Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > january 2004

Filter by week: 1 2 3 4 5

MyDoom and MSN
Posted by Dick at 1/31/2004 6:56:50 PM
The Microsoft security homepage provides links for protecting against MyDoom for Outlook, Outlook Express, but not for MSN. Where should an MSN user go for help?...more >>


Internet explorer
Posted by Randy at 1/31/2004 2:03:48 PM
Im having a problem when I go to explorer,I get a message to report this problem to microsoft, my homepage keeps changing,and I can't exit out of this message ,I Recently scanned for updates ,, Now when I Scan it tells me no critical, But My Internet Explorer Isn't Working Right, Do U Kno...more >>

XP IIS 5.1directory security issue
Posted by Mclin at 1/31/2004 10:55:32 AM
I using XP pro IIS 5.1 on my laptop, the issue is that can't use IUSR_computer account log in, only can do it by change Anonymous account to my windows user account with Anonymous access mode. and in the integrate windows authentication mode, none account can be log in, include system admin acco...more >>

IIS Security Lockdown Wizard
Posted by Chaffe at 1/31/2004 10:53:47 AM
Hello, I'm trying to find a way to disable the FTP server in my IIS 6.0. How can I launch the "IIS Security Lockdown Wizard"? Thanks very much for the help....more >>

urlscan and Frontpage
Posted by Pat at 1/30/2004 6:47:53 PM
Have W2K, IIS5 Frontpage ext, installed lockdown wizard and URLscan, now FP Clients can not publish modified Urlscan.ini according to setup for frontpage doc. getting following when user tries to publish, also does FP need Webdav to work? Sent verb 'PROPFIND', which is not specifically a...more >>

MDAC Update Locked out IE 3.1
Posted by Kevin Vogler at 1/30/2004 12:20:36 PM
I have a client with a windows 2000 server running IIS. They have a number of Pocket PCs (2002) and one PC wirelessly connecting to an ASP app on a closed intranet. After installing the security update for MDAC, the pocket PCs usually error with "page your are looking for can't be found" but s...more >>

IIS security statistics
Posted by Simon at 1/30/2004 10:01:09 AM
I'm trying to sell a IIS web-based solution to a customer who believes IIS to be inherently insecure no matter how it is configured. This is a general feeling on their part rather than a well researched position. I obviously disagree, and am looking for any pages with statistics or facts which will ...more >>

FileSystemObject and networked drives
Posted by Mark at 1/30/2004 12:00:45 AM
Hi - I am using the FileSystemObject to upload files to a directory on my web server. The directory has full permissions for the IUSR account. Problem is, I now need to store the documents on a network drive (eg. p:\\files\) - and when I try and do this, I get the message 'Path Not Found'. ...more >>



IIS lockdown tool
Posted by Samantha at 1/29/2004 6:33:05 PM
Hello, Does anyone know of any known problems encountered from running the iis lookdown tool on an exchange 2000 server? Thanks in advance ...more >>

Remote Virtual Directory problems
Posted by John Bunting at 1/29/2004 1:47:58 PM
I am having trouble accessing a file on a remote virtual directory when I use Integrated Windows Authentication (download ASP page on main server tries to download file on remote server). I was able to successfully test this when using Anonymous access (set up IUSR_ account and permissi...more >>

Public host security questions - ASP.NET
Posted by Ivan Demkovitch at 1/29/2004 11:44:24 AM
Hi! Not 100% sure if that would be appropriate group, but here is my problem: I'm designing portal where users will be able to upload files. I need permissions to create/delete files in specific directories. This will be actual .aspx and ascx files. I wonder what model I need to use to make...more >>

pop-up
Posted by sandi at 1/29/2004 10:30:42 AM
i am getting a pop-up appearing to be microsoft internet explorer based. it is a "warning" telling me my keystrokes are being monitored and i need to click on a link provided to install a "free scanner" that will let me know if i am being "watched". is this legitimate? thanks...more >>

