Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008


all groups > iis security > march 2005

Filter by week: 1 2 3 4 5

W2003 SP1 - IIS CRL Check
Posted by Mark Pfeifer at 3/31/2005 3:52:34 PM
Can anyone tell me (as I didn't see it in the big list) if the CRL Checking Timeout option actually made it into SP1. I remember reading a knowledge base document stating the IIS CRL check timeout would be added in SP1. Thanks, Mark ...more >>

405.1 error
Posted by j1c at 3/30/2005 11:39:33 AM
I have a site running on IIS 6 that uses Windows File Replication. I have set the permissions to allow anonymous and gave IWAM & IUSR read & execute perms. I am still however getting a 405.1 error. Any ideas? ...more >>

IIS Admin Service - changing Logon account
Posted by fwrs at 3/30/2005 11:11:07 AM
Within IIS 6, I am trying to change the Logon account for all of the IIS services (IIS Admin, HTTP SSL, and WWW) from the Local System account to a custom account in the Administrators group. Whenever I try to start IIS Admin, the service terminates with an error in the Event Log: "Access is ...more >>

IIS and .NET State
Posted by dm4714 at 3/30/2005 9:37:08 AM
Hello -- I'm using IIS on four W2K3 servers in a network load balancing server farm. There is one back-end state server running the .NET State Server. Each IIS server is configured with "StateServer" parameter pointing to the state server. My question is this... does anyone know of any ...more >>

Executables won't run in IIS 5.1 on XP pro
Posted by rtrammell at 3/30/2005 7:53:07 AM
I'm having problems getting my executables to run in IIS 5.1. I have moved my website from a Windows 2K server platform(where everthing runs perfectly) to a PC running XP Pro. I have set up the website with the exact same parameters as before and enabled scripts and executables for the scrip...more >>

turn this off NTAuthenticationProviders : (STRING) "Negotiate,NTLM
Posted by sun at 3/30/2005 6:47:01 AM
I ran this on my IIS box and now no one can access any website on it. how to I undo this and get IIS back to it's default settings NTAuthenticationProviders : (STRING) "Negotiate,NTLM" ...more >>

IIS 6.0 and Integrated Security - restricting logins
Posted by Sandy Wood at 3/29/2005 4:29:02 PM
I want to restrict user access to certain parts of my web site by creating local groups and adding those groups to the data folders that have the web content. Right now, when I create a new local user, and not add them to any group, he can access the web site which is configured to use Integra...more >>

Problems with IUSR after installing security templates
Posted by Raymond at 3/29/2005 10:31:42 AM
We have a webfarm with 6 webservers. Three of them run Win2k, the other three have recently been upgraded to Win2k3. After installing windows 2003, we applied the Windows 2003 Security Guide templates. (http://www.microsoftcom/downloads/details.aspx?FamilyID=8a2643c1-0685-4d89-b655-521ea6c7b4db...more >>



IIS 5.0 Directory Settings help
Posted by TheSonOfKrypton NO[at]SPAM earthlink.net at 3/28/2005 6:32:03 PM
I'm a college student and I've got my computer hosted by my university so that I can set up generally viewable websites and all that. Since I'm moving around a lot, I've set up RDC, but there are some times when it would be really handy to be able to access a specific file on one of three or fou...more >>

IIS6 to block someone from sharing files
Posted by Backup at 3/28/2005 2:58:58 PM
I am looking for a way, perhaps with ISAPI filters, in IIS6 to block someone from sharing files / "porn" pic's under their website. I have users with their www.domainname.com and they are hosting pics and files under their account. There isn't one link of the website at all pointing to these...more >>

Install a certificate on IIS 4
Posted by totomaster at 3/28/2005 12:53:05 PM
Hi I want to install a web certificate for a site configured on IIS 4.0 This server is the last Nt4 in the network, all others servers are on Windows 2000 or 2003. My enterprise CA is on a Windows 200 server. Do I have to create it in the Key Manager on IIS 4.0 and export it to the CA ...more >>

AD user name changed, IIS still sees old user name
Posted by Aaron at 3/28/2005 11:49:01 AM
We have an ASP.NET application running on Windows Server 2003, using IIS 6.0, and integrated windows authentication with SQL Server 2000 on the back-end. We store active directory user names in the SQL Server database for use in mapping application user accounts to active directory user accou...more >>

