all groups > iis security > january 2004 > threads for january 8 - 14, 2004
Filter by week: 1 2 3 4 5
Security of Excels and Documents on IIS
Posted by Avi at 1/14/2004 9:51:53 PM
Hi,
The pages on our IIS are a mix of ASP and documents (PDFs,
Docs, Excels etc).
The ASP pages are secured using a session. The session is
set only at the login page after proper authentication of
the ID and password. The interior ASP pages check for the
session and display only if th... more >>
http error 405
Posted by DOVE at 1/14/2004 8:37:40 PM
What is the cause of this error?... more >>
Trouble replacing certificate
Posted by Art O'Malley at 1/14/2004 6:15:22 PM
I was quite familiar installing, renewing & replacing certificates in IIS
4.0, but I having trouble with IIS 5.0 certificate wizard.
I have an existing Verisign certificate expiring on the 28th, but I'm not
able to easily renew because the organization name of the corporation has
change since ... more >>
-2147023569 error from IIS Password Change
Posted by Fred Yarbrough at 1/14/2004 5:08:35 PM
I am getting the following error when using the IIS password change site.
Normally I can change the password fine but occasionally my users get
this -2147023569 error returned. Has anyone seen this or know what it is?
NT 4.0 domain SP6a
Thanks,
Fred
... more >>
Loading IIS Users from TextFile.
Posted by John at 1/14/2004 4:04:49 PM
I have a client who is trying to load IIS Users from a CSV(textfile) of
names. They are looking at using some template to do the work. The client
has over 500 names to create IIS Users.
Is there a template or batch process that can be used to automate the
procedure.
Thank You for your Hel... more >>
unwanted links
Posted by jon at 1/14/2004 2:32:56 PM
HI my name is Jon and I have been having troubles
deleting certain internet links off my desk top...
they always come from the same places...
webforhumans.com, about-blank.biz, and idgsearch.com....
every time i log onto my computer these icons pop up onto
my desktop, I delete them and then ... more >>
annoying icons appearing on desktop
Posted by anonymous NO[at]SPAM discussions.microsoft.com at 1/14/2004 2:24:46 PM
HI my name is Jon and I have been having troubles
deleting certain internet links off my desk top...
they always come from the same places...
webforhumans.com, about-blank.biz, and idgsearch.com....
every time i log onto my computer these icons pop up onto
my desktop, I delete them and then ... more >>
urlscan
Posted by hkwan at 1/14/2004 1:16:38 PM
I have URLSCAN on our production server. When I use site
manager to do a manual import to the production server,
URLSCAN appears to be blocking it due to the limits set
by MaxAllowedContentLength. I tried increasing
MaxAllowedContentLength to an extremely large number but
it did not help... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Disabling IIS
Posted by Amir M. at 1/14/2004 1:00:00 PM
Hi,
For security reasons, we would like to disable the IIS on
all our Win2K Server machines that don't use it. How do
we disable/disconnect it? Could we remove it completely?
Does disabling or removing it cause any problems?
Thanks... more >>
ftp security question
Posted by bbxrider at 1/14/2004 12:53:59 PM
win2k adv serv/ iis5.0
this my first web site, this is my thinking for security for an application
that needs to write, copy, and delete flat files over the internet
the 1 and only basic internet user acct has privileges to write new flat
files to one directory, directly beneath the std inetpu... more >>
SSL cert problem
Posted by Frank J at 1/14/2004 10:28:57 AM
We are preparing new server in advance so that the
website down time will be minimium.
We export and import the SSL certificate from production
server to the new server. Everything is fine but when
browse to the website on new server, we get an error
saying the certificate is not valid or... more >>
Failed to create 'CertificateAuthority.Request' object
Posted by Zyck at 1/14/2004 10:14:07 AM
I've setup a Certificate Authority on W2003. I receive "Failed to create
'CertificateAuthority.Request' object" when I try to "Download CA
Certificate".