Need Help with FTP Home Folder Permissions Please!!
Posted by LB at 1/29/2004 9:25:13 AM
My IIS - FTP server is working fine. Users have home folders under default FTP root. BillB logs in and goes to home Folder BillB. The problem is that he can go up a folder and see the folders listed in the FTP root. He can't open the folders but I don't want him to be able to list the fold...more >>

regedt32
Posted by US NAVY at 1/29/2004 6:55:01 AM
receiving message " registry editing has been disabled by administrator" How do I enable it? I am logging in as administrator....more >>

IIS/SQL Crashing
Posted by Robert Abela at 1/28/2004 4:20:05 PM
Hi we run a website based on htm/html pages, asp scripts and an SQL backend. Before we had a problem and were having a lot of events in the sys event log and after some time, if i try to access the website i would have an error "Service Unavailable" Then i turned the web server to run in "Iso...more >>

IISAdmPwd
Posted by Rob Edwards at 1/28/2004 12:09:37 PM
After acquiring several new companies. They are still logging on to their own domains (not members of our forest) We want them to be able to access Intranet sites.... there AD accounts have been created with the default "User must change password on next logon" They are not logging on to ou...more >>

Post command in IIS 6.0
Posted by Rich at 1/28/2004 11:47:24 AM
I've upgraded my Windows 2000 Server to 2003, and IIS to version 6.0, and my post procedure no longer works in the application I'm hosting. The app is built on .NET. Any ideas of why it no longer works after the upgrade?...more >>

Secure FTP
Posted by Fabrizio Bocci at 1/28/2004 11:28:02 AM
I've been asked to create an FTP secure site (i guess and ftps:// connection). How can i do this in Windows 2000? thanks in advance ...more >>

IIS Client Certificate Mapping
Posted by David Smith at 1/28/2004 9:48:42 AM
Has anyone set up a system wher users authenticate using PKI Client Certificates? I am doing such a thing right now and using the Many-to-One mapping feature for IIS to map all certificates from a particular Issuer to the "\Everyone" user account. I have required Client Certificates as wel...more >>

IIS acessing SQL if not in the same domain
Posted by Michael G. Schneider at 1/28/2004 9:23:48 AM
Suppose you have two Windows 2000 servers. One is running MS IIS, the other is running the MS SQL Server. The IIS is accessible from the internet. Due to security reasons the servers are not in the same domain, actually they are standalone member servers. For accessing the SQL from the IIS, a ...more >>

backdoor.subseven trojan
Posted by Dale Motschman at 1/28/2004 8:14:26 AM
I keep getting this message "runtime error 216 at 013f3942. I checked this out on google and was told I have a backdoor. subseven trojan. I have checked and ran 4 different antivirus programs and none of the can find the trojan. I need to know how to get rid of it...Thanks...more >>

Access intranet from lan and internet
Posted by Update at 1/28/2004 2:26:08 AM
How do I best configure our iis6.0 if I want to access a intranet site locally in the lan without entering login and password but from the internet it must have authentication. Regards, Patrik ...more >>

Granting web access to single users
Posted by Enrico at 1/28/2004 1:39:57 AM
I'm setting up a projects' web and would like to grant access to projects selectively, i.e., specific users should access only specific projects. The IIS is set to request Windows authentication. The PROJECTS folder ACL grants list access to Domain Users. The ASP page PROJECTS\LIST.ASP disp...more >>

Opening cmd.exe to IUSR_<machine>
Posted by Brad Watson at 1/27/2004 10:38:01 PM
Hi, I'm developing a publicly accessible Perl CGI script that needs to run shell commands such as: my $suggestions = `echo misspelt | aspell.exe -a`; Perl requires use of cmd.exe in order to execute this command and on Windows 2003/IIS 6.0 this is not possible under the default securi...more >>

HTTP Error 401.5
Posted by kennethw NO[at]SPAM ozemail.com.au at 1/27/2004 8:59:32 PM
I have done a quick scan over the newsgroups and didn't find any postings about this so I thought I'd quickly post it and see if anyone has had the same error or was aware of this. We use Windows Server 2003 that hosts an ASP web site for our local office intranet. One of our pages, that displ...more >>