DMZ access for internal and external users
Posted by Susan at 3/28/2005 6:27:03 AM
I need to put a 2003 Web Edition server on a DMZ, but it has to be accessible by both internal LAN users from multiple world-wide subnets and by Employees on the outside. I configured it on the internal LAN, then moved it to the DMZ, but I did not put any user groups into it, and now I cann...more >>

Consuming ASP.NET Web Service
Posted by Thom Little at 3/27/2005 5:33:42 AM
I am trying to access the HelloWorld method compiled in one project using a consuming C# code-behind method compiled in a separate project. Both run on localhost. The test drivers provided in Visual Studio .NET 2003 can invoke the method. When I attempt to add a web reference in the consu...more >>

SMTSVC ?
Posted by razornt at 3/25/2005 1:45:05 PM
Someone is trying to hack our server via SMTPSVC. When I view the event log (system) I see Event ID 100 SMTPSVC and a login attempt. However, when I try to match the Event log time with the SMTPSVC log time nothing matches. I want to block the IP Address of this potential intruder. How do I fi...more >>

IIS 6 Write to the Event Log
Posted by JT at 3/25/2005 9:31:55 AM
I have an anonymous access web service that is running as IUSR_machineName. This application is set up in IIS 6 running in an application pool under the network service account. I understand that this network service account is low privledged. My question is: What do I have to do to change t...more >>

Block sites linking to my site
Posted by basin at 3/25/2005 8:41:03 AM
We have a site that has a "sample request " form where future customers can order sample of some of our paper. Well, apparenty some people found it and posted it on sites such as freesamplesite.com and fatwallet.com. So we have hundreds of orders for samples!! Is there any way we can blo...more >>

processing a CA certificate if initial pending request is deleted
Posted by Eddie at 3/23/2005 2:51:02 PM
Hi, needed some assistance or affirmation. I am in the process of installing a SSL Certificate for our web server and deleted the original pending requested that matches a certificate that was obtained from the CA. Is there a way of getting that back into IIS from the original saved request...more >>

How do I disable http traffic
Posted by Andre at 3/23/2005 1:19:06 PM
I want https to be the only option on my webserver. How do I disable http/80?...more >>

Adobd errors Permission denied IIS6
Posted by Infodon at 3/23/2005 12:47:04 PM
Ok here is the situation we have recently upgraded our 2000 server to 2003. We have several Virtual directories that authenticate anonymously, everything was working fine on the 2000 server. Now we experience errors when loading asp pages pointing to either mdb or sql, unless I perform the wor...more >>

401.1 After IIS6 Setup
Posted by WebGuyBob at 3/23/2005 6:23:03 AM
Hello, folks. I have setup literally dozens of IIS6 Web sites and just ran into subject problem. I read the following from Mr. Wang in a German IT forum: "401.1 means that the username/password that you gave to IIS for authentication was incorrect. If this happens when you have Anonymous a...more >>

how do i disable anonymous users and add a new user?
Posted by Rob White at 3/23/2005 6:13:06 AM
I’m trying to write a script for IIS 5.1 (hosted in XP embedded). I need the script to change the root of the ftp service to “c:\directoryname”, enable both read and write access and lastly allow only a sinlge user access to the site. The user is one built into the OS, so I also want the...more >>

AES 256-bit Certificate
Posted by Nick at 3/22/2005 7:55:03 PM
I am seeing that many websites are using AES-256 bit certificates. Is there a way to generate these using Windows 2000 Certificate Server? If it is not offered in 2000, is it available in 2003 Server?...more >>

Front Page Server Extensions: Change Port?
Posted by Fao, Sean at 3/22/2005 1:07:50 PM
Hello, I started a new ASP.NET Web Service project in VS .NET 2003 on a remote web server and the only way I could get it to work was by installing the Front Page Server Extensions on the server. I feel very uncomfortable, however, because of the insecure nature of the extensions, in the past...more >>

multiple SSL sites on single IP/port
Posted by yaponamat at 3/22/2005 11:47:02 AM
Hello, I`d appreciate help with the following scenario: I have a Sharepoint installation, obviously on top of IIS. We generated several sites via Sharepoint, that are accessible as third level domains: home.ourdomain.com project1.ourdomain.com, project2.ourdomain.com etc. They are all ho...more >>

