Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
all groups > iis security > january 2004 > threads for january 22 - 28, 2004

Filter by week: 1 2 3 4 5

IIS/SQL Crashing
Posted by Robert Abela at 1/28/2004 4:20:05 PM
Hi we run a website based on htm/html pages, asp scripts and an SQL backend. Before we had a problem and were having a lot of events in the sys event log and after some time, if i try to access the website i would have an error "Service Unavailable" Then i turned the web server to run in "Iso...more >>


IISAdmPwd
Posted by Rob Edwards at 1/28/2004 12:09:37 PM
After acquiring several new companies. They are still logging on to their own domains (not members of our forest) We want them to be able to access Intranet sites.... there AD accounts have been created with the default "User must change password on next logon" They are not logging on to ou...more >>

Post command in IIS 6.0
Posted by Rich at 1/28/2004 11:47:24 AM
I've upgraded my Windows 2000 Server to 2003, and IIS to version 6.0, and my post procedure no longer works in the application I'm hosting. The app is built on .NET. Any ideas of why it no longer works after the upgrade?...more >>

Secure FTP
Posted by Fabrizio Bocci at 1/28/2004 11:28:02 AM
I've been asked to create an FTP secure site (i guess and ftps:// connection). How can i do this in Windows 2000? thanks in advance ...more >>

IIS Client Certificate Mapping
Posted by David Smith at 1/28/2004 9:48:42 AM
Has anyone set up a system wher users authenticate using PKI Client Certificates? I am doing such a thing right now and using the Many-to-One mapping feature for IIS to map all certificates from a particular Issuer to the "\Everyone" user account. I have required Client Certificates as wel...more >>

IIS acessing SQL if not in the same domain
Posted by Michael G. Schneider at 1/28/2004 9:23:48 AM
Suppose you have two Windows 2000 servers. One is running MS IIS, the other is running the MS SQL Server. The IIS is accessible from the internet. Due to security reasons the servers are not in the same domain, actually they are standalone member servers. For accessing the SQL from the IIS, a ...more >>

backdoor.subseven trojan
Posted by Dale Motschman at 1/28/2004 8:14:26 AM
I keep getting this message "runtime error 216 at 013f3942. I checked this out on google and was told I have a backdoor. subseven trojan. I have checked and ran 4 different antivirus programs and none of the can find the trojan. I need to know how to get rid of it...Thanks...more >>

Access intranet from lan and internet
Posted by Update at 1/28/2004 2:26:08 AM
How do I best configure our iis6.0 if I want to access a intranet site locally in the lan without entering login and password but from the internet it must have authentication. Regards, Patrik ...more >>



Granting web access to single users
Posted by Enrico at 1/28/2004 1:39:57 AM
I'm setting up a projects' web and would like to grant access to projects selectively, i.e., specific users should access only specific projects. The IIS is set to request Windows authentication. The PROJECTS folder ACL grants list access to Domain Users. The ASP page PROJECTS\LIST.ASP disp...more >>

Opening cmd.exe to IUSR_<machine>
Posted by Brad Watson at 1/27/2004 10:38:01 PM
Hi, I'm developing a publicly accessible Perl CGI script that needs to run shell commands such as: my $suggestions = `echo misspelt | aspell.exe -a`; Perl requires use of cmd.exe in order to execute this command and on Windows 2003/IIS 6.0 this is not possible under the default securi...more >>

HTTP Error 401.5
Posted by kennethw NO[at]SPAM ozemail.com.au at 1/27/2004 8:59:32 PM
I have done a quick scan over the newsgroups and didn't find any postings about this so I thought I'd quickly post it and see if anyone has had the same error or was aware of this. We use Windows Server 2003 that hosts an ASP web site for our local office intranet. One of our pages, that displ...more >>

Invalid signature when restoring metabase
Posted by BG at 1/27/2004 4:28:49 PM
I get the message Invalid Signature when I try to restore my IIS metabase. Any ideas? I had to re-install Windows 2003 on this server. I backed up the files and restored and now I am attempting to restore the metabase using the Backup/Restore Configuration in IIS, when this error occurs. ...more >>

can my x get into my oe with the servers password
Posted by Anita at 1/27/2004 3:26:07 PM
I know this may seem thick, but my x has my password for my server (teleos in Germany) does that mean he can go into this server on his computer from another country and then download my OE files, I have changed my hotmail, and yahoo, passwords but will he beable to see what goes on the OE...more >>

