Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!


Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
all groups > iis security > april 2005

Filter by week: 1 2 3 4 5

why request for cmd.exe had passed UrlScan.dll?
Posted by Advertiser at 4/30/2005 6:17:38 PM
The below request for cmd.exe should not have reached IIS. Could somebody please tell me what setting in UrlScan.dll am I missing? This is what what I've found in my WEB server log file: ++++++++++++++++++++++++++++++++++++++++++++++++++++ #Software: Microsoft Internet Information Services 6...more >>


Guest book created through Frontpage
Posted by wosully at 4/30/2005 2:49:02 PM
Hi all, I have locked our 2003 SP1 server down using the security configuration wizard and group policy, now for the fun to begin: ever since I have completed this process, we can no longer write to the guest books. The content is there, but when we type a few words, then click on "Submit...more >>

MS Word Documents
Posted by GRT at 4/30/2005 12:33:47 AM
Setup: ASP.Net, IIS6, basic setup on Windows 2003 Server: -I have a directory in my web application that contains MS Word documents (.doc). -User opens one of the .doc in the browser it opens fine -User leaves the page (back button or close window) and there is a Windows challenge dialog! ...more >>

IIS no longer works with Windows KB886903
Posted by Robert Dickow at 4/29/2005 6:40:33 PM
With Windows update and KB886903 security patch, IIS will not server Active Server pages, .NET, etc. I simply get a 'Resource not found' screen. If I remove KB886903 it works properly again. Normal HTML files are served up fine, but no ASP.NET stuff will work, period. What's with this? B...more >>

Digest access to UNC share
Posted by Alan van der Vyver at 4/29/2005 12:00:00 AM
Hi! I am trying to set up webDAV folders using digest authentication. The event log shows the account authenticating correctly and everything works when trying to access a folder that is on the web server, but when trying to access a folder on another machine through a UNC name, after 3 a...more >>

IIS 5.0 - Create Server Certificate Wizard
Posted by sgm at 4/28/2005 3:35:08 PM
IIS 5.0 ->Default Web site->mywebsite->Right click->Properties->Directory Security In this window, 'Server Certificate' button is disabled. I cannot procedd further. These are some of the things I have tried - I have the admin access to my machine I have tried to remove access for annonymo...more >>

IIS not working in user mode in Xp pro
Posted by aken at 4/28/2005 5:18:03 AM
hi, IIS is being accessed only via administrator and power user. how can user use it. if in user mode, "http://localhost" tying does not perform any activity and shows a page with only error contents. pls suggest steps so that normal users account do have the facility to do ...more >>

Switching from Integrated Authentication to Anonymous
Posted by PMarino at 4/27/2005 9:26:01 PM
Hi all. I have a problem that I'm not sure I understand. I have a web site framework that is designed to support Windows Authentication, Forms Authenticatio or Mixed. When logging off from Windows Authentication, the framework redirects to a special page that allows Anonymous Access but doe...more >>



exporting key
Posted by alexk at 4/27/2005 10:20:27 AM
Good day, When creating a new certifcate requets via the IIS wizard, how the corresponding private key can be exported to a file? The key surely exists, since the cert viewer tells "you have a private key for this certificate" - after the certifcate is approved. (And of course the key exists, o...more >>

401 Error using HttpWebRequest in .NET
Posted by Ryan.Melena NO[at]SPAM gmail.com at 4/27/2005 8:26:45 AM
Hello all, I'm experiencing a very sporadic error since our company upgraded our intranet server to IIS6 (win2k3 sp1). The problem is stemming from an HttpWebRequest made in one of my .NET applications which is attempting to include the contents of a web page in an email. I have attempted s...more >>

Problem with Integrated Windows authentication on SSL connection - second times
Posted by mbente NO[at]SPAM gmx.de at 4/27/2005 7:39:00 AM
I'm using a https web site with SSL certificate on a IIS 6 and now I'm trying to configure the access to this site with "Integrated Windows authentication". If I access the site from my notebook which is connected to the LAN it works fine after I added the site to the trusted sites in the IE of ...more >>

Access Denied to share with anonymous access disabled
Posted by cis042000 NO[at]SPAM yahoo.com at 4/26/2005 4:54:55 PM
My asp.net app is trying to access a local share on my my server. The share and the server are on the same box. To begin with, I gave the ASPNet local user account full access to the share. Then I enabled anonymous access with integrated windows security on the web site. It works like a char...more >>