Local Groups
Posted by bho at 3/22/2005 9:16:37 AM
I have a number of pre-existing local groups on my Win2k3 box and I want to use them for authentication via IIS. The problem is, I can't add those groups to a site because IIS wants to create it's own local group and therefore won't allow nesting of MY existing group. How can I get IIS to NOT c...more >>

IIS Security Risks & Vulnerabilities
Posted by Roger Cox at 3/21/2005 2:47:02 PM
I am a web developer needing IIS to develop web pages on my PC. I am trying to get IIS installed on my PC within a fully developed network (e.g. DMZ, Firewalls, Network Servers, & Security). According to the network team, IIS poses too much of a threat to be installed on a user PC within t...more >>

OWA Exploit
Posted by Rex Young at 3/21/2005 1:22:24 PM
http://www.securiteam.com/windowsntfocus/5EP0E20F6C.html Anyone have a fix for this?...more >>

Login security issue.
Posted by Michael at 3/21/2005 10:43:38 AM
I've setup an ASP page to allow users to change their password from a website in ADS. The script I have is working, I can change the password, then login with a workstation with the new password and the old password won't work. However, if I connect to a website requiring basic authenticat...more >>

Integrated Windows Authentication Error,
Posted by Arthur Nyunt at 3/21/2005 10:25:04 AM
Hi, I have three w2k3 servers (live, staging and development) currently being setup to service our Intranet. I have built the servers is an identical fashion and use Integrated Windows Authentication to determine who can see certain links on the page. When initially setup all server...more >>

Firewall and Win 2K
Posted by Stibbs at 3/19/2005 1:05:06 PM
Hello all, I have a home development server and need a simple, easy to use and preferably free firewall. Is there such a thing? If not free at lease good. I have had Symantec’s 2002 firewall running but the updates do not work on Win servers. Much thanks David S ...more >>

IIS metabase permissions when creating new VirDir's
Posted by Tony D at 3/18/2005 1:47:08 PM
Hi, Theoretical, architecture-type question here: -=- If one wants to have an Asp.Net app programmatically create new VirDir's, how should you implement this? Open the doors wide-open to the ASPNET user account? (not!) Some Background: -=- We have an Asp.Net app that we ported from A...more >>

Problem with the "Too many users logged"
Posted by Kamyk at 3/17/2005 9:10:36 PM
Hello all! Sometimes I have a problem with the message: The page cannot be displayed There are too many people accessing the Web site at this time. -------------------------------------------------------------------------- Please try the following: a.....more >>

New SSL Certificate not showing on browsers?
Posted by Transam388 at 3/17/2005 2:19:51 PM
We use IIS 5.0 for Outlook Web Access under a secure https port and have a certificate. The original certificate has been replaced with a new one and the original completly removed yet when you go to the site and double click the little lock on the browser to see the SSL details it is still s...more >>

IUSR issue
Posted by Adam at 3/17/2005 1:59:46 PM
- The server was unable to logon the Windows NT account 'IUSR_HYUNDAI' due to the following error: Logon failure: user not allowed to log on to this computer. The data is the error code. - anyone please? all sites hosted by this web server could not be accessed, after a full system patch. ...more >>

does w2k3 server automatically change user's settings based on time?
Posted by Flip at 3/17/2005 10:37:20 AM
I have five users on my w2k3 server and they are setup to view a specific directory accessible via my website in IIS6. Last weekend my users started to fail their logins. I looked at the user setup and all of them had their properties changed to need to change password on next login. When I...more >>

IIS 6.0 Resource Kit
Posted by Phillip LeMaster at 3/16/2005 1:15:05 PM
We just had our annual security audit. We were advised that we should not have IIS 6.0 tools installed on web server connected to the internet. I can not find any information that states this. Does anyone know Microsoft's policy on resource kit installations?...more >>

IIS Server default user account reset after patching?
Posted by Steve Marshall at 3/16/2005 11:21:07 AM
We have a clustered application that required the use of a specific account for anonymous access. The application was configured with a local user account on each node in the cluster and has been working correctly since November. This week 2 situations occured that caused both nodes in the ...more >>

