all groups > iis security > may 2004 > threads for may 8 - 14, 2004
Filter by week: 1 2 3 4 5
IIS user getting locked out
Posted by Blake at 5/14/2004 2:37:34 PM
I have created a domain user called 'proxy' with certain permissions on an
AD OU. I have set IIS to run all pages in a certain folder as this user. I
submit the name/password in IIS settings. This works fine.
Somehow, this user is getting locked out. It works great for a time, then I
get t... more >>
IIS on 443 replaced by serv-u
Posted by Andrea at 5/14/2004 10:50:47 AM
Hi. I have installed as a testserver a windows 2000 with iis and a ssl
certificate. It has functioned good until last week. Now, i think for the
iis vulnerability MS04-011, on the 443port respond a Serv-u ftp server. i
have patched the system but i don't have found services, executables that
re... more >>
** READ THIS BEFORE POSTING - answers to frequently asked questions 2004.05.14
Posted by Karl Levinson [x y] mvp at 5/14/2004 7:31:51 AM
Before you post a question to a Microsoft.public.*.security newsgroup, note
that your question may already be answered below:
Answers to Top Frequently Asked Questions:
http://securityadmin.info
I'm getting an LSASS error message, and/or I have the Sasser virus.
1) Run anti-virus that is... more >>
ssl not using active direcotry
Posted by Marty at 5/13/2004 6:40:43 PM
Hi everyone,
I'm researching something for a friend that is trying to
set up ssl but not use active directory. I know it's
been done but I can't find any instructions anywhere on
how to set this up. The problem he is having is that
after he sets it up and you direct the browser to a web... more >>
Changing anonymous login
Posted by Albacrest at 5/13/2004 5:00:04 PM
Using my windows 2k workstation as an IIS server, I've attempted to change
the login name for anonymous access on IIS5 such that the user name
represents an Exchange Server mailbox I hope to connect to via CDO.
Trouble is, doing this makes my the directory pages unauthorised on my own
PC and I... more >>
How do I authenticate a UNIX account in IIS 6?
Posted by jwalzer NO[at]SPAM comcast.net at 5/13/2004 12:32:30 PM
I have an internal IIS6 server that has a web site on it. I have one
of the folders locked down in AD, while the other folders are open.
Someone has a script that uses a UNIX account to make a call for pages
and it can hit all of the folders except for the one I locked down.
How can I authentica... more >>
cookies
Posted by Don at 5/13/2004 12:10:50 PM
Why does my complete name appear in cookies in windows XP?
This does not happen other versions of windows IE 98 etc.
Is there any way to correct this? This does not seem to
be very secure when a full name is included in cookies.
Also how do you find the cookie settings in XP? I can not
find ... more >>
IWAM Account
Posted by Paul Speziali at 5/13/2004 10:51:04 AM
I accidentally deleted the IWAM account. I restarted the box per the article on the microsoft support site but the account did not re-created. What do I do to get this account back? Thanks Paul
... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
IIS Stops serving randomly
Posted by Ron L at 5/13/2004 9:21:14 AM
We have a server that is used on our internal intranet and hosts 2 web sites
using IIS. Both sites are configured to use HTTPS using a certificate we
generated. We have found that IIS will stop serving these sites at random
times. If I log directly into the server, start IE, and browse to one ... more >>
Weired 'Page Not Found' errors from IIS
Posted by Binoy at 5/13/2004 8:31:02 AM
Hello
Our Web server (Windows server 2000) had one e-commerce site (ASP/VB) for getting orders for our 9 divisions and one HTML informational site that provided informations about these 9 divisions and equipments they were selling
We are currently in the process of upgrading informational part o... more >>
IIS 6 Authentication Process for K-12 Schools
Posted by Wayne Morris at 5/13/2004 7:35:18 AM
Is it possible to configure authentication so that certain
groups are required to validate while others are not.
