Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
all groups > iis security > june 2004 > threads for june 22 - 28, 2004

Filter by week: 1 2 3 4 5

Can't make a domain user the "anonymous access" user
Posted by Jen Roth at 6/28/2004 1:51:14 PM
I have been trying to set up a website in IIS 6 so that a domain user account is used for anonymous access, instead of IUSR_SERVERNAME. (I am doing this because we have ASP scripts that need to connect to a datasource as this domain user.) Unfortunately, it doesn't work. I can set it up so t...more >>


Using IPSec to connect to a virtual folder on another PC on a different network
Posted by Rob Skinner at 6/28/2004 1:45:21 PM
I have a Windows 2000 Server running IIS 5.0 out in the DMZ of my Cisco firewall using IP 10.1.1.X. One of the websites on this server connects to a virtual directory which is located on a Windows 2000 Professional PC on the corporate secured LAN at 10.0.0.X. My ISP (they are configuring my...more >>

Does SSL encrypt the data from client to server and back
Posted by jeroenlauwers NO[at]SPAM hotmail.com at 6/28/2004 12:33:33 PM
If one only installs a certificate at server side, is all data transfered between client (browser without certificate) and server encrypted ?...more >>

How do I block unauthorized insertion of a default home page?
Posted by kp at 6/28/2004 12:10:53 PM
Every time I get onto the internet I find that my default home page has been adjusted from www.msn.com to "res://iglqz.dll/index.html#96676" I go into Tools and Internet Options and change it back to msn.com but during the next web event it is again changed back to "res://iglqz.dll/index....more >>

help: site hacked
Posted by HernĂ¡n_Castelo at 6/28/2004 11:03:54 AM
hi someone was hacked my site i have 2 servers : web--> IIS 5 / w2k adv Srv IIS lockdown sql--> SQL2k / w2k adv Srv i found the web srv doing "beeps" soon i found it serves html pages but don't serves asp with an error like "Error in the server application" sql srv lost sa password and...more >>

Cert requests Server 2003
Posted by Joe at 6/28/2004 9:51:27 AM
Hello, I have recently installed the stand alone CA in server 2003 Enterprise. I have been able to receive a request via the webserver https://servername/certsrv in IIS 6.0 and I issued the cert. I also was able to download the cert to a remote machine XP Pro via the internet. But I can...more >>

Allow verbs
Posted by JT at 6/28/2004 7:46:55 AM
Which verbs should I allow in URLScan for a static WEB site that does have a feedback page. Is there any place to find an explanation of allow verbs? Thanks...more >>

404.2 error clicking a link to download a file
Posted by chris.paus NO[at]SPAM orametrix.com at 6/28/2004 7:18:41 AM
We have a website that is set up to allow our employees to click a link to a .exe file to download and install a client application. It works fine under Windows 2000 Server and IIS 5.0 But on the new server running Server 2003 and IIS 6.0 the users get an error: HTTP Error 404 - File or ...more >>



No Internet Connection Firewall in windows 2003 standard
Posted by John at 6/28/2004 6:42:20 AM
How do i install this or is it missing from this release...more >>

iis5.log
Posted by Mike at 6/28/2004 6:32:42 AM
Hi, Noticed that I had a log for the iis5.log and was wondering why that would be. I do not have the services started and for some reason it seems to be active on occasion while looking at the file. Does anyone know if this could mean that the PC is comprimised? Thanks Mike...more >>

Disable Printing from the internet
Posted by Finnie B. at 6/28/2004 3:49:57 AM
Can someone please help me. I am a Photographer and I post photos on my website. I need to know how to disable all viewers from being able to print off of the internet. Although, I place my copyright stamp on the picture and reduce the resolution on 'em so that if they are printed it looks ...more >>

Can't get SSL to work locally
Posted by Mark Rae at 6/27/2004 1:40:10 PM
Hi, I've recently acquired an SSL certificate on my live web site which I maintain and develop in C# / ASP.NET with VS.NET 2003. That means I can use https://www.markrae.co.uk just as well as http://www.markrae.co.uk. Therefore, I need to be able to simulate this on my development machine. ...more >>

unable to delete program
Posted by Raquel at 6/27/2004 8:07:43 AM
I have a strange program listed in my C drive. I am unable to delete it. When I try, I get an error message that says it has to shutdown the program. Then it takes me back to my desktop page. The program remains!! ...more >>

Windows 2003 server in DMZ for websites
Posted by bits on glass at 6/26/2004 11:22:47 PM
I have a Windows SBS 2003 behind a PIX firewall with several clients behind the SBS. I want to place a Windows 2003 server in the DMZ to host a couple of external sites. I have enough static IPs to support the site. I am searching for a good resource to answer several questions related to managi...more >>

deleting addresses on internet browser
Posted by jason at 6/26/2004 12:24:36 PM
how do i remove addresses from my menu bar? ...more >>