Invalid signature when restoring metabase
Posted by BG at 1/27/2004 4:28:49 PM
I get the message Invalid Signature when I try to restore my IIS metabase. Any ideas? I had to re-install Windows 2003 on this server. I backed up the files and restored and now I am attempting to restore the metabase using the Backup/Restore Configuration in IIS, when this error occurs. ...more >>

can my x get into my oe with the servers password
Posted by Anita at 1/27/2004 3:26:07 PM
I know this may seem thick, but my x has my password for my server (teleos in Germany) does that mean he can go into this server on his computer from another country and then download my OE files, I have changed my hotmail, and yahoo, passwords but will he beable to see what goes on the OE...more >>

Local and doman db access with a twist!
Posted by John Hattersley at 1/27/2004 2:45:30 PM
Hi all, I have a scenario where I need to have both local users and domain users accessing a site. I've set this up fine, I've: 1) set the Auth Mode to Basic 2) added the 'Domain Users' group to a local group 3) set security on the home folder to the local group created in step 2. Every...more >>

II6 & Read-Only Properties
Posted by AspDotNetDeveloper at 1/27/2004 1:26:38 PM
One thing I noticed recently about Win 2k3 Server, and IIS6, is that it defaults to Read-Only permissions at the NTFS file and folders property level. I discovered this, when trying to get the FileSystemObject to write to a text file. All the permissions were set ok, but I discovered every folde...more >>

Automatic ssl certificate client install?
Posted by Update at 1/27/2004 1:09:13 PM
I have installed ssl on our exchange 2003 owa. Exported the certificat to a .crt file for the clients. Installing it manually in the trusted root cerificate authorities on the client works. In some cases I got a client authentication popup with no certificates in it. Enabling "Don't prompt ...more >>

Windows command line FTP
Posted by Al at 1/27/2004 12:11:25 PM
Problem: Command line FTP returns this message when trying to create a sub-directory using the commands mkd or mkdir. "500 command not permitted through gateway" I am running through a Gateway. I can send files, delete files even rename files but can not create sub directories. What is ...more >>

URLscan
Posted by Pat at 1/27/2004 9:07:50 AM
what do I need to do to get frontpage to work on a IIS 5 server with URLscan?...more >>

Invalid ProgID attribute?
Posted by Michel at 1/27/2004 8:10:05 AM
Hello support Team, Why do I get the following error when I try to browse an .ASP page in my Win2003-IIS6.0 web server: "Active Server Pages error 'ASP 0134' Invalid ProgID attribute /LM/W3SVC/1/ROOT/global.asa, line 1 The object has an invalid ProgID of 'MSWC.MyInfo'." The 'global....more >>

How to identify the web site with the IIS instance name
Posted by Mike at 1/27/2004 4:23:03 AM
In my logging, How can i determine what web site the log applies to when all I have is the instance name ? For example, if the Instance name is W3SVC15, how do I know which web site this applies to ? tia, Mike...more >>

Allowing access To Our INTRANET site from the outside
Posted by skeet4me NO[at]SPAM comcast.net at 1/26/2004 10:28:05 AM
I am hoping someone might give me some better ideas than what I have come up with on my own. I have our Internet Site in the DMZ and our Intranet site is inside and can only be accessed from the inside. The big bosses want the board to have access to our intranet site. My first solution was t...more >>

outrageous pop-ups
Posted by Jocelyn at 1/26/2004 9:22:03 AM
sometimes, while I'm on the internet a series of pops ups come up talking about I "only have seconds" and that things are wrong, but I found they come from this site http://www.passthison.com/r4/?s43. I don't advise anyone to go there, i haven't been, but then it changes your home page to ...more >>

