all groups > iis security > march 2004 > threads for march 8 - 14, 2004
Filter by week: 1 2 3 4 5
Token impersonation in IIS filter
Posted by pyang NO[at]SPAM rsasecurity.com at 3/14/2004 9:52:34 PM
Hi:
I am working on a project that requres impersonation of a user's
identity. I use a name pipe server to generate a user token by calling
LsaLogonUser. When the token is returned to ISAPI filter, I call
SetThreadToken to attach the token to the running thread, So that user
can access some M... more >>
IIS not functioning
Posted by Jibey Jacob at 3/14/2004 11:51:06 AM
Hello
I installed IIS on my Windows XP Professional desktop and it's not functioning. When I type http://localhost/aspnet_client/system_web/1_1_4322/SmartNav.htm it says the Page cannot be displayed. I'm able to run inetmgr
Can someone tell me what is wrong
Thanks
Jibey Jaco
... more >>
ClassFactory cannot supply requested class???
Posted by Jon at 3/14/2004 10:00:19 AM
I am not quit sure why I am get this error, because every
thing was working and then all of a suddon, it started to
give me this error when I tried to go to my web page:
HTTP 500.100 - Internal Server Error - ASP error
Internet Information Services
----------------------------------------... more >>
internet security patch
Posted by Francisco Diaz at 3/13/2004 7:44:35 PM
To whom it may concern:
I have been receiving emails from Microsoft Coorporation
Program Security Division regarding an internet security
patch. I have reasons tobelieve that this is a scam. Where
should I send the email so this can be studied?
Thank you,
Francisco Diaz
... more >>
IIS Won't Work W/Symantec Security/Virus?
Posted by Blue Whale at 3/13/2004 2:04:50 PM
I have been trying to install IIS on this Dell 1Ghz
Pentium III Workstation with Win2000Pro.
I am installing a local Intranet Web & using
FrontPage2002.
I finally got the IIS installed but I had to remove Norton
Internet Security and Anti-Virus 2004 to do it and IIS
will not work when I ... more >>
IE6 Home Page
Posted by Bobby at 3/13/2004 7:41:05 AM
Please help. I've downloaded and ran both Spybot and Ad-Adware, but even after I reset my home page it still periodically returns to something called "findthewebsiteyouneed.com." Also, something called "dotcomtoolbar" keeps popping up and tries to affix itself to my toolbar. I'm about to punch a ... more >>
Windows 2003-IIS - 6.0 Digest authentication issue (MD5 Vs MD5-Sess?)
Posted by T-90 at 3/13/2004 5:11:06 AM
I'm having some difficulties setting up Digest authentication on IIS 6.0 - Windows2003. Installation steps are as follows
1. Install Windows 200
2. Install Active Directory and DNS to make the machine a domain controlle
3. Install Internet Information Server 6.
Set the authentication of "Defau... more >>
Got a Redirect on Explorer .... Help!
Posted by Tony would like to stop the online-wizard.com at 3/12/2004 8:01:12 PM
These idiots changed my home page ... bought Spyware but
it comes back every time I boot up. Changed tools options
homepage still I redirected. How do I kill this thing?
http://online-wizard.com/index.php?aid=33... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
II6
Posted by Con at 3/12/2004 4:07:52 PM
I am unsure if this is a new problem or just how IIS6.0 functions; I setup a
SSL site on our server and tested user logons, if a login is successful or
not it is reported in the evenviewer security view as a golden key
(Successful). We need to be able to monitor our site and be able to
determine... more >>
IIS - problemer.
Posted by Hilde Bjørnstad at 3/12/2004 11:04:54 AM
BlankJeg pleier å browse mine websider fra IIS 5.0, normalt ingen problemer.
Men i dag fikk jeg skjedde dette på alle lokale sider:
I use IIS 5.0 for browsing my websites. Normally no problems, but today, I
got this message on every website on my local computer:
Access Denied
---------... more >>
Anonymouse Access
Posted by Liblib at 3/12/2004 8:53:51 AM
I recently had to enable anonymouse access on my server
after I started hosting a website. My problem is that I
started seeing strange IP addresses on my server
immediately. My server is behind an ISA firewall. My
question is how do I allow anonymouse access and still
prevent hackers on my... more >>
IIS6 and Nt4 domain authentication
Posted by Mitch Hoffa at 3/11/2004 3:01:09 PM
Hello All
I have both basic and integrated authentication enabled on a new win2003 server with iis6. But when accessing the default site throught a laptop which is connected to the same domain and authentication has already taken place, you still receive a nt login prompt when attempting to conne... more >>
Intermediate certificate not sent as a trusted CA
Posted by JimCorkey at 3/11/2004 2:31:16 PM
Greetings,
Problem Summary:
We are unable to configure IIS to allow an intermediate Certificate Authority certificate to be used for client authentication.