Any Idea?
Thanx.
... more >>
APSNET account permissions
Posted by Karin at 1/14/2004 6:50:20 AM
Dear all,
We'd like to setup an .NET framework on IIS 5.0. During
the installation of the framework the ASPNET account will
be created. My question now is, does this user has to be
in the admin group if the .NET framework will be used as
WebService?
Thanks for your help!
Cheers,
Karin... more >>
Allow file download only to subscribers
Posted by John Kotuby at 1/14/2004 6:49:42 AM
I have created a site with ASP (Active Server Pages). That requires a login
validated by an Access database. There is a file that I wish to be
accessible for download only by registered subscribers. All my ASP pages
check for the Userid/Password variables that I have set up, so a
non-subscriber ... more >>
IIS 5.1 (XP Pro) XML Security Issue
Posted by Richard Stewart at 1/14/2004 12:21:08 AM
I am running IIS 5.1 on XP Pro and running into an issue with an asp page this is trying to create an XMLDOM (see code snippet below). I get an error that object is required. After quite a bit of trial and error I think it is a security issue. If I change the IIS App to logon with windows (not an... more >>
Clean up CertSrv
Posted by i_robot73 NO[at]SPAM hotmail.com at 1/13/2004 6:04:50 PM
In my attempts to nullify my stupidy w/ ISS & SSL (hence 9 diff. cert.
req.) I made more of a mess than I needed to.
My ? being: Is there a way to 'cleanup' the Cert. Server &
remove/delete/nuke the other 'available certificates'??
Any help is appreciated.
David D.
(Network Engineer - M... more >>
IIS, OWA or AD problem ???!!!????
Posted by Bapu at 1/13/2004 4:58:32 PM
Administrator can log onto OWA over internet. A regualr
user cannot. The regular user and Administrator can log
into Outlook client.
What the heck is wrong?
I'm using Windows 2000 Server and a single Exchange 2000
Server both of which are my PDC. Software is vanilla
installations.
T... more >>
Internet Explorer Favorites Recreated
Posted by Roberta at 1/13/2004 3:09:53 PM
Please help me, I've spent over 3 hours on the phone with
Microsoft and they cant seem to fix my problem. My
brother was looking at porn sites over the holidays and
now my Internet Explorer Favorites are of kiddie porn
sites and even though I have deleted them ran spyware etc
and they sti... more >>
IIS - SSL Certificate
Posted by YoYo at 1/13/2004 2:44:37 PM
I have only my original certificate request file, and the
response file from the certificate issuer. How can I use
this to reinstall the certificate in IIS 5.0? Alas, I did
not back up the originally installed certificate as a .pfx
or .key.
Thanks for any help....... more >>
Problem with IIS 6.0
Posted by ericallenpaul NO[at]SPAM hotmail.com at 1/13/2004 1:53:17 PM
We recently upgraded to IIS 6.0 and Windows 2003 server and every
since we've upgraded we've been having an issue with authentication.
The web site in question is supposed to allow anonymous access, but
from time to time it will prompt for a username and password as if
authentication was turned ... more >>
AccessCheck problem
Posted by Jamie at 1/13/2004 1:49:01 PM
Hi all,
I have an ISAPI filter that determines a user's permissions from the ACL of
a file
using the 'AccessCheck' API call. This works fine on all of the platforms
except Windows 2003 server, where I'm having a strange problem. The
AccessCheck call is failing for users that are members of th... more >>
searchmeup.net popup
Posted by john at 1/13/2004 1:47:47 PM
How do I stop this from popping up on my computer??... more >>
How to create a cert for signing ActiveX using my own CA ???
Posted by SO at 1/13/2004 1:34:01 PM
Hello all,
I tried my best but could not find a solution for subj. There are
instructions for generating test cert signed by default test root or
signing with commercial CA like Thawte, Verisign etc., where actual request
process depends on a provider. But I need something in between.