OK---
Posted by Chris at 1/26/2004 7:35:47 AM
I can't even serv a simple web page from IIS 6.0 to netscape i go to a download page that has just images and a link an it gives me the error " the file "download.htm" is of type text/html (hypertext markup language) and netscape does not know how to handle this type of file" ANY ideas ...more >>

block chat room and downloading
Posted by razzooo at 1/26/2004 4:30:33 AM
i need bolck chat room and downloading software from internet in my office .what i do...more >>

block installing
Posted by razakuwait NO[at]SPAM hotmail.com at 1/26/2004 4:21:25 AM
i would like to know, i need block downloading from internet please inform me thanks razak...more >>

ssl and the win2k profesional operating system
Posted by Rea Peleg at 1/26/2004 12:13:56 AM
Hi all is there a problem with implementing ssl on a win2k professional machine? I have read in a msdn 'how to' (regarding Building Secure ASP.NET Applications) that a win2k server family is a must. TIA Rea ...more >>

Microsoft VBScript runtime error '800a01a8'
Posted by Glenn at 1/25/2004 6:38:12 PM
I keep getting this message when i go to particular websites...i've been trying to figure out what this is all day.......i've been to every website but i don't understand any of them.. can someone please help me! thanks Glenn...more >>

Messenger service pop ups
Posted by MT at 1/24/2004 6:52:50 PM
Whenever I am connected to AOL I receive pop ups. But the pop ups seem to be coming from my own computer and not from aol or IE. It shows them as if they are a file, and at the top it says "Messenger Service" Is this a virus? If not what is it? And how can I stop it? Thanks SOOOOOO...more >>

Server attack IIS/5.0 but why does IIS show 200 return codes for HEAD /c/winnt/system32/cmd.exe ?
Posted by David Martin at 1/24/2004 11:42:15 AM
Last night I experienced a server attack on IIS 5.0 - with all patches in place (thankfully). The logs are available on http://www.skill-it.com/Dave/www.asp and are quite interesting - as well as showing attempts to infect with the the CODE RED II worm they show what I think is a manual attemp...more >>

IP Address
Posted by anonymous NO[at]SPAM discussions.microsoft.com at 1/24/2004 11:08:11 AM
Is it possible for some site or someone to get your IP address and hack into my computer and then substitute their own IP address...Odd that I am getting error messages saying IP address conflict with another IP address......more >>

Want to prevent downloads on specific pages
Posted by Matty at 1/24/2004 9:51:36 AM
I have a web pages that have graphics of document files that we sell, and I want to prevent downloads of the graphics, which are copywrited and could be used to create the document files. How do you do that? I'm experienced with NTFS file permissions, but I'm not sure what settings are r...more >>

IIS LogParser 2.1 COM Object - Syntax for "FROM" statement with long filename?
Posted by Alex K. Angelopoulos [MVP] at 1/24/2004 8:13:28 AM
[cross-posted to scripting.wsh and likely most relevant IIS group, inetserver.iis.security] Can anyone shed light on a problem I'm having using the IIS LogParser COM object to query CSV files? I cannot successfully read files with long names; if I quote them the log parser utility appears t...more >>

Question On Internet Access While Logged In As VPN CLient
Posted by JIMB at 1/24/2004 7:07:55 AM
Question On Internet Access While Logged In As VPN CLient We have MSESKSB SERVER w\Firewall. My question is, can the VPN (outside!) (WAN,) client's while logged in to the Server & going through our Firewall, be able to access the internet through another port on the Firewall or from the...more >>

.NET HttpModule & NTLM Integrated Authentication
Posted by Rob Mayo at 1/23/2004 6:45:07 PM
What I'm trying to do is Create an ASP.Net app that has both Windows-authenticated users and Anonymous users. The idea is this: When authenticated users attempt to access the site, their credentials are passed to the Request, and I use the DOMAIN\USER value via the AUTH_USER server variable to...more >>

Help Mozillia and IIS 6.0
Posted by Chris at 1/23/2004 1:53:25 PM
Ok--- I have a site that uses custom extensions for a web app I define the mime types like this .* application/octet-stream I have a index.htm page that redirects the user to a download,htm or activex.htm page depending on the browser type this works perfect in IIS 5.0 but in 6.0 it trys t...more >>

OWA Access error
Posted by Don H at 1/23/2004 1:46:35 PM
I get prompted 3 times for username and password to try and logon to OWA 5.5. I found the fix on the knowledgebase but it still doesn't work. What is wrong with my IIS configuration??? Thanks in advance......more >>


DevelopmentNow Blog