Background:
We are setting up a secure web site. We want to enable access to a portion of the web site to holders of a particular cli... more >>
IIS Authentication using external database?
Posted by Yikes at 3/11/2004 2:13:06 PM
I am runnning a website in ASP, and want to use the basic authentication
method to validate my users.
However, rather than create windows accounts for each of the millions of
users, I want to store the usernames and passwords in a database. I am
currently using a form to authenticate, but it l... more >>
BS7799 - all vote in Favour.
Posted by The Poster at 3/11/2004 11:24:02 AM
G/day forum,
Can anyone give me an insight into the effectiveness of using BS7799 as a
basis for a corporate security policy? I work in an E-Commorce environment
and now it transpires that a strictly enforced corporate security policy has
to be put in place.
Regards,
Steve.
... more >>
Integrated Authentication - poor response
Posted by Paal Berggreen at 3/11/2004 8:31:39 AM
We are developing a web based asp.net application that is deployed
throughout the world. Many users have low latency connections to the
webserver, and we notice that when we use Integrated Authentication in IIS
(which we are required to do), the responsetimes for most requests are
doubled compar... more >>
Hyzzviec.exe
Posted by Kath SC at 3/11/2004 7:31:06 AM
Hi,
Can anyone help with this file that has created several logs on my Windows 98 PC? I have absolutely no idea what it is, but it is constantly running in the background under Windows/system/hyzzviec.exe
My main question is can I delete it, particularly as I don't know if it is harmful?
M... more >>
Require Certificates
Posted by Bob Francis at 3/11/2004 5:31:08 AM
The authentication dialog prompting for a client certificate is not displayed to the browser. Why? Note: This happens when the browser is requesting a protected resource for the first time.... more >>
IIS authentication problem.
Posted by Mleskine at 3/10/2004 11:11:08 PM
Hello
i have couple .asp -files that need authenticated access to display, but IIS doesn't seem to ask login information when i load the page first time. At the second time it asks for login/pass. Anyone know what this might be about? It might look like the page doesn't work for a user if it doesn'... more >>
Have I been hacked?
Posted by puppymalo NO[at]SPAM hotmail.com at 3/10/2004 5:38:53 PM
I am new to IIS and Windows servers so please excuse me before I start
....
I just loogged on to my server to do some work and noticed 4 new
directories have appeared that I did not create
named:
y 1878
P 86027
sds
sadaaaaaaaaaaaaaaaaaaa
I am worried someone has gained access to m... more >>
Virtual Directories
Posted by Barb at 3/10/2004 4:35:27 PM
I deleted IIShelp and MSADC from my IIS server.
Is it ok to delete the msadc and iishelp folders
c:\inetpub\iishelp
c:\program files\common files\system\msadc... more >>
Help SEARCH/AAAAA iis logs
Posted by dick.olsen NO[at]SPAM vita.virginia.gov at 3/10/2004 4:14:46 PM
Requesting advice re what exactly is going on here. We have a very
formal patch update process in place - these are reviewed every week
and installed during the weekly maintenance period, unless it requires
immediate application, or is not needed.
I know about webdav. I'm asking about the 200,... more >>
adminscripts
Posted by Bar b at 3/10/2004 3:51:05 PM
I have removed virtual directories and thelogical folders
from my iis server (ie. iisamples, iishelp, msadc)
What is the iisadmin virtual folder? Is it ok to remove?
Thanks.... more >>
trusted authority
Posted by JT at 3/10/2004 3:30:10 PM
i created my own certificate rather than using an external certificate
authority and the only problem is that when a user first goes to my site
they get the
"This certificate cannot be verified up to a trusted certification
authority." message since i didn't use someone like verisign to issue t... more >>
Help ..... with IIS 5 and IUSR_ Anonymous User Account
Posted by Rev Limbo at 3/10/2004 2:41:05 PM
I'm trying to setup anonymous access for viewing Online Archive files from a Web Server
In NT4.0 w/IIS 4 the IUSR_ Account was easy to setup & find but I can't seem to set it up or locate it in IIS 5
I have currently have my "Guest" account disabled because of this issue
Any help / input will be... more >>
resetting IUSR password
Posted by ster at 3/10/2004 2:35:21 PM
Does anyone know how to reset the password to the
original value. afer changing the anonymous login acct
from IUSR to a windows account (which did not work)
setting it back to IUSR requires a password prompt. If
you enter one in the account never works again. Seems
like you have to reload ... more >>
enabling ssl
Posted by JT at 3/10/2004 12:52:05 PM
i just setup Microsoft Certificate Services to act as my certificate
authority. i installed a new certificate on my website, then went into IIS
to test the cert. i enabled SSL on my website via the Directory Security
tab. then went back to internet explorer and browsed to:
http://mysite.co... more >>
Creating a subweb in IIS6
Posted by Vernon at 3/10/2004 9:48:24 AM
You are not authorized to view this page
You do not have permission to view this directory or page
due to the access control list (ACL) that is configured
for this resource on the Web server.