What... more >>
Should a Domain member server be put into a DMZ.
Posted by Brian at 1/13/2004 12:34:05 PM
First some history,
I have a web server running IIS5. On a windows 2000
server, all service packs have been installed. currently
this server is standalone with the exception of ports open
on the firewall to a SQL server on the local network. By
stand alone I mean, it is in its own littl... more >>
Delay in posting change to html page after uploading via ftp.
Posted by Joe Hodosky at 1/13/2004 8:56:40 AM
Hello,
I have users that ftp up to our web server complaining that there changes are not being noticed immediately. Can anyone point me in the right area to decrease the time it takes for the server to recognize the change to a page.
Thanks in advanc
Joe Hodosky... more >>
Soap, Authentication & IIS anonymous user
Posted by Vince C. at 1/13/2004 12:32:49 AM
Hi.
I'm struggling with authentication and Soap Toolkit 3.0 under IIS 5 on W2K. I've
written an ASP web service on an IIS machine, say A, that has a client on an IIS
machine too, say B. Both machines A and B can be the same or distinct ones.
Consider both machines are part of the same domain f... more >>
401.3 error on all files in root for iis for win xp pro
Posted by saenen_chr NO[at]SPAM yahoo.com at 1/12/2004 11:47:18 PM
hey,
i am really new at this, so go easy on me. i found a lot of articles
on how to specify ntfs permissions on win2000 but this can't be
applied on xp pro.
does someone know what i have to do exactly to get rid of these 401.3
no permission errors for iis on WIN XP PRO;
with desperate gr... more >>
Is it possible to force IIS to accept any client ssl certificate?
Posted by Tester at 1/12/2004 8:07:39 PM
Hello all,
Does anyone know if it is possible to tell IIS to accept any client
certificate (even self signed and not trusted). We have to do custom
authentication of legacy system, which uses self signed certificates without
"client" usage specified in certificate.
Alternatively is it possi... more >>
portnumbers for authenticating
Posted by Frode Sorken at 1/12/2004 7:24:27 PM
I have set up authenticating for my website, but no matter what method I use
I am not able to access the site from outside the LAN. I guess that it is a
problem with the ports on the firewall. Which ports does the different
authenticating metods use?
Frode Brean Sorken
... more >>
IUSR_Machine password
Posted by Arrian at 1/12/2004 6:57:58 PM
I have a IIS server running on Windows 2000 SP4.
I've accidentally deselected the 'Allow IIS to control
password' option and deleted the IUSR_machine password in
the Anonymous User section of Internet Service Manager
(the hazards of using terminal services for management).
Now everytime... more >>
Phantom Web Catalog
Posted by Captain Kirk at 1/12/2004 11:26:41 AM
The last few times we restarted our Windows 2000 Advanced
intranet server a "Web" catalog was auto-created. Even
though we deleted it keeps coming back. If anyone knows
what process is creating this catalog please let me know.
Thanks,
Kirk... more >>
i really need help
Posted by mark at 1/12/2004 9:03:18 AM
hey guys. im mark from the philippines. i really need
your help involving my internet explorer. everytime i try
to surf the net using internet explorer, the page of
www.hugesearch.net always appears. it is not my default
page and i already checked if it is spoefed. if i type
www.cnn.com in... more >>
Win2k Adv. Server contracts viruses before I can patch system
Posted by Matt at 1/12/2004 8:13:50 AM
I contract worms before I can get the patches to stop
these worms. I have tried disabling services, and getting
SP4 and security updates, but still end up getting hit
with codered or nimda, etc. I have a virus scan running
(although its very ineffective, obviously) Any suggestions
on qui... more >>
IIS 5 access through a firewall
Posted by Ryan at 1/12/2004 3:46:16 AM
Hi All,
I have an IIS 5.0 server sitting in my DMZ. I can access
the default site via the IP address but when I use DNS to
resolve the name the page cannot be displayed. Any help
would be appreciated. Thanks.... more >>
IIS and UseDigestSSP - requires me to log on permanently
Posted by Robert Wurzenberger at 1/11/2004 6:27:39 PM
Hi,
on my Win2003 server I want to use digest authentication to enable internal
web sites to be reached over the web.