Local and doman db access with a twist!
Posted by John Hattersley at 1/27/2004 2:45:30 PM
Hi all, I have a scenario where I need to have both local users and domain users accessing a site. I've set this up fine, I've: 1) set the Auth Mode to Basic 2) added the 'Domain Users' group to a local group 3) set security on the home folder to the local group created in step 2. Every...more >>

II6 & Read-Only Properties
Posted by AspDotNetDeveloper at 1/27/2004 1:26:38 PM
One thing I noticed recently about Win 2k3 Server, and IIS6, is that it defaults to Read-Only permissions at the NTFS file and folders property level. I discovered this, when trying to get the FileSystemObject to write to a text file. All the permissions were set ok, but I discovered every folde...more >>

Automatic ssl certificate client install?
Posted by Update at 1/27/2004 1:09:13 PM
I have installed ssl on our exchange 2003 owa. Exported the certificat to a .crt file for the clients. Installing it manually in the trusted root cerificate authorities on the client works. In some cases I got a client authentication popup with no certificates in it. Enabling "Don't prompt ...more >>

Windows command line FTP
Posted by Al at 1/27/2004 12:11:25 PM
Problem: Command line FTP returns this message when trying to create a sub-directory using the commands mkd or mkdir. "500 command not permitted through gateway" I am running through a Gateway. I can send files, delete files even rename files but can not create sub directories. What is ...more >>

URLscan
Posted by Pat at 1/27/2004 9:07:50 AM
what do I need to do to get frontpage to work on a IIS 5 server with URLscan?...more >>

Invalid ProgID attribute?
Posted by Michel at 1/27/2004 8:10:05 AM
Hello support Team, Why do I get the following error when I try to browse an .ASP page in my Win2003-IIS6.0 web server: "Active Server Pages error 'ASP 0134' Invalid ProgID attribute /LM/W3SVC/1/ROOT/global.asa, line 1 The object has an invalid ProgID of 'MSWC.MyInfo'." The 'global....more >>

How to identify the web site with the IIS instance name
Posted by Mike at 1/27/2004 4:23:03 AM
In my logging, How can i determine what web site the log applies to when all I have is the instance name ? For example, if the Instance name is W3SVC15, how do I know which web site this applies to ? tia, Mike...more >>

Allowing access To Our INTRANET site from the outside
Posted by skeet4me NO[at]SPAM comcast.net at 1/26/2004 10:28:05 AM
I am hoping someone might give me some better ideas than what I have come up with on my own. I have our Internet Site in the DMZ and our Intranet site is inside and can only be accessed from the inside. The big bosses want the board to have access to our intranet site. My first solution was t...more >>

outrageous pop-ups
Posted by Jocelyn at 1/26/2004 9:22:03 AM
sometimes, while I'm on the internet a series of pops ups come up talking about I "only have seconds" and that things are wrong, but I found they come from this site http://www.passthison.com/r4/?s43. I don't advise anyone to go there, i haven't been, but then it changes your home page to ...more >>

OK---
Posted by Chris at 1/26/2004 7:35:47 AM
I can't even serv a simple web page from IIS 6.0 to netscape i go to a download page that has just images and a link an it gives me the error " the file "download.htm" is of type text/html (hypertext markup language) and netscape does not know how to handle this type of file" ANY ideas ...more >>

block chat room and downloading
Posted by razzooo at 1/26/2004 4:30:33 AM
i need bolck chat room and downloading software from internet in my office .what i do...more >>

block installing
Posted by razakuwait NO[at]SPAM hotmail.com at 1/26/2004 4:21:25 AM
i would like to know, i need block downloading from internet please inform me thanks razak...more >>

ssl and the win2k profesional operating system
Posted by Rea Peleg at 1/26/2004 12:13:56 AM
Hi all is there a problem with implementing ssl on a win2k professional machine? I have read in a msdn 'how to' (regarding Building Secure ASP.NET Applications) that a win2k server family is a must. TIA Rea ...more >>

