Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008


all groups > iis security > january 2006

Filter by week: 1 2 3 4 5

IE claims unsafe ActiveX (TDC) on IIS6 and WinXP SP2 only
Posted by ocb NO[at]SPAM inorbit.com at 1/31/2006 6:40:32 AM
Hi. I'm moving an intranet based application from a Windows 2000 server (A) with IIS5 to a newer Windows 2003 server (B) with IIS6. When opening the application (located on B) with a Windows XP SP2 computer, Internet Explorer blocks an ActiveX-object on a crucial page claiming it contains uns...more >>

IWA but Login-Dialog - HTTP-Error 401.2
Posted by Georg Bauer at 1/30/2006 4:58:58 AM
I am using a XP-Client, IIS6 on W2k3 as Server, connected to Tomcat as Servlet-Container. If I start my Servlet without IIS, it works fine, if I start it with IIS (localhost), then IIS shows the Login-Dialog - I have unchecked anonymous access and checked integrated windows authentication. I ...more >>

Authentication
Posted by Mehdi at 1/30/2006 3:45:30 AM
Dear everyone I have a webserver with Windows Advance server 2000 and IIS 5.0,I have a virtual directory on it with basic authentication,When I browse a file from this virtual directory with this command: "http://userName:PassWord@HostName/Path.../filename" if my O.S is Windows 98,20...more >>

Selectively allow a user to Create Virtual Directories?
Posted by Joe at 1/30/2006 12:00:00 AM
We have an SQA machine set up to do testing of IIS hosted web applications. It is running Server 2003/SP1, and is joined to a domain, but not a domain controller. I need to delegate the following tasks to the SQA group, but would prefer not to give them full administrative rights on this ma...more >>

adware
Posted by clayers86 at 1/29/2006 8:49:25 PM
i get popups when ie isnt open. I installed an adware detection program from microsoft but it still happens....more >>

Can't logon on virtual directory
Posted by João Guerra at 1/28/2006 12:12:30 AM
Hi, I have a Website running on IIS in a W2K Server that has a virtual directory to a network resource on a W2K3 DC. The W2K Server is part of the domain. In the MMC i have a red error icon, although i can access the resource and the resource files appear on the MMC. In the Virtual Direct...more >>

Need to restrict access to an EXE in IIS6
Posted by Gregg Hill at 1/27/2006 7:33:46 PM
Hello! I have my web site running on Windows Server 2003 Standard with IIS 6.0. I have an executable file, support.exe, that I want to have accessible to my clients, but not to anyone else. I would like it to be available via http://www.mydomainname.com/support.exe so it is easy to downl...more >>

Website Permissions
Posted by apna at 1/26/2006 8:55:25 AM
Hi, I have Windows 2K with IIS 5.0 and Frontpage Extentions. To get Frontpage Extentions to work right you have to give read, read, and execute permissions to your internet guest users. To make my question easy, I'll show you how my Security is setup on a web folder and then can someone explai...more >>



HTTP to HTTPS
Posted by questions NO[at]SPAM resolutionsnet.co.uk at 1/25/2006 10:09:23 AM
This sounds like a simple question, but I'm getting a little confused If I have page X as HTTP and post to page Y which is HTTPS, is the data sent encrypted? And vice versa, if page Y (HTTPS) posts to page X (HTTP). I generally have both pages (X and Y) in HTTPS, which sorts out my...more >>

Secure IIS Management Interface
Posted by Brian Anderson at 1/24/2006 12:05:12 PM
Anyone know if it is possible to lock down the IIS 6 Manager interface? I need to have underprivileged users have the ability to manage IIS and nothing else on several servers in a web farm. Also any possibility of locking it down to read only access? Thanks, Brian ...more >>

BC31019: Unable to write to output file
Posted by MN at 1/24/2006 8:41:03 AM
My asp.net application works perfectly in IIS 5.0 with Windows 2000, but since its been deployed on Windows 2003 server with IIS 6.0 I have started getting following error on most of the pages "Compiler Error Message: BC31019: Unable to write to output file 'C:\WINDOWS\Microsoft.NET\Framew...more >>

WPAD.DAT problem
Posted by jo.harding NO[at]SPAM vmw.be at 1/24/2006 2:33:11 AM
Hi, i'm trying to get the "automatically detect settings" option in my internet explorer to work (you know, to get automatic proxy configuration form the webserver) i got as far as using the "use automatic configuration script" option with "http://wpad.my.domain.name/wpad.dat" filled in as...more >>

