have decided that FTP is our best approach.
Can anyone advise what is the best method of authentication from a security
point of view?
Anonymo... more >>
FTP Server configuration problems
Posted by jozeluis NO[at]SPAM telefonica.net at 11/16/2004 7:28:49 AM
Hi!
I have a W2K3 with IIS 6.
I've configure the FTP server with the next structure:
e:\globalFTP\localuser\user1
e:\globalFTP\localuser\user2
e:\globalFTP\localuser\user3
Anonymous access disable; Isolation mode;
I have three folders for the web pages; one for each user:
e:\WEBs... more >>
2 Questions - IIS6 Novice
Posted by Gary at 11/16/2004 4:59:03 AM
1. Users can view a Word .doc file by clicking a link. Occasionally the
following is displayed in the IIS Log when users try to access the file:
GET /_vti_inf.html - - xxx.xxx.xx.xx HTTP/1.1
Mozilla/2.0+(compatible;+MS+FrontPage+4.0)
POST /_vti_bin/shtml.exe/_vti_rpc - - xxx.xxx.xx.xx HTTP... more >>
Denny SYNCHRONIZE to IUSR_%COMPUTERNAME% causes remote access to prompt for username
Posted by Luis Garcia at 11/15/2004 5:27:24 PM
Hi,
I have IIS 6 installed and runnning. I try to denny write access to the user
IUSR_%COMPUTERNAME% in the root directory using the xcacls.vbs tool:
cscript xcacls.vbs d:\inetpub\wwwroot /E /D IUSR_%COMPUTERNAME%:W
The following rigths are dennied:
SYNCHRONIZE
FILE_WRITE_DATA
FILE_APPE... more >>
Client certificates: security vulnerability?
Posted by Max Metral at 11/15/2004 4:55:14 PM
So I have an application that uses client certificates on smart cards. The
problem is that if you "login" to a web site using the cert, and then pull
the smart card, the session stays valid, for a long time.
I think I understand what's happening, namely that the SSL session has been
negoti... more >>
User can not download activex control updates.
Posted by Scottwn at 11/15/2004 11:24:05 AM
I have been receiving complaints from users that they can not get activex
control updates. This seems to be the case for normal users, users with admin
or power users can download updates without a problem.
Did I miss something or can't domain/local users download activex updates?
How does... more >>
Integrated Windows Authentication - Different results on different machines
Posted by James Leech at 11/15/2004 10:40:39 AM
Hi there,
I am building an intranect/extranet for which I am using my SBS2000 server
as a test bed. I took the asp files and database along to the customers on
friday to do some pre-emptive testing on their SBS2000 server and found that
I get a login prompt appear which I don't get when I b... more >>
KRB_AP_ERR_MODIFIED
Posted by Jörgen at 11/15/2004 2:47:12 AM
The error below occurs periodically when running a webapplication (.net). The
server is a Windows 2003 and the clients run Windows XP. It is a intranet
with Windows integrated authentication.
"The kerberos client received a KRB_AP_ERR_MODIFIED error from the server
host/pasp1h1.forsmark.se.... more >>
|