all groups > iis security > january 2004 > threads for january 22 - 28, 2004
Filter by week: 1 2 3 4 5
IIS/SQL Crashing
Posted by Robert Abela at 1/28/2004 4:20:05 PM
Hi we run a website based on htm/html pages, asp scripts and an SQL backend.
Before we had a problem and were having a lot of events in the sys event log
and after some time, if i try to access the website i would have an error
"Service Unavailable"
Then i turned the web server to run in "Iso... more >>
IISAdmPwd
Posted by Rob Edwards at 1/28/2004 12:09:37 PM
After acquiring several new companies.
They are still logging on to their own domains (not members of our forest)
We want them to be able to access Intranet sites.... there AD accounts have
been created with the default "User must change password on next logon"
They are not logging on to ou... more >>
Post command in IIS 6.0
Posted by Rich at 1/28/2004 11:47:24 AM
I've upgraded my Windows 2000 Server to 2003, and IIS to
version 6.0, and my post procedure no longer works in the
application I'm hosting. The app is built on .NET. Any
ideas of why it no longer works after the upgrade?... more >>
Secure FTP
Posted by Fabrizio Bocci at 1/28/2004 11:28:02 AM
I've been asked to create an FTP secure site (i guess and ftps://
connection). How can i do this in Windows 2000?
thanks in advance
... more >>
IIS Client Certificate Mapping
Posted by David Smith at 1/28/2004 9:48:42 AM
Has anyone set up a system wher users authenticate using
PKI Client Certificates?
I am doing such a thing right now and using the Many-to-One
mapping feature for IIS to map all certificates from a
particular Issuer to the "\Everyone" user account. I have
required Client Certificates as wel... more >>
IIS acessing SQL if not in the same domain
Posted by Michael G. Schneider at 1/28/2004 9:23:48 AM
Suppose you have two Windows 2000 servers. One is running MS IIS, the other
is running the MS SQL Server. The IIS is accessible from the internet. Due
to security reasons the servers are not in the same domain, actually they
are standalone member servers.
For accessing the SQL from the IIS, a ... more >>
backdoor.subseven trojan
Posted by Dale Motschman at 1/28/2004 8:14:26 AM
I keep getting this message "runtime error 216 at
013f3942. I checked this out on google and was told I have
a backdoor. subseven trojan. I have checked and ran 4
different antivirus programs and none of the can find the
trojan. I need to know how to get rid of it...Thanks... more >>
Access intranet from lan and internet
Posted by Update at 1/28/2004 2:26:08 AM
How do I best configure our iis6.0 if I want to access a
intranet site locally in the lan without entering login
and password but from the internet it must have
authentication.
Regards,
Patrik
... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Granting web access to single users
Posted by Enrico at 1/28/2004 1:39:57 AM
I'm setting up a projects' web and would like to grant
access to projects selectively, i.e., specific users
should access only specific projects. The IIS is set to
request Windows authentication.
The PROJECTS folder ACL grants list access to Domain
Users. The ASP page PROJECTS\LIST.ASP disp... more >>
Opening cmd.exe to IUSR_<machine>
Posted by Brad Watson at 1/27/2004 10:38:01 PM
Hi,
I'm developing a publicly accessible Perl CGI
script that needs to run shell commands such as:
my $suggestions = `echo misspelt | aspell.exe -a`;
Perl requires use of cmd.exe in order to execute
this command and on Windows 2003/IIS 6.0 this is
not possible under the default securi... more >>
HTTP Error 401.5
Posted by kennethw NO[at]SPAM ozemail.com.au at 1/27/2004 8:59:32 PM
I have done a quick scan over the newsgroups and didn't find any
postings about this so I thought I'd quickly post it and see if anyone
has had the same error or was aware of this.
We use Windows Server 2003 that hosts an ASP web site for our local
office intranet. One of our pages, that displ... more >>
Invalid signature when restoring metabase
Posted by BG at 1/27/2004 4:28:49 PM
I get the message Invalid Signature when I try to restore my IIS metabase.
Any ideas? I had to re-install Windows 2003 on this server. I backed up the
files and restored and now I am attempting to restore the metabase using the
Backup/Restore Configuration in IIS, when this error occurs.