W2k3 IIS6 Basic auth over domain
Posted by Anonymous at 1/24/2006 12:00:00 AM
Hi! Im trying to get basic authentication work in IIS6. I have checked the basic auth box in settings and selected domain and realm but when i try to access the site I have to specify the username in the DOMAIN\USERNAME format or else I'm denied access. I've also tried this on an WinXP work...more >>

App Pool crashes on W2K3 SP1
Posted by Gary at 1/23/2006 12:35:03 AM
Hello, App pool crashes on W2K3 SP1 while running with Network Service identity. However it runs OK under local system account. We didn't face similar issue before SP1. Component services security for Network service has been adjusted, however it didn't help. I would be very grateful for ...more >>

REGISTRY CLEANER
Posted by Bob Johannson at 1/22/2006 6:08:02 PM
I RECNENTLY STARTED RECEIVING A POP UP WANTING ME TO SUBSCRIBE TO A REGISTRY CLEANER PROGRAM IS THIS A LEGITIMATE PROGRAM FROM MICROSOFT OR IS IT SPAM PLEASE REPLY TO bjohanns@telus.net Bob Johannson...more >>

How to reinstall old SSL cert on a IIS installation?
Posted by nospam NO[at]SPAM nospam.sss at 1/21/2006 4:51:50 PM
I had to restore an image to my boot drive. The restore has an IIS image before it had the IIS cert. Is there any way to install the ssl certificate I have? I tried to create a new pending request but I couldn't use my existing cert. I don't have a backup of the private and public keys. J...more >>

Use Secure Sockets Layer for a single web site
Posted by NuBee at 1/21/2006 12:36:02 PM
(1) How do I install (or require SSL) SSL on a web site? (2) Do I have to use a certificate? If yes, can I create my own? -- NuBee...more >>

IIS Security
Posted by RobG at 1/20/2006 12:16:03 PM
I am a local administrator on a Windows Server 2003 system (SP1) and I cannot successfully logon to the Default Web Site. Permissions and Security for WWWRoot lists Administrators as Full Control. What am I missing?...more >>

Wildcard SSL cert error
Posted by news.microsoft.com at 1/20/2006 9:07:24 AM
Hi I have a problem with a wildcard SSL and I'm sure someone else must have come across this scenario and solved it. We have a wildcard SSL *.domain.com I have installed the SSL and if the website is called whatever.domain.com the client receives no errors and the SSL is established. ...more >>

IIS protocol question
Posted by Georg Bauer at 1/20/2006 7:55:02 AM
Hi there, I use IIS6 on Server2003Standard with isapi-redirector to Tomcat 4.1.31 as servlet-engine. Everything works fine, ... but: every time, I call my servlet (even local or from a client) there are three entries in the IIS-Log, the first two of them with an error 401 Where are this erro...more >>

How do I reset ACL of C:\Inetpub\wwwroot
Posted by Gaetan at 1/20/2006 4:20:42 AM
For a long time, I experienced random problems with Microsoft IE Web Controls. Most of the time, I managed to get the Tree View and Tab Strip to work again after they mysteriously stopped working. Unfortunately, IE Web Controls seems to have stopped working for good on my IIS 6.0 server. I tr...more >>

I need less IIS security to fwrite via PHP
Posted by ctrygstad at 1/19/2006 5:11:06 PM
I get denied access, where can I allow PHP to write files? I get error messages when I try to fwrite, and I checked my php.ini file, there is a specific line to grant access to fwrite and fopen, does anyone know anything about this? -- ctrygstad --------------------------------------...more >>

Default Site & Application Pool / ASP.NET security problems
Posted by Jonathon J. Howey at 1/19/2006 1:47:05 PM
Hi, The problem i'm seeing seems to exist only with the Default Web Site and Default App Pool. Earlier today, we installed MS Project Server 2003, and had Sharepoint extend the default Web Site. Since then our two ASPNET applications running, plus WSUS, have stopped working; throwing a .N...more >>

authentication problem IIS6 on Win2003
Posted by Georg Bauer at 1/19/2006 1:21:02 AM
Hello! I really hope, you can help me: I have installed an ASP-application with exactly the same IIS-definitions on Win-XP and it works fine! I try to install the same ASP-application on Windows Server 2003 Standard / IIS6 I have created 3 separate virtual directorys: for the *.asp, for ...more >>