From the default web site popup I select New -> Server
Extensions 2002 web
My admin account is... more >>
I E 6 privacy alert
Posted by mmtc at 3/10/2004 7:21:07 AM
is there anybody who can tell me how to disable the
annoying "plop" from the privacy alert, I check the sites
privacy statements etc automatically and would dearly love
to strangle the incessant "plop" while I am surfing,
please help, my sanity relies upon it.... more >>
IIE stopped unexpectedly
Posted by Wilson at 3/10/2004 6:26:25 AM
Hi all
Please help me:
The IIS Admin Service service terminated unexpectedly. It
has done this 1 time(s). The following corrective action
will be taken in 60000 milliseconds: No action. I have
installed antivirus Symantec 8.1 Event ID: 7031 I work
with Echange server 2000 and stopped al ... more >>
Exporting a web page to Excel asking for client authentication
Posted by kernal94_99 NO[at]SPAM yahoo.com at 3/10/2004 4:43:12 AM
Hi All,
Could someone please help me on this? I have a SSL site and one page
which is exported to Excel by clicking a button. Everytime it asks for
client authentication "the website you want to view requests
identification, select the certificate to use when connecting". The
IIS server has "... more >>
web site access denied
Posted by Bob K. at 3/9/2004 11:33:20 PM
Hi,
I'm working on a web app that uses IIS 5.1, MSDE, .NET 1,1. I believe that
my IIS install went fine and I am able to serve .html, .asp, etc. pages to
the installation PC as well as others on my local net from the Default Web
Site folder. The iisstart.asp as well as another test .asp pag... more >>
NULL.IDA IIS exploit - cmd.exe
Posted by rich at 3/9/2004 10:41:04 PM
Hi
I'm aware that there was a vulnerability in IIS for buffer overflow attacks, and that it was resolved in an SP2 patch... however scratching thru our logs today found the following
2004-03-09 14:36:40 210.5.27.100 - 192.168.1.104 80 GET /NULL.IDA
~~ insert several lines of gibberish here ~
cm... more >>
Permission Error When Using FSO In ASP!?
Posted by Jon at 3/9/2004 7:26:08 PM
Hello,
I searched every where on the internet (including here)
and I could not find any suggestions that would work for
my problem.
I am trying to use a counter script which writes to a file
in asp using fso. I set the file that I am trying to
write to's security settings so that
unde... more >>
Newbie: get SSL sertificate
Posted by Dmitry Davletbaev at 3/9/2004 5:51:55 PM
I have a web server in intranet and need SSL sertificate to use in intranet
only. What I'm interested in is can I get free SSL sertificate for use
during long time (1 year, for example)? And how can I obtain it?
Thanks for help.
Dmitry Davletbaev
... more >>
manually undo IIS lockdown changes re: indexing service and search pages
Posted by L Wick at 3/9/2004 2:10:20 PM
I ran the IIS lockdown tool about 10 months ago and everything has been fine
until recently - one of our instructors decided she wanted to require
students to include a search page in their websites. I can't really undo the
IIS lockdown because there's been a ton of changes since then. I went
th... more >>
SSL errors
Posted by anonymous NO[at]SPAM discussions.microsoft.com at 3/9/2004 12:38:12 PM
We were receiving the following error message on a
regular basis for quite sometime and I came across the
article below the error message. The article references
an issue based on SP2, and I do not know if it still
applies with SP4 which we are running on our Win2k IIS
5.0 Servers.
... more >>
Session variables in ASP
Posted by FM at 3/9/2004 9:41:08 AM
Can session variables be used with the latest service pack
for NT or windows 2000?... more >>
URLSCAN errors?
Posted by Matthew at 3/9/2004 7:53:03 AM
I was wondering what error a user would receive back from
the web server when the resource they are trying to
access is blocked by the URLSCAN filter? I.E., 404, 403,
401, etc?
Thanks,
Matthew... more >>
Access denied on loading DLLs with PHP 4.3.4, Oracle 9i and IIS 5
Posted by elmex NO[at]SPAM augenblick-software.de at 3/9/2004 6:22:03 AM
Hi!