ASPUSER account problem?
Posted by Cwhitmore at 3/16/2005 8:57:04 AM
I've installed an app that requires ASP.NET 1.1. I'm running on Windows 2k Server, with IIS 5.0, Active Directory and ASP.NET 1.1. I get to the login screen of the app, but I get an error message after that. Here is what I've tried so far: 1.) Created ASPUSER account and given it full access ...more >>

SSL & The page cannot be displayed
Posted by Berre at 3/16/2005 4:31:01 AM
I'm having this huge problem on which I have been working for more than a day now and I'm getting desperate. I'm also running out of time as the site is down at this moment. I hope someone here can give me some input on a possible solution. I have an SSL site which is listening on port 443....more >>

Permissions wizard
Posted by rjolivie at 3/15/2005 7:23:08 PM
I've been trying to figure this out for weeks but have been too stuborn to ask. I created an FTP site using IIS. I run the permissions wizard and there is only one option - public FTP site. (note that public does not allow users to upload). I want users to be able to upload. How do I crea...more >>

404 comes back with a 200 added
Posted by Prabha at 3/15/2005 1:15:02 PM
The webserver receives a 404 response code from an IIS filter. However, when it returns the data to the browser, it appends 200 OK along with the content of the target page. Anyone seen this behavior? Anyone knows how to correct this problem? Thanks, Hema ...more >>

Cannot access default site?
Posted by Cwhitmore at 3/15/2005 9:25:03 AM
I have Win2k Server on Active Directory running IIS 5.0 and acting as an ILS server. When I try to access http://localhost or http://servername I get the following error: EVENT # 39141 EVENT LOG System EVENT TYPE Error SOURCE DCOM EVENT ID 10004 COMPUTERNAME FAX2000 TIME 3/15/20...more >>

Problem with Integrated Windows authentication on SSL connection
Posted by mbente NO[at]SPAM gmx.de at 3/14/2005 5:49:47 AM
I'm using a https web site with SSL certificate on a IIS 6 and now I'm trying to configure the access to this site with "Integrated Windows authentication". If I access the site from my notebook which is connected to the LAN it works fine after I added the site to the trusted sites in the IE of ...more >>

Integrated Windows authentication on SLL connection
Posted by mbente NO[at]SPAM gmx.de at 3/14/2005 5:44:41 AM
I'm using a https web site with SSL certificate on a IIS 6 and now I'm trying to configure the access to this site with "Integrated Windows authentication". If I access the site from my notebook which is connected to the LAN it works fine after I added the site to the trusted sites in the IE of ...more >>

Server security
Posted by Jorge_Pérez at 3/13/2005 5:38:33 PM
Hi to all, I have an Internet Server with W2003 and recently we were hacked. I will appreciate if somebody can suggest me a site for novices like me where in a simple language I can find out how to secure my server. Our provider doesn't gives us any support on this matter (he should) and as...more >>

Problem with securing of Windows 2000 SP4 IIS with AD Windows 2003
Posted by Guardian-M2005 at 3/12/2005 7:59:02 PM
I have a question regarding the securing of Windows 2000 SP4 IIS with AD Windows 2003. The symptoms are that the security prompts users to log in on opening an intranet page. I reset the security setting on the folder and the prompting stops. However, after a reboot of the server or restart of...more >>

Cannot set up an ftp site with restricted access
Posted by Tom Allen at 3/12/2005 5:21:11 PM
I want to set up a ftp site on SBS 2003, IIS 6 and I am unable to. I set up a ftp site with no vdir, port 5001, no anon access, permissions set to the user I created in SBS users on the site and the working directory. My firewall in/out is allowing port. If I test on localhost it works fine, ...more >>

Web Application cannot create folder in wwwroot\
Posted by jaz2003 at 3/12/2005 12:09:02 PM
I have IIS 5.1 installed in my Windows XP pro, when my web appilcation is try to create a folder in the wwwrootl dir, it cannot do it so I get an exception error. How can I give full perimsiion to the web application so that it can write to the wwwroot dir? If I create a folder myself in the...more >>

How to create a client side certificate on a Windows 2000 Server
Posted by Abel Chan at 3/11/2005 2:47:05 PM
Hi all, I would like to create a client side certificate on my test box so I can attach it to my BizTalk channel and submit a request to an external HTTPS test site. I used SelfSSL to generate one but I got a 406 error when submitting a request to the external HTTPS site. I compared ...more >>


DevelopmentNow Blog