Groups | Blog | Home


Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
all groups > iis security > january 2004 > threads for january 8 - 14, 2004

Filter by week: 1 2 3 4 5

Security of Excels and Documents on IIS
Posted by Avi at 1/14/2004 9:51:53 PM
Hi, The pages on our IIS are a mix of ASP and documents (PDFs, Docs, Excels etc). The ASP pages are secured using a session. The session is set only at the login page after proper authentication of the ID and password. The interior ASP pages check for the session and display only if th...more >>


http error 405
Posted by DOVE at 1/14/2004 8:37:40 PM
What is the cause of this error?...more >>

Trouble replacing certificate
Posted by Art O'Malley at 1/14/2004 6:15:22 PM
I was quite familiar installing, renewing & replacing certificates in IIS 4.0, but I having trouble with IIS 5.0 certificate wizard. I have an existing Verisign certificate expiring on the 28th, but I'm not able to easily renew because the organization name of the corporation has change since ...more >>

-2147023569 error from IIS Password Change
Posted by Fred Yarbrough at 1/14/2004 5:08:35 PM
I am getting the following error when using the IIS password change site. Normally I can change the password fine but occasionally my users get this -2147023569 error returned. Has anyone seen this or know what it is? NT 4.0 domain SP6a Thanks, Fred ...more >>

Loading IIS Users from TextFile.
Posted by John at 1/14/2004 4:04:49 PM
I have a client who is trying to load IIS Users from a CSV(textfile) of names. They are looking at using some template to do the work. The client has over 500 names to create IIS Users. Is there a template or batch process that can be used to automate the procedure. Thank You for your Hel...more >>

unwanted links
Posted by jon at 1/14/2004 2:32:56 PM
HI my name is Jon and I have been having troubles deleting certain internet links off my desk top... they always come from the same places... webforhumans.com, about-blank.biz, and idgsearch.com.... every time i log onto my computer these icons pop up onto my desktop, I delete them and then ...more >>

annoying icons appearing on desktop
Posted by anonymous NO[at]SPAM discussions.microsoft.com at 1/14/2004 2:24:46 PM
HI my name is Jon and I have been having troubles deleting certain internet links off my desk top... they always come from the same places... webforhumans.com, about-blank.biz, and idgsearch.com.... every time i log onto my computer these icons pop up onto my desktop, I delete them and then ...more >>

urlscan
Posted by hkwan at 1/14/2004 1:16:38 PM
I have URLSCAN on our production server. When I use site manager to do a manual import to the production server, URLSCAN appears to be blocking it due to the limits set by MaxAllowedContentLength. I tried increasing MaxAllowedContentLength to an extremely large number but it did not help...more >>



Disabling IIS
Posted by Amir M. at 1/14/2004 1:00:00 PM
Hi, For security reasons, we would like to disable the IIS on all our Win2K Server machines that don't use it. How do we disable/disconnect it? Could we remove it completely? Does disabling or removing it cause any problems? Thanks...more >>

ftp security question
Posted by bbxrider at 1/14/2004 12:53:59 PM
win2k adv serv/ iis5.0 this my first web site, this is my thinking for security for an application that needs to write, copy, and delete flat files over the internet the 1 and only basic internet user acct has privileges to write new flat files to one directory, directly beneath the std inetpu...more >>

SSL cert problem
Posted by Frank J at 1/14/2004 10:28:57 AM
We are preparing new server in advance so that the website down time will be minimium. We export and import the SSL certificate from production server to the new server. Everything is fine but when browse to the website on new server, we get an error saying the certificate is not valid or...more >>

Failed to create 'CertificateAuthority.Request' object
Posted by Zyck at 1/14/2004 10:14:07 AM
I've setup a Certificate Authority on W2003. I receive "Failed to create 'CertificateAuthority.Request' object" when I try to "Download CA Certificate". Any Idea? Thanx. ...more >>

APSNET account permissions
Posted by Karin at 1/14/2004 6:50:20 AM
Dear all, We'd like to setup an .NET framework on IIS 5.0. During the installation of the framework the ASPNET account will be created. My question now is, does this user has to be in the admin group if the .NET framework will be used as WebService? Thanks for your help! Cheers, Karin...more >>

Allow file download only to subscribers
Posted by John Kotuby at 1/14/2004 6:49:42 AM
I have created a site with ASP (Active Server Pages). That requires a login validated by an Access database. There is a file that I wish to be accessible for download only by registered subscribers. All my ASP pages check for the Userid/Password variables that I have set up, so a non-subscriber ...more >>