CDOSYS - security
Posted by Rusty at 1/18/2006 1:26:02 PM
I am hosting a few websites on a win2003 server (fully patched) / IIS6. Each site has forms that when filled out use CDOSYS to email info to users inside the company. Everything works great. Are there any CDOSYS vulnerabilities that a spammer could use to take advantage of those forms to ...more >>

Remote access outside local network
Posted by d3scr1pt0r NO[at]SPAM gmail.com at 1/18/2006 5:44:43 AM
Hi, I am trying to use the remote workspace , remote access website of our network, but it seems as it can be accesed only from inside our local network, how can i make it work from outside? Our outlook webmail and OMA work fine from outside. Also a secondary website i have running on a diff...more >>

FP Site Access - User/Pass required ?
Posted by Bob at 1/17/2006 11:07:36 PM
I have a newly built Win2003 server w/IIS6. The server is standalone and there is no AD. Users log onto client machines with credentials that match user/pass accounts on the Win2003 machine. Everything works fine, clients get access to shared win2003 resources as expected. However, when I sta...more >>

Client certificate mapping question
Posted by Bob at 1/17/2006 8:09:30 PM
I have a web server running Windows 2003 with SP1. I need to use a client certificate to control the access to a path. Under Properties -> Directory Security -> Security Communications (Edit) of the folder, I checked Require secure channel and Require client certificates. Then I added a mappin...more >>

keep getting massage -encrypted connection error code 8075
Posted by boxer184 at 1/17/2006 3:26:01 PM
would someone please tell my how to set my encryption higher...more >>

installing virus scanning
Posted by Bad Beagle at 1/17/2006 11:46:05 AM
Is there any ill effects of installing virus scanning on an IIS 6.0 website - is there any directories that should be excluded? ...more >>

Using Root of Drive for Home Directory of Virtual Directory
Posted by hotsdogs at 1/17/2006 9:27:02 AM
Does anyone know of a security issue of using the root of a drive, for instance d:\, as the home directory of a virtual directory in IIS? I am proposing doing this for purposes of Remoting to save a lot of effort in configuring remoting objects. My company already has an established directory ...more >>

Cookies not working on a specific computer
Posted by Padraic at 1/17/2006 3:55:04 AM
I am developing on two seperate laptops and I am posting my code to a hosting provider. My code works perfectly on laptop1 and on the hosting provider. The same code does not work on laptop2. On this laptop2 I am unable to create cookies, sessions or a ticket. I know cookies work on laptop2 ...more >>

IIS on a domain controller
Posted by Khizer at 1/17/2006 2:03:03 AM
Hi, We have a w2003 domain controller which also has IIS ans WSUS on it. Are there any security implications with this setup or do you think it's better if I install IIS and WSUS on a seperate server. Thanks Khizer ...more >>

Can not get Security tab in folder properties to set webserver use
Posted by Steve at 1/16/2006 7:50:02 PM
I am writing an ASP page to edit a database. Ive done it many times in the past successfully and I am using copies of that successful code, so i wont worry about the db code or setup its fine. i can read no problem from the db's, but if i try to edit one i get... Microsoft OLE DB Provider for...more >>

Encryption of Credit Card files
Posted by The Poster at 1/16/2006 12:47:46 PM
G/Day Forum, We are working on complying with the Visa/MAsterCard Payment Card Industry Data Security Standard (PCI DSS). As part of this we need to imply the following controls on the storage of credit card data: to encrypt data at a folder level - that is all of the containing folders and...more >>

Kerberos Error 4
Posted by Michael Morisoli at 1/16/2006 6:24:24 AM
I am still trying to get all my spn's configured properly and seem to be missing something. The details of the event log are; "The kerberos client received a KRB_AP_ERR_MODIFIED error from the server host/vieon-sql2k5-01.vieon.net. The target name used was HTTP/VIEON-Sql2k5-01.vieon.net. ...more >>

Hardware Load Balanced IIS SSL Web Farm
Posted by phil.stollery NO[at]SPAM gmail.com at 1/16/2006 3:39:46 AM
I've read through all the SSL and Web Farm posts on microsoft.public.inetserver.iis.security and non of them seem to have the answer for me. Before I start I have read the following articles: http://support.microsoft.com/?id=313299 (how to setup SSL on webfarms) http://support.microsoft.com/?...more >>

