all groups > iis security > march 2005 > threads for march 1 - 7, 2005
Filter by week: 1 2 3 4 5
IServerXMLHTTPRequest authentication problem
Posted by Lamberti Fabrizio at 3/7/2005 3:43:55 PM
I've an authentication problem with IServerXMLHTTPRequest.
I've got two web server named WS_1 and WS_2 part of the same NT domain.
On WS_1 I've published on the virtual directory virt1 the asp file
example1.asp.
On WS_2 I've published example2.asp on the virtual directory virt2.
Both vi... more >>
Scope of authentication
Posted by Dave Williams at 3/7/2005 3:12:05 PM
Hi all, I wonder if you can help me with getting rid of a
double-authentication problem.
I have a web service (acutally Exchange OWA) running on server A, and
another service (actually an ASP.NET app I've developed) running on server
B. The users are not authenticated to the domain these two w... more >>
Using Virtual Directory to remote folder
Posted by Lamberti Fabrizio at 3/7/2005 3:05:50 PM
I've created a medium large library of ASP routine and I've published on a
web server part of a NT domain.
Now I need to publish this ASP modules on other web servers part of the same
NT domain.
For not having the problem of synchronization and versioning of ASP modules
on different webserv... more >>
Problems with code behind
Posted by Fabio Negri Cicotti [MCP] at 3/7/2005 2:24:49 PM
Hi,
I have an application written in vb.net /sql server 2000. I am hosting a
test site with a hosting company that offers shared ssl. They have created a
directory for me and I have copied my pages into this directory. Until this
point everything worked just fine, however, since moving the ... more >>
Parent Path Issue in IIS 5
Posted by clf30 at 3/7/2005 11:11:03 AM
I recently disabled parent paths on a Windows 2000 machine running IIS. I ran
the Baseline Security Analyzer and the Parent Paths Enabled area came up as
red flagged. The 3 sites listed in the entry are all sub sites that are set
up as redirect urls like sales.mysite.com, parts.mysite.com,
s... more >>
Is the fact of allowing parent path in IIS a security issue?
Posted by rachidk at 3/7/2005 2:13:03 AM
Hi all
Is the fact of allowing parent path in IIS 6.0 a security issue?
Is it a must for shared hosting accounts not to allow it?
Is it true that any domain on the server could read any file from another
domain when enabled?
Any clues anyone?
Thank you
... more >>
IIS Windows 2003 Basic
Posted by Carl at 3/7/2005 1:01:02 AM
HI
I need some advice. I am new to IIS on Windows 2003 and I need some adivce.
If I have a server on a DMZ and the server is only using http what active
steps do I need to take to secure the server.
Windows update ! Is that enough ?
Do I need to do more then this. Is there a commen "How... more >>
Virus Taking Over E2K3 Server?
Posted by Meron Lavie at 3/6/2005 9:52:44 PM
I have E2K3 installed on W2K3 in full native mode.
Suddenly 3 days ago, I noticed a tremendous load on my Internet connection.
Upon further analysis, I saw that there was an outgoing SMTP connection from
my Exchange server to mx1.business.mindspring.com (sometimes mx2, mx3,
etc.), that was ... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Enable 2003 firewall, can't visit sites
Posted by Mike at 3/6/2005 4:58:21 PM
Hi there,
I've just installed 2003 server, and a single site.
When I enable the built in firewall, I can no longer visit the site, even
when I tick all available service options (including Web Server (HTTP) -
Port 80.
Any advice much appreciated.
Cheers
Mike
... more >>
Basic Security ?
Posted by Robert A. at 3/6/2005 11:36:20 AM
Hi guys,
I use the IIS included in Windows XP Pro, I only use it on my home computer
for development purposes (ASP, PHP, etc.) I looked up security techniques
and it all seems pretty involved and for actually running a Web server.
What's some basic stuff I should be doing in my situation ?... more >>
Expiring passwords
Posted by Allen at 3/4/2005 2:37:01 PM
Is there a standard method to prompt someone (when their password expires)
and allow them to modify their password?
I have a CMS channel that is secured using SSL, IIS (Windows
authentication), and the web.config file. When the user hits the URL, they
are prompted for a userid and password... more >>
Accessing network file form ASP page
Posted by Lamberti Fabrizio at 3/4/2005 2:17:30 PM
Hi all,
I've to access to a network file from an asp pages.
I've red a lot of things on old posts and on Microsoft article but I can't
still solve my problem.
I've got two server inside the same NT domain, each one has its own web
server.
The web server is always IIS 5.0.
One of this ... more >>
IUSR_MachineName privilagies
Posted by GeorgeK at 3/4/2005 12:13:02 PM
Hello everybody,
I have an issue with a new site. I can access the website if I type the
administrator username and password. If not, I receive the "HTTP 401.3
Unauthorized due to access control list (ACL) on resource" message.
I've checked the permissions as per the KB 812614 and everything... more >>
LSASRV SPNEGO error
Posted by Teraze at 3/4/2005 7:01:05 AM
LSASRV SPNEGO error NEGOTIATE_DOWNGRADE_DETECTED
The Security System detected an authentication error for the server
DNS/nXmsa.abcd.edu. The failure code from authentication protocol Kerberos
was "There are currently no logon servers available to service the logon
request.