IIS 5.1 (XP Pro) XML Security Issue
Posted by Richard Stewart at 1/14/2004 12:21:08 AM
I am running IIS 5.1 on XP Pro and running into an issue with an asp page this is trying to create an XMLDOM (see code snippet below). I get an error that object is required. After quite a bit of trial and error I think it is a security issue. If I change the IIS App to logon with windows (not an...more >>

Clean up CertSrv
Posted by i_robot73 NO[at]SPAM hotmail.com at 1/13/2004 6:04:50 PM
In my attempts to nullify my stupidy w/ ISS & SSL (hence 9 diff. cert. req.) I made more of a mess than I needed to. My ? being: Is there a way to 'cleanup' the Cert. Server & remove/delete/nuke the other 'available certificates'?? Any help is appreciated. David D. (Network Engineer - M...more >>

IIS, OWA or AD problem ???!!!????
Posted by Bapu at 1/13/2004 4:58:32 PM
Administrator can log onto OWA over internet. A regualr user cannot. The regular user and Administrator can log into Outlook client. What the heck is wrong? I'm using Windows 2000 Server and a single Exchange 2000 Server both of which are my PDC. Software is vanilla installations. T...more >>

Internet Explorer Favorites Recreated
Posted by Roberta at 1/13/2004 3:09:53 PM
Please help me, I've spent over 3 hours on the phone with Microsoft and they cant seem to fix my problem. My brother was looking at porn sites over the holidays and now my Internet Explorer Favorites are of kiddie porn sites and even though I have deleted them ran spyware etc and they sti...more >>

IIS - SSL Certificate
Posted by YoYo at 1/13/2004 2:44:37 PM
I have only my original certificate request file, and the response file from the certificate issuer. How can I use this to reinstall the certificate in IIS 5.0? Alas, I did not back up the originally installed certificate as a .pfx or .key. Thanks for any help.......more >>

Problem with IIS 6.0
Posted by ericallenpaul NO[at]SPAM hotmail.com at 1/13/2004 1:53:17 PM
We recently upgraded to IIS 6.0 and Windows 2003 server and every since we've upgraded we've been having an issue with authentication. The web site in question is supposed to allow anonymous access, but from time to time it will prompt for a username and password as if authentication was turned ...more >>

AccessCheck problem
Posted by Jamie at 1/13/2004 1:49:01 PM
Hi all, I have an ISAPI filter that determines a user's permissions from the ACL of a file using the 'AccessCheck' API call. This works fine on all of the platforms except Windows 2003 server, where I'm having a strange problem. The AccessCheck call is failing for users that are members of th...more >>

searchmeup.net popup
Posted by john at 1/13/2004 1:47:47 PM
How do I stop this from popping up on my computer??...more >>

How to create a cert for signing ActiveX using my own CA ???
Posted by SO at 1/13/2004 1:34:01 PM
Hello all, I tried my best but could not find a solution for subj. There are instructions for generating test cert signed by default test root or signing with commercial CA like Thawte, Verisign etc., where actual request process depends on a provider. But I need something in between. What...more >>

Should a Domain member server be put into a DMZ.
Posted by Brian at 1/13/2004 12:34:05 PM
First some history, I have a web server running IIS5. On a windows 2000 server, all service packs have been installed. currently this server is standalone with the exception of ports open on the firewall to a SQL server on the local network. By stand alone I mean, it is in its own littl...more >>

Delay in posting change to html page after uploading via ftp.
Posted by Joe Hodosky at 1/13/2004 8:56:40 AM
Hello, I have users that ftp up to our web server complaining that there changes are not being noticed immediately. Can anyone point me in the right area to decrease the time it takes for the server to recognize the change to a page. Thanks in advanc Joe Hodosky...more >>

Soap, Authentication & IIS anonymous user
Posted by Vince C. at 1/13/2004 12:32:49 AM
Hi. I'm struggling with authentication and Soap Toolkit 3.0 under IIS 5 on W2K. I've written an ASP web service on an IIS machine, say A, that has a client on an IIS machine too, say B. Both machines A and B can be the same or distinct ones. Consider both machines are part of the same domain f...more >>

401.3 error on all files in root for iis for win xp pro
Posted by saenen_chr NO[at]SPAM yahoo.com at 1/12/2004 11:47:18 PM
hey, i am really new at this, so go easy on me. i found a lot of articles on how to specify ntfs permissions on win2000 but this can't be applied on xp pro. does someone know what i have to do exactly to get rid of these 401.3 no permission errors for iis on WIN XP PRO; with desperate gr...more >>

Is it possible to force IIS to accept any client ssl certificate?
Posted by Tester at 1/12/2004 8:07:39 PM
Hello all, Does anyone know if it is possible to tell IIS to accept any client certificate (even self signed and not trusted). We have to do custom authentication of legacy system, which uses self signed certificates without "client" usage specified in certificate. Alternatively is it possi...more >>

portnumbers for authenticating
Posted by Frode Sorken at 1/12/2004 7:24:27 PM
I have set up authenticating for my website, but no matter what method I use I am not able to access the site from outside the LAN. I guess that it is a problem with the ports on the firewall. Which ports does the different authenticating metods use? Frode Brean Sorken ...more >>