Traverse rights - yet can read files. Help?
Posted by ben.werdmuller NO[at]SPAM sbs.ox.ac.uk at 4/26/2005 2:59:13 AM
Hi all, I've got an IIS webserver where I need some users (authenticated using active directory) to have traverse rights through a directory but *not* rights to read or execute any of the files in it. I've set up a particular group with traversal rights with no read/execute, yet try as I migh...more >>

Issiung certifcates by a Windows 2000 Enterprise CA
Posted by Patrick at 4/26/2005 12:28:01 AM
Hi All, We have a AD domain with a Win2K and a Win2K3 server. IIS runs on ythe Win2K3 server. I am about to install a Certificate Server on the Wn2K box (anr using "Windows" Certifcatesand then use it to service https requests. Has anyone of you come across/foresee problems with this se...more >>

How to remove version of IIS 6.0 on Windows 2003 Server?
Posted by Mark Smith at 4/26/2005 12:00:00 AM
Hello all. I use Windows 2003 Server and IIS 6.0 for Web Server. I want to remove banners of IIS. URLSCAN is Security Utility for this case, but I can't find version of this utility for IIS6.0 Please give me any idea, how I can remove IIS version baners? Thank in advance. ...more >>

Cannot find server or DNS error
Posted by brianmwood at 4/25/2005 3:08:30 PM
On XP Pro, trying to access a web page (a simple "hello world" type of default.htm page) located in C:\inetpub\wwwroot on an XPe machine on the same LAN. XPe PC name is "SIENNA1", at 192.168.0.100. The other, "Bigguy" is at 192.168.0.101. Both are able to access the internet via IE6. Both can ...more >>

401 Unauthorized trying to read SPList Attachment - owssrv.dll
Posted by Chris Kane at 4/25/2005 8:51:02 AM
We have written a class that enumerates the items in a WSS list and then attemptes to open the attachment for each item. We have written two classes, one to impersonate a user and read in the list information and the other to be called by the first which actually opens the attachment. Our co...more >>

Using custom authentication and integrated authentication in the same time in different subsites?
Posted by mulleteer NO[at]SPAM ziplip.com at 4/25/2005 8:23:16 AM
Hello, Platform: Windows Server 2003 IIS 6.0 I have several subsites in a single web site. Is it possible to have one subsite to use custom login utilizing the CustomAuth.dll (provided in e.g. IIS 6.0 resource kit) while preserving the integrated windows authentication in the other subsit...more >>

Permission Denied when writing text file from ASP Site
Posted by GregRoberts at 4/25/2005 7:59:02 AM
We currently have a custom ASP front end application for our SQL 2000 database. The ASP is running on a Windows 2000 Advanced Server with SP-4 and IIS 5. The ASP files are physically located on the IIS server. The export files must be written to a file server in the domain. Configuration:...more >>

access only through Local groups
Posted by Sk Thilakan at 4/25/2005 12:00:00 AM
Hi All, I have a IIS 6 server, I created a website, and this sevrver in a Domin, = i want give access to this website only the domain users who are in the = local group ( loacl group in the IIS server, not any domain local group) = how do I do that? I am trng varios options not geting what I = ...more >>

SSL doesn't work
Posted by cjobes at 4/21/2005 6:23:03 PM
Hi all, We are trying to get SSL going on one of the websites on a 2003 server. We generated the certificate and it shows up as an option when selecting Sever Certificate under the Security tab on the properties. Everything seems to be fine until we try to connect to the website via https. We ...more >>

SSL Setup
Posted by Willie Bodger at 4/21/2005 3:41:16 PM
OK, here's my dilemma: I have a site with a login script and the usual checking each time you hit a page that requires it. We have finally gotten an SSL cert and it is installed, but from here I am not sure of the best approach to get it implemented. If all of the files pertaining to the area...more >>

IWA with multiple AD
Posted by Tao Tao at 4/21/2005 1:52:02 PM
Hi, have a site on IIS 6.0 configured using IWA only, becaues that site will grab user's logon information to keep track it. people in same AD with IIS server logon fine with no issues. people in other AD (same domain tree, sibling domains) got 401 error. while those users in sibling domai...more >>

Locked out of Frontpage 2002
Posted by Bryan K. Adams at 4/21/2005 9:44:35 AM
Not sure what caused this but I can get to the admin page to manage accounts but if I try to go to the site admin I am locked out? We were running the server in iis 5 isolation mode but we have corrected that problem and switched back to 6. Now I can not add users back to those accounts....more >>

Administrator 401.1 after SP1
Posted by Adam M at 4/20/2005 8:46:52 PM
I'm unable to administer to my sites with my administrator password. Definitely SP1 related is anyone else experiencing the same type issue? Here is the error: You are not authorized to view this page You do not have permission to view this directory or page using the credentials that you...more >>

