Groups | Blog | Home
all groups > iis security > march 2005 >

iis security : Login security issue.


Michael
3/21/2005 10:43:38 AM
I've setup an ASP page to allow users to change their password from a
website in ADS. The script I have is working, I can change the password,
then login with a workstation with the new password and the old password
won't work.

However, if I connect to a website requiring basic authentication, both
passwords work. I've tried closing all browsers to make sure its not
locally cached, plus I've even logged in from a workstation that had no
browsers open and had not previously been authenticated.

It seems to take about 20 minutes for till the old password stops working,
20 minutes is the same as the session timeout.

Could I be reconnecting to the same session even though I've closed all
browsers?

Any ideas on how not to have this happened?

TIA

Michael
3/21/2005 1:57:31 PM
Thanks for the info. I couldn't find that KB when I was looking, wasn't sure
what was being cached.


[quoted text, click to view]

Tom Kaminski [MVP]
3/21/2005 2:23:10 PM
[quoted text, click to view]

This explains it:
http://support.microsoft.com/default.aspx?scid=kb;en-us;152526

--
Tom Kaminski IIS MVP
http://www.microsoft.com/windowsserver2003/community/centers/iis/
http://mvp.support.microsoft.com/
http://www.iistoolshed.com/ - tools, scripts, and utilities for running IIS

AddThis Social Bookmark Button