IUSR_Machine password
Posted by Arrian at 1/12/2004 6:57:58 PM
I have a IIS server running on Windows 2000 SP4. I've accidentally deselected the 'Allow IIS to control password' option and deleted the IUSR_machine password in the Anonymous User section of Internet Service Manager (the hazards of using terminal services for management). Now everytime...more >>

Phantom Web Catalog
Posted by Captain Kirk at 1/12/2004 11:26:41 AM
The last few times we restarted our Windows 2000 Advanced intranet server a "Web" catalog was auto-created. Even though we deleted it keeps coming back. If anyone knows what process is creating this catalog please let me know. Thanks, Kirk...more >>

i really need help
Posted by mark at 1/12/2004 9:03:18 AM
hey guys. im mark from the philippines. i really need your help involving my internet explorer. everytime i try to surf the net using internet explorer, the page of www.hugesearch.net always appears. it is not my default page and i already checked if it is spoefed. if i type www.cnn.com in...more >>

Win2k Adv. Server contracts viruses before I can patch system
Posted by Matt at 1/12/2004 8:13:50 AM
I contract worms before I can get the patches to stop these worms. I have tried disabling services, and getting SP4 and security updates, but still end up getting hit with codered or nimda, etc. I have a virus scan running (although its very ineffective, obviously) Any suggestions on qui...more >>

IIS 5 access through a firewall
Posted by Ryan at 1/12/2004 3:46:16 AM
Hi All, I have an IIS 5.0 server sitting in my DMZ. I can access the default site via the IP address but when I use DNS to resolve the name the page cannot be displayed. Any help would be appreciated. Thanks....more >>

IIS and UseDigestSSP - requires me to log on permanently
Posted by Robert Wurzenberger at 1/11/2004 6:27:39 PM
Hi, on my Win2003 server I want to use digest authentication to enable internal web sites to be reached over the web. It works, but to log on once is by far not enough when I work with my sites. I have to log on permanently....so it is nearly impossible to work with this setting. The sam...more >>

to access nt auth. required folders
Posted by yipchunyu NO[at]SPAM pcihl.com at 1/11/2004 4:41:58 PM
Hi guys, I am working for an asp app with the use of sql 2000, COM+ and iis 5.0. In part of the solution, some files (lotus notes related) will put in a folder that need a higher security and so I only granted the right for certain NT auth. user to access. I need a method to let the user ...more >>

Minimum number of ports needed?
Posted by The Pistoleer at 1/10/2004 1:39:11 PM
What are the minimum number of ports needed for a dedicated public web server. W2K3 with IIS6. Below are the services I will be needing with the ports I'm aware of: HTTP: TCP 80 HTTPS: TCP 443 FTP: TCP 20 TCP 21 SMTP: TCP 25 POP3: TCP ...more >>

IUSR_PCNAME unable to access Server
Posted by DJ at 1/10/2004 8:30:55 AM
I am setting up a WebServer on a Windows 2000 Pro Machine running IIS. The website is running fine. But, I need to access a database on my SBS2000 Server system through the web page. I am unable to access the SBS system using the IUSR_Webserver user in any way. Even after verifying the...more >>

Upgrading W2K IIS5 to W2K3 IIS6
Posted by Sascha at 1/10/2004 12:12:46 AM
I've upgraded the W2K IIS5 box with some sites on it. The box had the URLScan 2.0 installed, and IIS Lockdown tool ran, prior to the upgrade. I've removed URLScan 2.0 after the upgrade. My question is: How come I don't have the "Security" option when I right-click the server name in the IIS M...more >>

IIS4 no longer requests client certs issued by our CA!
Posted by Craig Humphrey at 1/10/2004 12:00:16 AM
Hi, our WinNT4 SP6a, IIS4 server has suddenly stopped requesting/accepting client certificates issued by our CA. The only things that have changed since I last saw it work (pre Christmas) are: A bunch of patches: Root Certificates Update Enabling the PIP_CREATE_INSTANCE flag for non-admin...more >>

System shutdown/ NT Authority/System
Posted by Darci at 1/9/2004 3:41:27 PM
When I am on the internet, periodically I recieve a message that says something about that system shutting down and it allows me 1:00 minutes to save any open files. It says something about NT Authority/System, but I don't use Windows NT, I have XP. It also says something about an RPC serv...more >>