SharePoint password prompting
Posted by MichaelHensley at 4/20/2005 2:15:01 PM
I have SharePoint installed on Windows Server 2003. I'm accessing it form IE6 on a Windows XP computer logged into the same domain as the server. I'm attempting to configure it so that I don't get prompted for a username and password; however, nothing I do seems to work. I've tried integrated ...more >>

webdav prompts for second password
Posted by tony at 4/20/2005 11:03:12 AM
I have WebDav set up on a 2003 server and everything seems to be working fine. When a user opens a web folder he/she gets prompted to enter credentials and then can browse folders and subfolders that they have access to. The issue is that when they try to open a file like excel or word they...more >>

Why is iis6.log on an XP home machine?
Posted by provasek NO[at]SPAM sbcglobal.net at 4/20/2005 8:28:46 AM
With security concerns that back door trojans can install zombie servers on systems, I am quite concerned that IIS components are installed on my XP home machine, particularly with this log file refering to "returned from France" [4/18/2005 18:52:28] LogFile Open. [***** Search on FAIL/Message...more >>

Service Principal Name Confusion
Posted by boarding_king at 4/20/2005 6:27:02 AM
Setting up IIS 6.0 with Kerberos authentication on sites using domain accounts to run application pools has always caused me problems. I think this is because I never *really* understood what an SPN was and what it was for. Recently I did some reading and I think I've just about got it licked....more >>

FSO exploit
Posted by Savas at 4/20/2005 12:26:02 AM
Hi, My server was hacked over this weekend using the FSO exploit. It is sad that by uploading one simple asp file to one website in a server, hacker can access the whole machine, both drive C and drive D. Well I should have played around with the IUSR permissions not allowing it to access d...more >>

401.1 - Integrated security issue on local machine only
Posted by Chris Kane at 4/19/2005 10:55:03 AM
I recently upgraded our development application server with SP1 for Windows Server 2003 and the Web Services Enhancements 2.0 SP3. Now our developers receive "HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials" when they attempt to work on their VS.Net 2003 web ...more >>

SelfSSL Utility - Not working?
Posted by Jody at 4/18/2005 1:26:05 PM
I just downloaded the SelfSSL for the IIS 6.0 resource kit and ran the following command line: selfssl.exe /NCN=MySSL /K:1024 /Vv:7 /S:1 /P:443 I got a message that it was successful however when I go in to "Directory Security" for my in IIS, the "View Certificate" is grayed out. I also get...more >>

Where to find the denied requests for IIS 6
Posted by Keith-Earl at 4/18/2005 7:57:25 AM
We know that the std IIS logs contain the return codes of 401, 402, etc., but we are interested in the URLScan logs that were present in IIS 5 and prior with the URLScan tool was setup. I am told not to run URLScan or IIS Lockdown on an IIS 6 box because that functionality is baked right in...more >>

UrlScan.dll Terminating
Posted by Advertiser at 4/16/2005 11:04:16 AM
Hi there. I've just installed UrlScan.dll and noticed that at the end of the log = that it is terminated. I have several questions: 1) What causes termination of a UrlScan.dll? 2) What should I do to prevent termination of UrlScan.dll in the future? Thanks....more >>

IIS folder structure and security.
Posted by edroszcz NO[at]SPAM gmail.com at 4/15/2005 3:26:17 PM
Hi, Been browsing for some information about how I should organize our Windows 2003 servers running IIS6. Whith organize I mean which folder structure we should use and to to make it secure. The structure I have atm looks like this: D:\Websites ..=2E. D:\Websites\domain1.com D:\Website...more >>

Need to block Web Spider software like Teleport pro
Posted by Rijesh at 4/14/2005 11:10:01 PM
Hi, Recently our website crashed due to malicious activities by a stranger by using web spider software Teleport pro. Teleport Pro is the software that does this web capture activity, the client that was repeatedly hitting us every few seconds with the ‘web capture’ and ultimately cause...more >>

Looking for suggestions on how to clean up ACL - W2k+IIS
Posted by M. Simioni at 4/14/2005 7:12:13 PM
Hi, i'm new to Windows 2000 server administration. I just got a Windows 2000 server machine that acts as a webserver. I saw that the ACL is very dirty: the ASPNET, FTP and IUSR_ accounts have full control in too much directory. Well, i was looking for a good tutorial on how to clean the acl...more >>