It works, but to log on once is by far not enough when I work with my sites.
I have to log on permanently....so it is nearly impossible to work with this
setting.
The sam... more >>
to access nt auth. required folders
Posted by yipchunyu NO[at]SPAM pcihl.com at 1/11/2004 4:41:58 PM
Hi guys,
I am working for an asp app with the use of sql 2000,
COM+ and iis 5.0.
In part of the solution, some files (lotus notes related)
will put in a folder that need a higher security and so I
only granted the right for certain NT auth. user to
access.
I need a method to let the user ... more >>
Minimum number of ports needed?
Posted by The Pistoleer at 1/10/2004 1:39:11 PM
What are the minimum number of ports needed for a dedicated public web
server. W2K3 with IIS6. Below are the services I will be needing with the
ports I'm aware of:
HTTP:
TCP 80
HTTPS:
TCP 443
FTP:
TCP 20
TCP 21
SMTP:
TCP 25
POP3:
TCP ... more >>
IUSR_PCNAME unable to access Server
Posted by DJ at 1/10/2004 8:30:55 AM
I am setting up a WebServer on a Windows 2000 Pro Machine
running IIS. The website is running fine.
But, I need to access a database on my SBS2000 Server
system through the web page. I am unable to access the SBS
system using the IUSR_Webserver user in any way.
Even after verifying the... more >>
Upgrading W2K IIS5 to W2K3 IIS6
Posted by Sascha at 1/10/2004 12:12:46 AM
I've upgraded the W2K IIS5 box with some sites on it. The box had the
URLScan 2.0 installed, and IIS Lockdown tool ran, prior to the upgrade.
I've removed URLScan 2.0 after the upgrade.
My question is:
How come I don't have the "Security" option when I right-click the server
name in the IIS M... more >>
IIS4 no longer requests client certs issued by our CA!
Posted by Craig Humphrey at 1/10/2004 12:00:16 AM
Hi,
our WinNT4 SP6a, IIS4 server has suddenly stopped requesting/accepting
client certificates issued by our CA.
The only things that have changed since I last saw it work (pre Christmas)
are:
A bunch of patches:
Root Certificates Update
Enabling the PIP_CREATE_INSTANCE flag for non-admin... more >>
System shutdown/ NT Authority/System
Posted by Darci at 1/9/2004 3:41:27 PM
When I am on the internet, periodically I recieve a
message that says something about that system shutting
down and it allows me 1:00 minutes to save any open
files. It says something about NT Authority/System, but I
don't use Windows NT, I have XP. It also says something
about an RPC serv... more >>
IIS - question
Posted by steve at 1/9/2004 12:13:16 PM
The FBI has been harassing and mentally torturing me for
two and half years since around Oct 01. The FBI has
installed
gps tracking devices in my car, tracked me like an animal,
wire tapped my phone and has been monitoring all my web
surfing
activities for 2.5yrs and completely dehumanize... more >>
Secure directory access via password
Posted by Paul at 1/9/2004 8:27:18 AM
I have IIS 5.0 on an SBS server, running web access to a
couple of applications (Exchange and ACT) both of which
have their own security system. I have another, seperate
directory (I'll call it Stuff) that contains files that I
wish to make accessible to only certain people by use of a
use... more >>
Access denied when upgrading to WSK3
Posted by Natalia at 1/9/2004 5:36:48 AM
Hi all,
I develop an intranet on a server that was recently
upgraded from W2K to WSK3. I use integrated authentication
for this intranet so I can give users some personalized
content and selective access to protected areas.