... more >>
can my x get into my oe with the servers password
Posted by Anita at 1/27/2004 3:26:07 PM
I know this may seem thick, but my x has my password for
my server (teleos in Germany) does that mean he can go
into this server on his computer from another country and
then download my OE files, I have changed my hotmail, and
yahoo, passwords but will he beable to see what goes on
the OE... more >>
Local and doman db access with a twist!
Posted by John Hattersley at 1/27/2004 2:45:30 PM
Hi all,
I have a scenario where I need to have both local users and domain users
accessing a site. I've set this up fine, I've:
1) set the Auth Mode to Basic
2) added the 'Domain Users' group to a local group
3) set security on the home folder to the local group created in step 2.
Every... more >>
II6 & Read-Only Properties
Posted by AspDotNetDeveloper at 1/27/2004 1:26:38 PM
One thing I noticed recently about Win 2k3 Server, and IIS6, is that it
defaults to Read-Only permissions at the NTFS file and folders property
level. I discovered this, when trying to get the FileSystemObject to write
to a text file. All the permissions were set ok, but I discovered every
folde... more >>
Automatic ssl certificate client install?
Posted by Update at 1/27/2004 1:09:13 PM
I have installed ssl on our exchange 2003 owa.
Exported the certificat to a .crt file for the clients.
Installing it manually in the trusted root cerificate
authorities on the client works.
In some cases I got a client authentication popup with no
certificates in it.
Enabling "Don't prompt ... more >>
Windows command line FTP
Posted by Al at 1/27/2004 12:11:25 PM
Problem: Command line FTP returns this message when
trying to create a sub-directory using the commands mkd or
mkdir. "500 command not permitted through gateway"
I am running through a Gateway. I can send files, delete
files even rename files but can not create sub directories.
What is ... more >>
URLscan
Posted by Pat at 1/27/2004 9:07:50 AM
what do I need to do to get frontpage to work on a IIS 5 server with
URLscan?... more >>
Invalid ProgID attribute?
Posted by Michel at 1/27/2004 8:10:05 AM
Hello support Team,
Why do I get the following error when I try to browse
an .ASP page in my Win2003-IIS6.0 web server:
"Active Server Pages error 'ASP 0134'
Invalid ProgID attribute
/LM/W3SVC/1/ROOT/global.asa, line 1
The object has an invalid ProgID of 'MSWC.MyInfo'."
The 'global.... more >>
How to identify the web site with the IIS instance name
Posted by Mike at 1/27/2004 4:23:03 AM
In my logging,
How can i determine what web site the log applies to when
all I have is the instance name ?
For example, if the Instance name is W3SVC15, how do I
know which web site this applies to ?
tia,
Mike... more >>
Allowing access To Our INTRANET site from the outside
Posted by skeet4me NO[at]SPAM comcast.net at 1/26/2004 10:28:05 AM
I am hoping someone might give me some better ideas than what I have
come up with on my own. I have our Internet Site in the DMZ and our
Intranet site is inside and can only be accessed from the inside. The
big bosses want the board to have access to our intranet site. My
first solution was t... more >>
outrageous pop-ups
Posted by Jocelyn at 1/26/2004 9:22:03 AM
sometimes, while I'm on the internet a series of pops ups
come up talking about I "only have seconds" and that
things are wrong, but I found they come from this site
http://www.passthison.com/r4/?s43. I don't advise anyone
to go there, i haven't been, but then it changes your
home page to ... more >>
OK---
Posted by Chris at 1/26/2004 7:35:47 AM
I can't even serv a simple web page from IIS 6.0 to
netscape i go to a download page that has just images and
a link an it gives me the error
" the file "download.htm" is of type text/html (hypertext
markup language) and netscape does not know how to handle
this type of file"
ANY ideas ... more >>
block chat room and downloading
Posted by razzooo at 1/26/2004 4:30:33 AM
i need bolck chat room and downloading software from
internet in my office .what i do... more >>
block installing
Posted by razakuwait NO[at]SPAM hotmail.com at 1/26/2004 4:21:25 AM
i would like to know, i need block downloading from
internet
please inform me
thanks
razak... more >>
ssl and the win2k profesional operating system
Posted by Rea Peleg at 1/26/2004 12:13:56 AM
Hi all
is there a problem with implementing ssl
on a win2k professional machine?