In a K-12 setting (Schools K to 12)the IIS is set to basic
authentication. I want teachers, office users,
administrators, to have to validate their logon but would
like for th... more >>
Http 401.1 error
Posted by JonathanL at 5/12/2004 10:11:03 PM
I've set up IIS6 on a 2003 member server. I copied the content from a W2K IIS server to this one and set up the website to be as duplicte to the W2K one as I could. I have set Anonymous only read access in the website and NTFS perms are set for all the folders/files to include the IUSR_servername ac... more >>
Passing the IPS Proxy?
Posted by Leon_Amirreza at 5/12/2004 8:55:17 PM
used to set an anonymous web server to be used in my internet explorer to
by pass my ISP Proxy! now it doesnt work?
what settings u guess that has changed in the ISP proxy! and what can i do
now?!
Internet options> Connection>settings>Proxy
Or can u recommend me a powerful tool to by pass th... more >>
Windows Authentication Expiration
Posted by Michael J. Mooney at 5/12/2004 3:35:02 PM
Greetings,
If you set either an ASP or ASP.NET site up with Windows NT Authentication,
is it possible
to set a session timeout? Currently, it appears that the IIS session will
timeout after the specified period of time, but if the user keeps the
browser open, they are never prompted for their ... more >>
HTTP Error 401.3 with anonymous login enabled.
Posted by reena NO[at]SPAM cottermangroup.net at 5/12/2004 3:11:23 PM
Anyone's help in this matter would be greatly appreciated...
I have a Windows 2003 Server with IIS 6.0 installed (fresh install).
I made the application pool account run as local system, registered
iissuba.dll, and enabled the AnonymousPasswordSync metabase property.
(I have made sure my app... more >>
browser hijacked
Posted by dr at 5/12/2004 2:49:01 PM
Whenever I turn off my computer and then restart it, I
get a home page on internet explorer that I dont want and
never saw before. In addition, there are 5 sites that
consistently show up in my list of favorites that I dont
want. When I delete them, they just return whenever I
restart my... more >>
File sharing security
Posted by reden at 5/12/2004 1:41:05 PM
Hello
We are running IIS5 and I trying to allow access to a pdf file repository inside our DMZ. These are "controlled" documents so I need the ability to manage a single point of document control that is currently used internally. Is there a "secure" way to allow anyomous access to these documen... more >>
IIS 6 Unable to use Integrated (NTFS) Authentication
Posted by RayTracer at 5/12/2004 11:01:10 AM
I have a web application on Windows Server 2003. The application is a mix of ASP 3.0, .Net, and utilizes a SQL Server 2000 backend. It was initially setup with Basic Authentication. When I add Integrated Authentication I get "Page cannot be found" errors and my web access log shows 401 errors. I... more >>
Spyware software question
Posted by pillybob at 5/12/2004 10:59:58 AM
How can I tell if my computer has had that Spyware
software "legally" installed without my permission?... more >>
dail up connections
Posted by griff at 5/12/2004 9:34:08 AM
i keep getting a dail up connection that closes down my
on line time, i dont want it but i cant seem to get rid
of it. Can someone help me please?... more >>
IIS 6.0 cgi process not running as same user as worker process?
Posted by Issac Goldstand at 5/11/2004 11:27:23 PM
Hi list,
I've set up an application pool to run as a specific user which I set up
properly (member of IIS_WPG, relevant security policy, relevant NTFS
permissions, etc). When I run a Perl CGI in this application pool, the w3wp
process runs as my user, but the Perl processes seems to be runnin... more >>
Need help getting iis5.1 going on XP pro
Posted by news.htcomp.net at 5/11/2004 6:39:32 PM
I use a web server to build and preview pages before posting them on a ww
server. Have ben using PWS4 under 98/Me. Upgraded?? to XP pro. Have IIS
installed and it reports running. I type http://localhost or
http://computername and I get.......