HTTP 403.6 error message
Posted by Joyce E. Nelson at 6/26/2004 11:05:04 AM
Web site www.riograndeair rejects my IP address...more >>

Testing security
Posted by Mike at 6/25/2004 4:36:44 PM
Hi, Is there any tools out there that would test your server for any security holes or weakness. How would one go about to test their server again possible hackers. Thanks Rick...more >>

Server got hacked. Help please.
Posted by Mike at 6/25/2004 1:07:16 PM
Hello, This week we got a call from our security guys informing us that the web server got hacked. Upon investigation, I've found compressed MP3 files that were distributed from this server. Security guys informed me that the break-in was probably done using MS FrontPage extension hack...more >>

Can't get to SSL site
Posted by Mike Plagge at 6/25/2004 12:47:05 PM
We've got SSL set up on our exchange server with the exchange server set up as the CA. We've set up IIS to use SSL on port 443. We've checked to make sure the the exchange server is listening on port 443. Whenever we try to get to OWA (or any page in the default website) using SSL, we get a pag...more >>

Users cannot download files from site
Posted by Jake at 6/25/2004 7:00:48 AM
Hello, We just converted our site to IIS6 from IIS5 or win2k to win2k3. Now none of the users can download .exe files or any .bpf files. If we type in the url http://www.mysite.com/virtualdirectory/updates/filename.bpf we get a 404 error. Is there some setting in IIS6 that needs to be set to...more >>

how to work asp.net as local user
Posted by jeeve at 6/25/2004 12:30:04 AM
hai i want to allow local windows user to work on asp.net? but now i am working only by using the administrator account. please send me the deatils about how to overcome the above as quick as possible. thanks...more >>

problems accessing database
Posted by John at 6/25/2004 12:05:03 AM
I have installed a Windows2000 server with several accounts and developed a Paradox 7 database. The database is accessable an intranet. The webserver is the microsoft IIS and CGI software developped with Borland Delphi 5.0!! When I try to login it starts the program correct but when I sele...more >>

Website allows everyone in, not matter what
Posted by Tom Pennington at 6/24/2004 7:53:28 PM
Okay, I have created a web site that is open to the public, yet there are pieces that need username/passwords to be able to get in, at least I thought. NTFS Permissions are set so that only members of a particular group can get to this directory, IIS Admin has this directory set to not allow A...more >>

How to setup HTTPS
Posted by Philip at 6/24/2004 11:27:36 AM
I have Windows 2000 Server and Exhcange 2000 Server. How do I enable HTTPS for Exchang Web access? Thanks! Philip...more >>

IE6
Posted by Kiuna at 6/24/2004 8:00:10 AM
What causes run time error in IE6 and what's the fix?...more >>

IIS virtual directory access permission
Posted by Raymond at 6/24/2004 3:40:21 AM
Hi, I want to allow specific windows users accessing a virtual directory and deny all other users. Is it possible? Thanks for your help!...more >>

IIS 6 on Win 2003 hardening query?
Posted by Sunil Vakharia at 6/24/2004 3:30:01 AM
Hi, For IIS 5 hardening, the following are some of the registry keys to be set: HKLM\System\CurrentControlSet\Services\HTTP\Parameters AllowRestrictedChars == 0 MaxFieldLength == 16384 bytes UrlSegmentMaxLength == 260 UrlSegmentMaxCount == 255 ---------------------------------------------...more >>

Login failed for user '(null)'
Posted by haltenberg NO[at]SPAM yahoo.com at 6/24/2004 3:21:48 AM
I am running a third-party web application (mainly ASP and specific pages with their own extension that are processed by a third-party ISAPI dll) on a Windows 2000 Server (IIS 5.0) which is also a domain controller and has MS SQL 2000 installed. Anonymous access in IIS for this application is se...more >>

LogParser's XML Output contains linefeed characters
Posted by Craig Dunstan at 6/23/2004 11:07:11 PM
I am using LogParser 2.1 and sending the output to XML so I can review the results. Unfortunately, it appears as though LogParser (or perhaps the underlying log) is generating a linefeed character (0x0A) and two spaces after the contents of each element value. Any ideas how to remove any...more >>

Why IIS requires login dialog?
Posted by Lei Jiang at 6/23/2004 8:55:26 PM
When I access a web site on my machine, such as http://localhost/MyWebSite, a dialog appears ask me to input username and password. Only after I input my windows login name and password could I enter the site. How could I solve this problem? My environment is : Windows 2003 Enterpries Edi...more >>