After the upgrade, the IT people who run the server played
aro... more >>
Logfile question
Posted by Arjen at 1/9/2004 12:19:35 AM
Hello,
Under this message I have copy-paste some logfile lines.
Can somebody tell me what this means?
Am I hackt?
And what can I do about this?
Thanks!
Arjen
#Software: Microsoft Internet Information Services 6.0
#Version: 1.0
#Date: 2004-01-06 07:55:43
#Fields: date time s-s... more >>
What are the vulnerabilities?
Posted by The Pistoleer at 1/9/2004 12:08:25 AM
What are the "out-of-the-box" vulnerabilities of IIS6? Specifically, a
dedicated web server connected directly to the Internet through SDSL. W2K3
Standard and IIS6 freshly installed, html (SSI, CGI scripts), ftp, smtp (and
POP3), and public DNS service. Multiple IP numbers, so ICF cannot be us... more >>
Setting Application Mappings...
Posted by sisar at 1/8/2004 6:51:38 PM
Please tell me how to configure the IIS application
mappings using Custom action in the setup projects. I am
using Custom action(installer class)to create a virtual
directory and i have to set the application mappings to
that virtual directory for .jpg extension. Please help me.... more >>
IIS 6.0 secured just for printing
Posted by Sean M at 1/8/2004 2:50:10 PM
Hi. I'm new to IIS. I'm going to be using W2K3 as a print server for my
users. I have seen IIS 5.0 under W2K make printer installation quite
easy, so I intend to use the same under W2K3 and IIS 6.0.
So, for using IIS just for this one task, how can I lock it down to not
permit anything else... more >>
access denied
Posted by Adrian at 1/8/2004 12:06:10 PM
i can access my virutal dir. my client cannot he was first receiving 401.2 error not hes getting access denied
does anyone know what the problem could be... more >>
Database Security
Posted by ursinho NO[at]SPAM yahoo.com at 1/8/2004 11:16:24 AM
I am planning on deploying a fairly unsophisticated web application
using ASP. The app will read a user's record from an Access database
stored on the web server (the database file will not be anywhere
within wwwroot), display the contents of the record (in a pre-filled
out form) to the user, a... more >>
VeriSign Inermediate Certificate Question
Posted by Dan NO[at]SPAM redridge.com at 1/8/2004 9:37:02 AM
When Verisign issues an SSL certificate for an IIS Server (any
server), the certificate is associated with an Intermediate
Certificate Authority (CA). There must be a corresponding, valid
Intermediate CA certificate on every web browser that wants to have an
SSL connection with the server.
I ... more >>
msn messenger
Posted by kr at 1/8/2004 7:33:07 AM
I'd like to block msn messenger from my iis5 server
config. Is this possible and how do I go about this?
Thanks.... more >>
Certificate wizard apparently not available now - server 2003
Posted by Bruce Cornett at 1/8/2004 7:31:18 AM
Hello
I have been putting off renewal of a web server cert on w2003 server- figuring I am missing the obvious. Time is running out so I need to ask for help.
The Thawte folks want me to generate a new CSR. Following every set of directions I can find, I open mmc and dig about and find my existi... more >>
history on Internet Explorer
Posted by Dave W at 1/8/2004 7:09:41 AM
Does anyone know how to get the exact time that a website
was visited you used to be able to in the older ver.
Thanks
Dave W... more >>
Newer Update for IIS 5.0
Posted by Bob at 1/8/2004 6:39:25 AM
I am trying to run the Q319733 Roll Up Package on one of
my servers. When I try to install it I get a message
stating "The service pack running is newer than the
patch...". Is there a newer version of the update that I
can download and run that will work ?
Thanks In Advance of your help.
... more >>
how to authenticate against ldap ?
Posted by Bill Coulter at 1/8/2004 6:38:01 AM
Can someone point toward instructions on how to set up an
ldap authentication configuration? We have an external
ldap data source of usernames and passwords. We need a
web site to authenticate against that.
Thanks
Bill... more >>
|