Security concern in event viewer
Posted by Joe at 4/14/2005 4:31:03 PM
I posted this in the Security General section also and was helped to a point but then asked to come here for better assistance. Here goes: Hello, I am getting this in my event viewer every now and then. The configuration information of the performance library "C:\WINDOWS\system32\inetsr...more >>

IIS Challenge for Password. WinXP authenticates differently than Win2k.
Posted by Benjamin Chan at 4/14/2005 2:51:37 PM
To Whom It May Concern: Problem: Windows XP tries to authenticate with IIS as IIS_Machinename\Username Where I'd like to get it to do it like Win2k used to do and authenticate with IIS as Domain\Username I recently migrated IIS from a domain controller where the way the WinXP machines ...more >>

URLScan as an attack vector?
Posted by Sleepless in Vancouver at 4/13/2005 5:25:02 PM
Wondering if anyone has experienced this or may have some insight in to what happened. We discovered that production internet web-server (in a DMZ) stopped serving pages after a reboot (patches). We had installed the patches on test servers earlier in the day and not experienced any proble...more >>

How to tell if IIS lockdown Tool is installed?
Posted by John Smith at 4/12/2005 12:00:00 AM
Hi Sorry for the simplicity of this question but can anyone tell me how I can easily tell if the IIS lockdown Tool as been installed on a machine. I know it doesnt appear in Add/Remove programs. I also know Urlscan does appear there but URLscan may have not been installed. I have compared ...more >>

How to set up a certificate server
Posted by Alvaro Moncada at 4/11/2005 1:44:44 PM
Hi guys, Our company has been required now to encrypt our e-mails and FTP transmissions by the new HIPPA regulations. I've been researching a few options like using PGP or MS Certificate server. I was wondering if some one out there could provide with some information about setting this ser...more >>

IIS calling cscript.exe from cgi permission denied - WMI access
Posted by J M at 4/11/2005 12:00:00 AM
I have a perl cgi script on Windows 2003 server with IIS 6.0 that is calling prnport.vbs, prnmgr.vbs (supplied by microsoft that creates printer port and print queue on server) however IIS returns "cscript ... permission denied" error even after adding IUSR_<SERVER> user id to administrator l...more >>

Anonymous access
Posted by finding.alan NO[at]SPAM gmail.com at 4/10/2005 11:10:59 PM
Hi Ken, I had found my problem of those "HTTP and 404" and "The Page cannot be displayed". The problem due to those shared folder didn`t configure as a Web Shaing. Thanks for your advise for the past few days. I have a question to you. I had deleted my default web site and created a new one a...more >>

Intranet problem - 404 and 405 errors
Posted by David at 4/8/2005 10:01:06 AM
We have recently moved from Server 2000 to SBS 2003. In addition to the companyweb site, I also wanted to set up an intranet that housed a few functions and applications for our internal users that are html-based. I created a new web-site, etc. called home. If I type http://home in my bro...more >>

IIS 6 conflict using port 443 for NON-SSL traffic
Posted by Richard Dixson at 4/8/2005 9:31:34 AM
I need IIS to respond to HTTP requests on port 443 for different IPs on the same web server, with one IP set up to handle NON ssl traffic (http://), and the other set up with a certificate to handle SSL (https://) traffic. IIS 6.0 (using Win2K3 latest updates/patches) will NOT allow this. When...more >>

request certificate immediately
Posted by John Grandy at 4/8/2005 8:41:32 AM
IIS > Default Web Site > Properties > Directory Security > Secure Communications > Server Certificate > In the Wizard's 2nd pane choose "Create a new certificate" ... In the 3rd pane, the choice "Send the request immediately to an online certification authority" is disabled. How to enab...more >>

update databse
Posted by sebastiano at 4/8/2005 12:41:03 AM
Hi, i have this configuration: *) Windows 2000 server *) iis 5.0 *) pages html + page asp (no asp.net) *) 1 file as databse (access 2000) *) website and database are on the same computer the problem is: i have a web server where i need to update a databse only with an authenticated users. ...more >>

encrypting and signing
Posted by John Grandy at 4/7/2005 3:50:18 PM
I understand the use of public/private keys for encrypting. Could someone explain to me how a second public/private key pair is used for signing? Thanks. ...more >>

NTFS permissions
Posted by Darren at 4/7/2005 8:05:08 AM
I'm going in circles trying to figure this out without any luck. I disabled anonomous access and am using basic authentication (integrated unchecked as well). I have created a local user on the IIS 6.0 server and assigned this user NTFS permissions to directories in question. From the out...more >>


DevelopmentNow Blog