IIS - question
Posted by steve at 1/9/2004 12:13:16 PM
The FBI has been harassing and mentally torturing me for two and half years since around Oct 01. The FBI has installed gps tracking devices in my car, tracked me like an animal, wire tapped my phone and has been monitoring all my web surfing activities for 2.5yrs and completely dehumanize...more >>

Secure directory access via password
Posted by Paul at 1/9/2004 8:27:18 AM
I have IIS 5.0 on an SBS server, running web access to a couple of applications (Exchange and ACT) both of which have their own security system. I have another, seperate directory (I'll call it Stuff) that contains files that I wish to make accessible to only certain people by use of a use...more >>

Access denied when upgrading to WSK3
Posted by Natalia at 1/9/2004 5:36:48 AM
Hi all, I develop an intranet on a server that was recently upgraded from W2K to WSK3. I use integrated authentication for this intranet so I can give users some personalized content and selective access to protected areas. After the upgrade, the IT people who run the server played aro...more >>

Logfile question
Posted by Arjen at 1/9/2004 12:19:35 AM
Hello, Under this message I have copy-paste some logfile lines. Can somebody tell me what this means? Am I hackt? And what can I do about this? Thanks! Arjen #Software: Microsoft Internet Information Services 6.0 #Version: 1.0 #Date: 2004-01-06 07:55:43 #Fields: date time s-s...more >>

What are the vulnerabilities?
Posted by The Pistoleer at 1/9/2004 12:08:25 AM
What are the "out-of-the-box" vulnerabilities of IIS6? Specifically, a dedicated web server connected directly to the Internet through SDSL. W2K3 Standard and IIS6 freshly installed, html (SSI, CGI scripts), ftp, smtp (and POP3), and public DNS service. Multiple IP numbers, so ICF cannot be us...more >>

Setting Application Mappings...
Posted by sisar at 1/8/2004 6:51:38 PM
Please tell me how to configure the IIS application mappings using Custom action in the setup projects. I am using Custom action(installer class)to create a virtual directory and i have to set the application mappings to that virtual directory for .jpg extension. Please help me....more >>

IIS 6.0 secured just for printing
Posted by Sean M at 1/8/2004 2:50:10 PM
Hi. I'm new to IIS. I'm going to be using W2K3 as a print server for my users. I have seen IIS 5.0 under W2K make printer installation quite easy, so I intend to use the same under W2K3 and IIS 6.0. So, for using IIS just for this one task, how can I lock it down to not permit anything else...more >>

access denied
Posted by Adrian at 1/8/2004 12:06:10 PM
i can access my virutal dir. my client cannot he was first receiving 401.2 error not hes getting access denied does anyone know what the problem could be...more >>

Database Security
Posted by ursinho NO[at]SPAM yahoo.com at 1/8/2004 11:16:24 AM
I am planning on deploying a fairly unsophisticated web application using ASP. The app will read a user's record from an Access database stored on the web server (the database file will not be anywhere within wwwroot), display the contents of the record (in a pre-filled out form) to the user, a...more >>

VeriSign Inermediate Certificate Question
Posted by Dan NO[at]SPAM redridge.com at 1/8/2004 9:37:02 AM
When Verisign issues an SSL certificate for an IIS Server (any server), the certificate is associated with an Intermediate Certificate Authority (CA). There must be a corresponding, valid Intermediate CA certificate on every web browser that wants to have an SSL connection with the server. I ...more >>

msn messenger
Posted by kr at 1/8/2004 7:33:07 AM
I'd like to block msn messenger from my iis5 server config. Is this possible and how do I go about this? Thanks....more >>

Certificate wizard apparently not available now - server 2003
Posted by Bruce Cornett at 1/8/2004 7:31:18 AM
Hello I have been putting off renewal of a web server cert on w2003 server- figuring I am missing the obvious. Time is running out so I need to ask for help. The Thawte folks want me to generate a new CSR. Following every set of directions I can find, I open mmc and dig about and find my existi...more >>

history on Internet Explorer
Posted by Dave W at 1/8/2004 7:09:41 AM
Does anyone know how to get the exact time that a website was visited you used to be able to in the older ver. Thanks Dave W...more >>

Newer Update for IIS 5.0
Posted by Bob at 1/8/2004 6:39:25 AM
I am trying to run the Q319733 Roll Up Package on one of my servers. When I try to install it I get a message stating "The service pack running is newer than the patch...". Is there a newer version of the update that I can download and run that will work ? Thanks In Advance of your help. ...more >>

how to authenticate against ldap ?
Posted by Bill Coulter at 1/8/2004 6:38:01 AM
Can someone point toward instructions on how to set up an ldap authentication configuration? We have an external ldap data source of usernames and passwords. We need a web site to authenticate against that. Thanks Bill...more >>


DevelopmentNow Blog