I have read in a msdn 'how to' (regarding Building Secure ASP.NET
Applications)
that a win2k server family is a must.
TIA
Rea
... more >>
Microsoft VBScript runtime error '800a01a8'
Posted by Glenn at 1/25/2004 6:38:12 PM
I keep getting this message when i go to particular
websites...i've been trying to figure out what this is
all day.......i've been to every website but i don't
understand any of them..
can someone please help me!
thanks
Glenn... more >>
Messenger service pop ups
Posted by MT at 1/24/2004 6:52:50 PM
Whenever I am connected to AOL I receive pop ups. But
the pop ups seem to be coming from my own computer and
not from aol or IE. It shows them as if they are a file,
and at the top it says "Messenger Service"
Is this a virus? If not what is it? And how can I stop
it?
Thanks SOOOOOO... more >>
Server attack IIS/5.0 but why does IIS show 200 return codes for HEAD /c/winnt/system32/cmd.exe ?
Posted by David Martin at 1/24/2004 11:42:15 AM
Last night I experienced a server attack on IIS 5.0 - with all patches in
place (thankfully).
The logs are available on http://www.skill-it.com/Dave/www.asp and are quite
interesting
- as well as showing attempts to infect with the the CODE RED II worm they
show
what I think is a manual attemp... more >>
IP Address
Posted by anonymous NO[at]SPAM discussions.microsoft.com at 1/24/2004 11:08:11 AM
Is it possible for some site or someone to get your IP
address and hack into my computer and then substitute
their own IP address...Odd that I am getting error
messages saying IP address conflict with another IP
address...... more >>
Want to prevent downloads on specific pages
Posted by Matty at 1/24/2004 9:51:36 AM
I have a web pages that have graphics of document files
that we sell, and I want to prevent downloads of the
graphics, which are copywrited and could be used to create
the document files.
How do you do that? I'm experienced with NTFS file
permissions, but I'm not sure what settings are r... more >>
IIS LogParser 2.1 COM Object - Syntax for "FROM" statement with long filename?
Posted by Alex K. Angelopoulos [MVP] at 1/24/2004 8:13:28 AM
[cross-posted to scripting.wsh and likely most relevant IIS group,
inetserver.iis.security]
Can anyone shed light on a problem I'm having using the IIS LogParser COM
object to query CSV files?
I cannot successfully read files with long names; if I quote them the log
parser utility appears t... more >>
Question On Internet Access While Logged In As VPN CLient
Posted by JIMB at 1/24/2004 7:07:55 AM
Question On Internet Access While Logged In As VPN CLient
We have MSESKSB SERVER w\Firewall.
My question is, can the VPN (outside!) (WAN,) client's
while logged in to the Server & going through our
Firewall, be able to access the internet through another
port on the Firewall or from the... more >>
.NET HttpModule & NTLM Integrated Authentication
Posted by Rob Mayo at 1/23/2004 6:45:07 PM
What I'm trying to do is Create an ASP.Net app that has both
Windows-authenticated users and Anonymous users. The idea is this:
When authenticated users attempt to access the site, their credentials are
passed to the Request, and I use the DOMAIN\USER value via the AUTH_USER
server variable to... more >>
Help Mozillia and IIS 6.0
Posted by Chris at 1/23/2004 1:53:25 PM
Ok--- I have a site that uses custom extensions for a web
app I define the mime types like this .*
application/octet-stream
I have a index.htm page that redirects the user to a
download,htm or activex.htm page depending on the browser
type this works perfect in IIS 5.0 but in 6.0 it trys t... more >>
OWA Access error
Posted by Don H at 1/23/2004 1:46:35 PM
I get prompted 3 times for username and password to try
and logon to OWA 5.5. I found the fix on the knowledgebase
but it still doesn't work. What is wrong with my IIS
configuration???
Thanks in advance...... more >>
SSL with internal CA and public clients
Posted by Bobby at 1/23/2004 1:40:12 PM
We have 3 web sites that we have individual verisign ssl
certificates for. We would like to run our own CA server
to cut down costs.
I've setup a test server with an SSL certificate generated
by our internal CA server. Our domain computers can
access the server over SSL fine. External ... more >>
Problem with IIS6.