Microsoft VBScript runtime error '800a01a8'
Posted by Glenn at 1/25/2004 6:38:12 PM
I keep getting this message when i go to particular websites...i've been trying to figure out what this is all day.......i've been to every website but i don't understand any of them.. can someone please help me! thanks Glenn...more >>

Messenger service pop ups
Posted by MT at 1/24/2004 6:52:50 PM
Whenever I am connected to AOL I receive pop ups. But the pop ups seem to be coming from my own computer and not from aol or IE. It shows them as if they are a file, and at the top it says "Messenger Service" Is this a virus? If not what is it? And how can I stop it? Thanks SOOOOOO...more >>

Server attack IIS/5.0 but why does IIS show 200 return codes for HEAD /c/winnt/system32/cmd.exe ?
Posted by David Martin at 1/24/2004 11:42:15 AM
Last night I experienced a server attack on IIS 5.0 - with all patches in place (thankfully). The logs are available on http://www.skill-it.com/Dave/www.asp and are quite interesting - as well as showing attempts to infect with the the CODE RED II worm they show what I think is a manual attemp...more >>

IP Address
Posted by anonymous NO[at]SPAM discussions.microsoft.com at 1/24/2004 11:08:11 AM
Is it possible for some site or someone to get your IP address and hack into my computer and then substitute their own IP address...Odd that I am getting error messages saying IP address conflict with another IP address......more >>

Want to prevent downloads on specific pages
Posted by Matty at 1/24/2004 9:51:36 AM
I have a web pages that have graphics of document files that we sell, and I want to prevent downloads of the graphics, which are copywrited and could be used to create the document files. How do you do that? I'm experienced with NTFS file permissions, but I'm not sure what settings are r...more >>

IIS LogParser 2.1 COM Object - Syntax for "FROM" statement with long filename?
Posted by Alex K. Angelopoulos [MVP] at 1/24/2004 8:13:28 AM
[cross-posted to scripting.wsh and likely most relevant IIS group, inetserver.iis.security] Can anyone shed light on a problem I'm having using the IIS LogParser COM object to query CSV files? I cannot successfully read files with long names; if I quote them the log parser utility appears t...more >>

Question On Internet Access While Logged In As VPN CLient
Posted by JIMB at 1/24/2004 7:07:55 AM
Question On Internet Access While Logged In As VPN CLient We have MSESKSB SERVER w\Firewall. My question is, can the VPN (outside!) (WAN,) client's while logged in to the Server & going through our Firewall, be able to access the internet through another port on the Firewall or from the...more >>

.NET HttpModule & NTLM Integrated Authentication
Posted by Rob Mayo at 1/23/2004 6:45:07 PM
What I'm trying to do is Create an ASP.Net app that has both Windows-authenticated users and Anonymous users. The idea is this: When authenticated users attempt to access the site, their credentials are passed to the Request, and I use the DOMAIN\USER value via the AUTH_USER server variable to...more >>

Help Mozillia and IIS 6.0
Posted by Chris at 1/23/2004 1:53:25 PM
Ok--- I have a site that uses custom extensions for a web app I define the mime types like this .* application/octet-stream I have a index.htm page that redirects the user to a download,htm or activex.htm page depending on the browser type this works perfect in IIS 5.0 but in 6.0 it trys t...more >>

OWA Access error
Posted by Don H at 1/23/2004 1:46:35 PM
I get prompted 3 times for username and password to try and logon to OWA 5.5. I found the fix on the knowledgebase but it still doesn't work. What is wrong with my IIS configuration??? Thanks in advance......more >>

SSL with internal CA and public clients
Posted by Bobby at 1/23/2004 1:40:12 PM
We have 3 web sites that we have individual verisign ssl certificates for. We would like to run our own CA server to cut down costs. I've setup a test server with an SSL certificate generated by our internal CA server. Our domain computers can access the server over SSL fine. External ...more >>