Houston, we've got a problem:
every time we're going to load the PHP extensions php_oci8.dll and
php_oracle.dll with Oracle 9i Personal Edition and IIS 5 running we
got an 'Access denied' for the DLLs. This is our Dev-Environment:
- Windows 2000 Server SP1
- PHP 4.3.4
- Oracle 9i Pe... more >>
homepage
Posted by john at 3/9/2004 5:18:56 AM
My homepage has been highjacked. how can I get my homepage
back? Internet options doesn't work. Each time alter it
back to my old one. the new one takes over.Please Help... more >>
Login box
Posted by kilit NO[at]SPAM yahoo.com at 3/9/2004 3:13:52 AM
I have an intranet site like http://MySite/xyz
If I directly go to this site I can not get the user name and account
name using Request.ServerVariables["LOGON_USER"].
But I type http://MySite then internet explorer asks my my username,
password and domain. Then I type my credentials and can se... more >>
Digest authentication issue with IIS 6.0
Posted by Varun at 3/9/2004 2:16:01 AM
Hi All,
I'm having problems with using Digest Authentication on
IIS 6.0. I'm using Windows 2003. The setup is as follows:
DC Server (Active Directory): Windows 2003
Web Server (Separate machine): Windows 2003 as a member of
above domain.
I set the Directory Security setting of "Default... more >>
IIS - problems after move from 5 to 6.
Posted by Gareth at 3/9/2004 2:13:03 AM
Since I'm moved all my data from IIS 5 on 2k workstation
to IIS 6 on 2003 enterprise server I have a few issues
with the Intranet pages that its hosting. Most things
work but I can't run the hyperlinks that open Outlook
template files (.oft files) and the hit counter created in
Front Page... more >>
Directory.GetFiles() in web app has error "Logon failure: unknown user name or bad password"
Posted by xiaomin at 3/8/2004 5:41:07 PM
I haven't worked on web app for a while
Now my web app needs to check if a network file exists or not. When it calls Directory.GetFiles(), the web app gets error saying "Logon failure: unknown user name or bad password.
Anyone can tell me what I should do
Thanks
Xiaomin... more >>
trouble enabling internet connection firewall
Posted by Derik at 3/8/2004 3:02:02 PM
I'm running IIS 5.1 and xp pro. I want to enable
the internet connection firewall in network connections,
only letting through port 80. when i check off the http
box and let the standard service definition (port 80
coming and going) stand, I instantly lose the ability to
see my web site fro... more >>
IIS Website Authentication
Posted by Ryan W at 3/8/2004 2:51:06 PM
I have created a website using Basic Authentication over SSL. I am using IIS 5.0 on Windows 2000 server. On my initial page request I am prompted to enter my username and password. This is all well and good. But I have created a link on a webpage to point to another directory with more strict pe... more >>
IIS/OWA PIX DMZ question
Posted by Marc O at 3/8/2004 2:42:23 PM
Hi,
Hope someone can point me in a good direction.
I have a new application that's web based for both internal and external
users. I purchased a new Win 2k3 server for the application and would like
to place it in my DMZ(without a public IP) for everyone to use. My problem
is how do I set up my... more >>
IIS Lockdown tool un-installation
Posted by Tom at 3/8/2004 10:53:00 AM
Hi,
I need to un-install IIS lockdown tool but didn't seem to
be possible. Is there anybody out there has done this
before? Appreciate if you can share your tips. Thank you.
... more >>
Domain Name Problems
Posted by Jolene at 3/8/2004 9:51:05 AM
Hello
I am having a problem with my IIS 5.0 on Windows 2000. One of my domains shows up under the http://www.mydomain.com but not under http://mydomain.com. I think I've got the www.mydomain.com and the mydomain.com both registered correctly in IIS and also our router translation. I've just rec... more >>
anonymouse logging to SQL database
Posted by liblib at 3/8/2004 8:35:55 AM
I enabled anonymouse access on my server to allow access
to my database from the internet. I've however realised
this allows other people to log on to my network. My
question is how do I allow someone to log on to my
database without allowing everyone else to log on to my
network.... more >>
computer problems
Posted by mary at 3/8/2004 7:42:59 AM
hi i was wondering if there was any way some1 can help me?
i'm having problems while i'm on the computer, i am
getting a 'banner' off microsoft internet explorer saying'
cannot find 'file:///C/bns/NEW/B.555800.htm:Make sure the
path or internet address is correct! this keeps cropping
up e... more >>
winforms user control in web page
Posted by jcooper at 3/8/2004 6:26:11 AM
I created a winforms user control that I would like to put in a web page. For the moment, I've just created a simple control with a label on it to test the functionality before I go and code real the user control which will be much more complicated. But, I can't even get the control with a label to ... more >>
Problem with SSL on default site
Posted by Lee Elliott at 3/8/2004 4:49:50 AM
Hello:
I have required SSL with 128-bit encryption on the default
web site in IIS. When I do this, it says server cannot be
found when I try using the IP address, NETBIOS name, or
DNS name. When I remove the SSL requirement, I can
connect to the web site with no problem when using an IP... more >>
|