How can I remove the "NTAuthenticationProviders" node in IIS 6
Posted by Michael Morisoli at 1/15/2006 3:00:06 PM
I ran the command cscript adsutil.vbs set w3svc/NTAuthenticationProviders "Negotiate,NTLM" which is causing some services to not use Kerberos which is causing some other problems. I would like to find out how to remove this node as if I never ran the command. Thanks, Mike ...more >>

Restrict by UserAgent
Posted by Ed at 1/14/2006 1:22:02 PM
What was a "trivial occurrence" is now a cause for concern. We've been seeing increased activity which seem to be from Java based crawlers/spiders/scrapers. User agent is of the form: Java/[various versions] Is there a way to restrict/deny requests by a specific useragent on IIS 6 /W2K...more >>

NTFS to secure directory in IIS6 not working as expected
Posted by Troy at 1/12/2006 6:45:02 PM
I am attempting to secure a directory off a URL (ex. www.domain.com/dir1/members I have changed the NFTS permissions on the member (this is not a virutal) directory to remove my anonmyous user and added a user who has local login rights. When I attempt to access the URL, I am prompted for ...more >>

hardening web server
Posted by Bad Beagle at 1/12/2006 6:38:37 PM
Is there a standard security template that comes with IIS to harden it? Anythin like securedc.inf? ...more >>

WSUS - Not Rebooting machines and resetting user profile
Posted by vehemeni NO[at]SPAM gmail.com at 1/12/2006 2:38:13 PM
We are using WSUS as well. All of the updates since the WMF patches has caused some of our Windows 2000 systems to reset the user profile. For example, if my username is vehemeni, when the update finished it hang and did not reboot the machine and i had to manually reboot it. When i then logged...more >>

Accessing from another domain
Posted by Claudio Schmid at 1/11/2006 11:16:03 AM
Hi All. Thanks in advance. I have two Domains, one "AM" and another "EU", I have a website hosted on a server on the domain "AM" called SERVER1, and the site called "Site1". I want thar users from "EU" domain can connect to the Site1, but using Integrated Security on the Site1. The p...more >>

Pass through authentication
Posted by RaziLevin at 1/11/2006 11:00:02 AM
Hello, I was wondering how I could implement pass through authentication. What I need is to be able to programmatically retrieve a users password so that I may pass that information along to another website. Request.ServerVariables("REMOTE_USER") will give me the username how can I get th...more >>

IIS 6.0 Host Headers and Kerberos
Posted by Simon Jackson at 1/11/2006 10:56:02 AM
Hi I have two IIS Servers that are exhibiting the same behaviour one is IIS 5.0 (exchange) the other is IIS 6.0 (Sharepoint Services 2.0) My issues is that if I connect to either of these servers using anything other than the Netbios server name I get prompted for authentication. e.g. ...more >>

Change IIS user access from NT domain to AD
Posted by PaulSe at 1/11/2006 7:06:04 AM
We have migrated from Exchange 5.5 to 2003, creating a new AD for the users and mailboxes. We have another server running IIS 5 that we controlled access to by setting up Windows authentication to the NT domain. We are now trying to link access to the user-id's in AD, to avoid keeping two id...more >>

IP address and domain name restrictions behind a Proxy
Posted by Ben at 1/11/2006 6:00:04 AM
Hi all, We want to control access to different sites with “IP address and domain name restrictions” in IIS6 (2003 SP1) but ran into proxy problems. The server is hosting a Citrix Webinterface 4.0 website and all traffic is routed via/through Citrix Secure Gateway that acts as a proxy,...more >>

IIS requires firefox to do basic authentication
Posted by strycat NO[at]SPAM gmail.com at 1/11/2006 5:41:12 AM
I've got this really weird problem... I have two directories on my server with very similar apps. The index page of both, is a simple web form which submits some fields to an ASP script. This script checks our database, validates the information, and if it thinks the info is correct starts a...more >>

How do I block visitors via referrer in IIS6 ?
Posted by Edwin Lau at 1/10/2006 10:56:55 PM
I was wondering if it is possible to block visitors coming from a particular website ? I want to be able to block via referrer links, if that is at all possible ? Thanks. Edwin...more >>

Default Domain not working on IIS 5
Posted by David Parker at 1/10/2006 8:47:02 PM
I am setting up an ASP web site on IIS 5. To handle authentication, I check Request.ServerVariable("AUTH_USER") and send a 401 Unauthorized response if no user is authenticated. When the login box pops up, I want to specify the default domain so that the user doesn't have to type in domain\use...more >>


DevelopmentNow Blog