(0xc000005e)"... more >>
web service extensions for http
Posted by Teraze at 3/4/2005 6:13:04 AM
what IIS web service extensions should be loaded on my web servers (2003) for
export from application to local ms excel or other office apps?... more >>
IIS Authentication bug?
Posted by andy.heydon NO[at]SPAM gmail.com at 3/3/2005 5:21:43 PM
I have an application that is accessed via a Java Servlet, and so in an
IIS environment we have the Jakarta redirector ISAPI filter connecting
to Tomcat. This all works perfectly.
Now our application has its own username data store and so we want to
use that as the basis for authentication. We... more >>
Securing IIS for SUS
Posted by ChrisH at 3/3/2005 3:59:03 PM
I would like to lockdown IIS as much as possible, without affecting SUS. The
web server is used only because SUS requires it, so I dont want to leave my
self open if I dont have to.... more >>
Script generating in each 5 minutes on IIS 6.0. Win 2000
Posted by Marcin Zmyslowski at 3/3/2005 1:56:46 PM
Hello all!
Is it possible to generate some script which will be deleting one value
from specific field from MS SQL Server 2000 (which is a datetime field)
when the date value is 15 minutes older than the current time. But I
want this script to be generating periodicaly in each 5 minutes? I... more >>
WHY can NOT open files in the aspx Page under IIS6?
Posted by swankhli at 3/3/2005 11:02:15 AM
I can open file in the CONSOLE process
StreamReader sr = new StreamReader(@"\\vas4\c$\odbcconf.log");
but I can NOT open files in the WebForm Page under IIS6,WHY???
thanks
Swan
... more >>
security logon failures?
Posted by param NO[at]SPAM community.nospam at 3/3/2005 9:21:12 AM
Hi all, I have a new web server running 2003. It is a member of a domain but
IIS is configured to use all local accounts including IUSR & Network
Service. I have begun to see a bunch of failure audits in the Security Event
Log:
Logon Failure:
Reason: An error occurred during logon
Use... more >>
URL Scan
Posted by Justin at 3/3/2005 6:31:04 AM
I have currently installed URL Scan and configured it for my server. I have a
URL for an ecommerce cart that passes this /4.20/modules/fulfill/promotrk.mvc
URL Scan log says it was rejected because URL contains '.' in the path. The
problem I have is that I allow a . as an extenstion in my ini... more >>
certain file extensions disallowed in IIS6?
Posted by Bob at 3/2/2005 5:29:21 PM
I have two Windows 2003 machine running IIS 6. One of them always returns
404 if the resource being accessed on the URL is jsp or php? The other one
these run correctly. I'm suspecting the extension names jsp and php are
blocked on the first machine as I'm 100% sure the files are there. Where... more >>
Windows Auth requires Anonymous access too...why?
Posted by Jordan at 3/2/2005 2:57:11 PM
I've used Intergrated Windows Authentication before but have been
troubleshooting why a site of mine suddenly stopped working. This required
Integrated Windows Authentication, and no other security was required. This
was working for those computers who were already in the domain, but any
com... more >>
XP can authenticate but some 2000 can't?
Posted by Mike_lsfh at 3/2/2005 8:31:23 AM
We have a perplexing problem where all of our XP clients and most of
our 2000 clients can authenticate to our 2000 Server with IIS 5.0, but
one group of 2000 Professional clients can't. XP machines on the same
subnet as the problem 2000 machines have no trouble (same user on both
machines). Ever... more >>
pages aren't availabe through SSL
Posted by Alan at 3/2/2005 8:17:07 AM
Hi,
I'm having problem configuring SSL on my web server.
I created certificate and assign it to my local server.
I can veiw it from web site I'm trying to switch to SSL.
Then I checked SSL check box and thought it should be enough.
But I'm still getting error message from web browser:
"The pa... more >>
Required permission settings to allow exe to modify text files
Posted by Ben Falcon at 3/1/2005 9:40:38 PM
Hello:
I was previously running W2000 and then upgraded to XP Professional. After
doing so, I can no longer fully test my cgi because it will no longer update
text files (stored in the same directory as the exe). This happened after
the OS upgrade.
My exe file:
C:\Inetpub\wwwroot\Shop... more >>
Problem of DCOM rights with CoInitializeSecurity and IIS
Posted by Eric P. at 3/1/2005 2:26:10 PM
My IIS5/Windows XP internet server runs a CGI.
This CGI tries to instanciate COM objects hosted by a service running on
the same machine.
My problem is that when the Windows XP SP2 is present, the first
CoCreateInstance by the CGI on an object hosted by the service fails
with an access den... more >>
Windows authentication breaks after configuring application pool identity
Posted by Igor Dombrovan at 3/1/2005 12:06:02 PM
Hi group
I run IIS 6.0 on W2k3 being an Active Directory Controller in a test lab.
Create a virtual directory 'test' with Windows authentication on and
anonymous access off.
Create a static test.html file in the directory.
Open it in a browser and it's ok.
Now I configure a separate applicat... more >>
Logoff Issue
Posted by Ken at 3/1/2005 11:04:20 AM
I am new to IIS so please bear with me. I have IIS6 setup on W2K3 Web
Edition. I have removed anonymous connections and require users to login.
When a user tries to access the website they are greeted with a standard
login box. The credentials are compared to the local account list for the... more >>
|