Problem with IIS6.
Posted by Alexey Kurnosov at 1/23/2004 10:12:03 AM
I had some configuration based on IIS 5. After installation of a new MS Server 2003 with IIS 6.0 this site dosn't work more. I suppose that IIS 6.0 isn't able to perform .dll as a script. How is it possible to force IIS to do it? Thanks in advance. ...more >>

How to have clients request a certificate in AD-mode which are not automatically issued?
Posted by Jochen Ruhland at 1/22/2004 10:33:56 PM
Hi, I want to secure some webapplication so I installed a enterprise CA and issued a SSL-certificate for the server. Works fine. Now I want that users must use a certificate to automatically log in. No problem, I put the IIS in AD-mapping-mode, the client requests a certificate through http...more >>

Another IIS Permissions Question
Posted by CT1705 NO[at]SPAM hotmail.com at 1/22/2004 8:16:21 PM
I'm trying to straighten out a mess at my new office on a web server running IIS5 on Win2000. Running basically as an ISP, have 8 websites running on the IIS server, with FrontPage Server Extensions installed. Most of our clients aren't allowed to upload their own files, however, a couple s...more >>

e-mail from MICROSOFT
Posted by fz1169wu at 1/22/2004 6:38:15 PM
I have recieved about 15 e-mails marked as "MICROSOFT use this patch immediately!" I thought microsoft never sent E- mail of this kind?how do I verify if this is from microsoft or if it's a virus in discuise???...more >>

Security Lock not displayed after SSL Certificates imported.
Posted by Discussion at 1/22/2004 5:11:06 PM
Hi All, I got a SSL certificate issued and then installed it on my IIS5 box w/ Win 2000 Adv Server. Installed it on the default website since there is only 1 website via Directory Security. I did not ENABLE the "Require Securechannel SSL" via EDIT as I don't want the whole site to be encrypted. I...more >>

Users
Posted by Chris Miller at 1/22/2004 2:58:47 PM
I've got a few sites I host on my Win2k3 box with IIS 6.0. They are all ASP.NET sites. I have it broken down into 2 application pools. Could someone point me in the right direction for setting up user security? I've got both pools running a "Network Service" right now, but I've got a feeling that...more >>

E Mail Messages
Posted by Chester Hill at 1/22/2004 12:10:24 PM
I am receiving messages from the following: Admin MS Internet Mail Storage, Inet Mail Delivery Systems, Network Message Storage They indicate I have sent mail to people or addresses unknown to me. I have not sent messages to them. How can this be stopped. I do not want to open these ...more >>

IIS permissions
Posted by Auddog at 1/22/2004 11:19:53 AM
I have taken over a new position and I'm trying to get a grasp on the last IT admin's settings. We have an SSL page on our website (IIS 5) for employee login. We currently have the permission set to Anonymous access as well as Integrated Windows authentication. I have 2 users that are denied ...more >>

SUS10SP1 with ShrPntSrvcs on IIS60?
Posted by Michel at 1/22/2004 7:42:13 AM
I have installed SUS1.0-SP1 successfully and tested it with clients. I have IIS6.0 and all worked fine... until I installed SharePoint Team Services 2.0. The SUSAdmin page is found no more and the AutoUpdates Clients can't find the "content" and SUS-server to connect. Nothing is written in...more >>

Windows integrated authentication with site content on UNC share...
Posted by pdabak NO[at]SPAM yahoo.com at 1/22/2004 7:32:34 AM
Hello, I have the following setup Machine setup ------------- Windows 2003 Domain Controller (Domain function level is Windows 2000 native). Windows 2003 server running IIS 6 Windows 2003 server acting as a file server. Configuration ------------- 1. The file server has a share called...more >>

New to IIS Security
Posted by darkangelforyou2003 NO[at]SPAM yahoo.com at 1/22/2004 6:41:10 AM
Hello All, I am new to the world of IIS. I have heard a lot about the hacking on IIS server. I would appreciate if some body can please show me some guides, where in i can not only test my server by breaking into it but also harden it. I want a sort of how-to book where in i can get to kno...more >>


DevelopmentNow Blog