There is a problem with a program on the page ... more >>
SSL Certificate causes information store termination
Posted by James at 5/11/2004 1:17:52 PM
Windows Server 2000
I am installing a web Cert from Entrust on my default web
site(IIS 5.0). Once installed it causes my Exchange 2003
information store to terminate unexpectedly. Does anyone
have any ideas?... more >>
File in Virtual Directory
Posted by Beryl Small at 5/11/2004 9:50:25 AM
I have a .NET web application that uses forms
authentication. There are CBTs in a virtual directory on
the IIS server. I do not want users logging into to the
website to be able to navigate to the virtual folder and
start any of the CBTs. The CBTs should only be able to be
accessed thro... more >>
IIS log files and how to locate if the client is trying to infect my web server
Posted by godtoall NO[at]SPAM hotmail.com at 5/11/2004 9:20:38 AM
I know how to find Nimda and Code Red, but was curious if their is a
complete list of all of the viruses that can be found in th IIS Log
files.... more >>
Error 1933 when trying to install Jasc PaintShop Pro
Posted by Sargon at 5/11/2004 12:50:18 AM
--
Hi,
I'm trying to install Jasc PaintShop Pro 8 on my WinXPPro computer.
After going through I think the last stage of copying new files, I get the
message about System Files Protection (Some system files that the system
needs where replaced with an unrecognized version please inse... more >>
SSL & Page not found
Posted by phil at 5/10/2004 9:01:23 PM
I have multiple sites assigned to an IP using host header
names. DNS points and it answers. I want to assign SSL on
a new folder for one of the sites. ie.
https://secure.mydomain.com. The link works, but the SSL
doesn't. I can see the Host header line in top box show
port 80 w/secure.mydom... more >>
How to read user created attribute in the digital certificate
Posted by MK at 5/10/2004 4:44:43 PM
When creating a digital certificate, you are allowed to
create an attribute e.g. hostname="myhost".
My question is:
How can an application read this attribute value on the
IIS server during authentication process.
Thanks,... more >>
unable to log in
Posted by lisa at 5/10/2004 8:43:56 AM
i cant log into any secure websites.... more >>
Integrated authentification mode with ssl ... don't work
Posted by PsyKotroP at 5/10/2004 8:32:22 AM
Hello excuse for spellingmistake ! i'll try to explain my problem
i have a IIS 6.0 with architecture :
-Root (identification page)
|--Portail
|--Exchange
Root directory is protected by integrated authentification and is on ssl
mode. Portail is protected by integrated authentification a... more >>
homepage
Posted by homepage pirating at 5/10/2004 7:21:09 AM
homepage keeps changing to coolsearch.biz automatically
even after i reset homepage... more >>
II6, sql server 2000, windows 2003, web access problem
Posted by (urbain.zibo-detto NO[at]SPAM sgcib.com) at 5/10/2004 1:48:06 AM
Hi everybody
I think my server my server is ill-configured, because I can't generate xml files using " FOR XML AUTO" in my sql queries. It's works with II5+WinXP+sql server 2000. Please help me.
I need to create those files and use then to achieve a web site in an Intranet for the company.
... more >>
403 Error on CGI Pages in IIS 6.0
Posted by Issac Goldstand at 5/10/2004 12:43:38 AM
I'm trying to set up an Application Pool for use with a Perl CGI application
on IIS 6.0. I am using a custom user (among other reasons, I need to set up
different environment settings for each application). I added the user to
the IIS_WPG group, set NTFS permissions on the file system, enables ... more >>
passthison.com
Posted by glenn at 5/8/2004 10:20:57 AM
how do I get rid of passthison.com from a xp system???... more >>
HOW-TO CREATE MY OWN SSL CERTIFICATE
Posted by c at 5/8/2004 2:53:57 AM
Hi guys.
I heard there is a way to create and use your own SSL certificate on your
mechines. Even they won't be CA certified and whenever you visit the page it
will tell you just that.(it is not CA certified)
I tried to make it on my windows 2000 mechine there is a wizard as you all
know but ... more >>
|