Posted by Alexey Kurnosov at 1/23/2004 10:12:03 AM
I had some configuration based on IIS 5. After installation of
a new MS Server 2003 with IIS 6.0 this site dosn't work
more. I suppose that IIS 6.0 isn't able to perform .dll as a
script. How is it possible to force IIS to do it?
Thanks in advance.
... more >>
How to have clients request a certificate in AD-mode which are not automatically issued?
Posted by Jochen Ruhland at 1/22/2004 10:33:56 PM
Hi,
I want to secure some webapplication so I installed a enterprise CA and
issued a SSL-certificate for the server. Works fine.
Now I want that users must use a certificate to automatically log in. No
problem, I put the IIS in AD-mapping-mode, the client requests a
certificate through http... more >>
Another IIS Permissions Question
Posted by CT1705 NO[at]SPAM hotmail.com at 1/22/2004 8:16:21 PM
I'm trying to straighten out a mess at my new office on a web server
running IIS5 on Win2000.
Running basically as an ISP, have 8 websites running on the IIS
server, with FrontPage Server Extensions installed.
Most of our clients aren't allowed to upload their own files, however,
a couple s... more >>
e-mail from MICROSOFT
Posted by fz1169wu at 1/22/2004 6:38:15 PM
I have recieved about 15 e-mails marked as
"MICROSOFT use this patch immediately!" I thought
microsoft never sent E- mail of this kind?how do I verify
if this is from microsoft or if it's a virus in
discuise???... more >>
Security Lock not displayed after SSL Certificates imported.
Posted by Discussion at 1/22/2004 5:11:06 PM
Hi All,
I got a SSL certificate issued and then installed it on my IIS5 box w/ Win 2000 Adv Server. Installed it on the default website since there is only 1 website via Directory Security. I did not ENABLE the "Require Securechannel SSL" via EDIT as I don't want the whole site to be encrypted. I... more >>
Users
Posted by Chris Miller at 1/22/2004 2:58:47 PM
I've got a few sites I host on my Win2k3 box with IIS 6.0. They are all
ASP.NET sites. I have it broken down into 2 application pools. Could someone
point me in the right direction for setting up user security? I've got both
pools running a "Network Service" right now, but I've got a feeling that... more >>
E Mail Messages
Posted by Chester Hill at 1/22/2004 12:10:24 PM
I am receiving messages from the following: Admin
MS Internet Mail Storage, Inet Mail Delivery Systems,
Network Message Storage
They indicate I have sent mail to people or addresses
unknown to me. I have not sent messages to them. How
can this be stopped. I do not want to open these ... more >>
IIS permissions
Posted by Auddog at 1/22/2004 11:19:53 AM
I have taken over a new position and I'm trying to get a grasp on the last
IT admin's settings. We have an SSL page on our website (IIS 5) for
employee login. We currently have the permission set to Anonymous access as
well as Integrated Windows authentication. I have 2 users that are denied
... more >>
SUS10SP1 with ShrPntSrvcs on IIS60?
Posted by Michel at 1/22/2004 7:42:13 AM
I have installed SUS1.0-SP1 successfully and tested it
with clients. I have IIS6.0 and all worked fine... until
I installed SharePoint Team Services 2.0. The SUSAdmin
page is found no more and the AutoUpdates Clients can't
find the "content" and SUS-server to connect. Nothing is
written in... more >>
Windows integrated authentication with site content on UNC share...
Posted by pdabak NO[at]SPAM yahoo.com at 1/22/2004 7:32:34 AM
Hello,
I have the following setup
Machine setup
-------------
Windows 2003 Domain Controller (Domain function level is Windows 2000
native). Windows 2003 server running IIS 6
Windows 2003 server acting as a file server.
Configuration
-------------
1. The file server has a share called... more >>
New to IIS Security
Posted by darkangelforyou2003 NO[at]SPAM yahoo.com at 1/22/2004 6:41:10 AM
Hello All,
I am new to the world of IIS.
I have heard a lot about the hacking on IIS server.
I would appreciate if some body can please show me some guides, where
in i can not only test my server by breaking into it but also harden
it.
I want a sort of how-to book where in i can get to kno... more >>
|