Impersonating a specific thread
Posted by Tony Proctor at 6/23/2004 7:16:28 PM
I need a little help with getting an IIS thread (well, actually a DLLHOST one) to impersonate the same account as another thread is doing. My situation is as follows: our application involves a VB6 component. This accepts a number of special "admin" requests which have to be synchronised and m...more >>

website ask for ID and password???????
Posted by Need help!!!!! at 6/23/2004 5:25:09 PM
Why is my website that should be open to the world is asking for a userID and password? How do I stop the website from asking for a userID and password? I have a 2k3 server running IIS6. Thanks!!!!! ...more >>

Problem with Mapping Certificate to User account
Posted by Mike Seising at 6/23/2004 5:24:33 PM
Hi, I'm using IIS 6.0 on Windows 2003 server. I have created a simple web site that I have secured by requiring SSL and trying to map a client certificate to a user account using IIS Mapping. The user account I'm mapping a certificate to is a local user account on the Server - the server is...more >>

Webserver accessing Active Directory information
Posted by Toddah at 6/23/2004 2:44:34 PM
I have a 3 leg PIX 515 with Inside (full AD), DMZ and outside(internet) interfaces. I have a (workgroup) 2003 Server with IIS6 running a website in the DMZ. I have allowed 1433 thru the firewall to talk to the inside SQL server and that works fine. Our programmer has developed an ASP appli...more >>

Can't access anything
Posted by BSUMelissa at 6/23/2004 1:47:02 PM
On June 19 I upgraded to Windows 2003. Since then previously running/working apps no longer work. One is Outlook Web Access (OWA) I am getting a 503 Service Unavailable error. The other is the web interface for my Exchange Antivirus software. Both interfaces do not work. I have gone through sev...more >>

Setting up a web site
Posted by Nathan Henderson at 6/23/2004 12:29:35 PM
I am a web designer and have a client who needs for a number of reason to host his own site. The client has a small P2P network however the website will potentially receive a fair bit of traffic. I can organise for a third party to direct the domain name to their IP address. Should I simply se...more >>

hijackers & popups
Posted by anonymous NO[at]SPAM discussions.microsoft.com at 6/22/2004 10:17:56 PM
Any suggestion as to how to get rid of Zestyfind hijackers sites as well as a host of "pc security' hijackers that pop up unwantedly....highjack this..adaware...spybot as well as the standard MS security suggestion have not worked....more >>

No ASP pages in WinXP SP1 IIS5
Posted by NorTor at 6/22/2004 6:09:39 PM
Hi, I have set up ISS on my computer, to test webpages i make. On my former setup, I ran Win 2000 Pro SP4 with office 2000, and all was working smoothly. Now I am running Win XP SP1 with office 2003, and only plain html-pages show up, not .asp-pages, which I mainly use (using Access-mdb ...more >>

Russian IIS hack? Malicious Javascript code
Posted by Oca Hoeflein at 6/22/2004 5:42:01 PM
I successfully removed some malicious code from my IIS 5.0 server that may not have had all it's patches updated, but I cannot find any information on this malicious code that redirected on a random basis the users of my websites to a russian website that appeared to be down. to a domain called bala...more >>

Virtual Directory Security & VBScript FileSystemObject
Posted by p.lo at 6/22/2004 4:14:01 PM
I have an asp page that uses the FileSystemObject to retrieve folder structure information on a virtual directory located in the inetpub/wwwroot folder on a Windows XP pro box. I've verified that the code is correct on another machine, but when executed on the win xp pro box, the asp page just ...more >>

Localhost problem !
Posted by Faram at 6/22/2004 12:13:33 PM
I installed IIS, In a LAN environment, for a work station. localhost does not work! when i do ping IP address from command line, I can see reply from work startion BUT when I put IP address in address bar, there is no respond! what is the different between them? I just need a hint to solve...more >>

move inetpub to x:\inetpub on exch2k box
Posted by gotenks at 6/22/2004 11:21:30 AM
We are planning to deploy exch2k, i want the inetpub to reside on x:\new-inetpub-name, while making sure that IIS still works properly to run Exch2k. I look at mskb that show how to move the www and ftp, but it doesnt mention anything about the smtp and nntp, which exch2k needs....more >>

Renew SSL
Posted by Kelly Jordan at 6/22/2004 6:23:21 AM
I'm trying to export the CSR to renew our certificate, but i'm getting an error from Windows. In the IIS Certificate Wizard window, it tells me 'Failed to Generate the Certificate Request. An internal error occured'. ...more >>


DevelopmentNow Blog