Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > march 2006

Filter by week: 1 2 3 4 5

On sandboxes, and why you should care
Posted by Dinis Cruz at 3/31/2006 11:50:28 PM
Here is a post I did to the webappsec mailing list which I is very relevant to this newsgroups. I also very interested if your comments about this issue. Dinis -------- Original Message -------- Subject: On sandboxes, and why you should care On 29/03/06, Andrew van der Stock <vand...more >>


Simple Anonymous Access question
Posted by rolfejr NO[at]SPAM gmail.com at 3/31/2006 2:39:20 PM
I accidentally posted the following message in the ASP newsgroup, so I thought I would post it here as it probably belongs in this group instead. I have what I think is a simple question but I am finding nothing but complicated answers. I have a web site running on IIS6. One directory used...more >>

Communicator Web Access Authentication Not Working
Posted by Ben at 3/31/2006 1:32:50 PM
Hi, I'm trying to setup Communicator Web Access (CWA) on a server that is already running Live Comms 2005, Exchange 2003 & OWA. I have done a test install on a VMWare machine, got it up and running successfully. However now I am trying to do it on the live system, I can not get it working. ...more >>

Iusr_Servername NetworkPrinter
Posted by Lye at 3/31/2006 7:52:02 AM
Hi, any expert out there can advise on how to allow the iusr_servername to access a network printer? I have try the solution posted on KB to edit the hkey_users/.default..... setting, no luck. Please help..... I need the isur_servername to print to a printer link to a PC printserver. I have se...more >>

Do I really need a wild card certificate ?
Posted by Mike_IntermediateVB at 3/30/2006 4:42:01 PM
I am trying to set up a virtual directory that uses SSL (at the moment it just contains index.htm). Once all the various settings are set I can navigate to this page from within my network (but external sites produce a page not found error) If I switch off ‘Require SSL’ I can navigate to t...more >>

BIN Directory being hidden automatically
Posted by T-1000 at 3/30/2006 3:13:44 PM
For some reason all of the BIN folder in any IIS virtual servers are being hidden automatically. I don't mean hidden from the .net application, but simply hidden. They are visible only via FTP or command prompt, but not explorer (regardless of folder options.) There have been no changes made...more >>

Restricting IIS from serving static content
Posted by Nico at 3/30/2006 1:57:05 PM
I'm trying to determine the best way to restrict access to static files in IIS6.0. From my understanding the recommended solution is to remove the extension from the MIME types in the IIS6.0 console. However testing has shown that you also need to remove these from HKEY_CLASSES_ROOT as well....more >>

IIS and enterpise sub CA on different machines
Posted by Edward Ray at 3/30/2006 12:50:32 PM
The Brain Komar texts implies that the enterprise subordinate CA (i.e. issuing CA) needs to reside on the same machine as IIS. From a security perspective, this seems like a poor design. From a network standpoint, it means I have to support multiple IIS servers in my LAN. Neither is accep...more >>



Current User Credential Security settings don't seem to allow access when they should.
Posted by D Witherspoon at 3/30/2006 11:23:00 AM
IIS 6 Win2K3. I created a new virtual folder. That points to \\fileshare\myfolder. the virtual folder is set to use integrated windows authentication and the "connect as" is set to "Always use the authenticated user's credentials when validating access to the network directory." So.. I...more >>

Err:The server certificate for instance '4' has expired or is not
Posted by vecozo NO[at]SPAM online.nospam at 3/30/2006 3:22:01 AM
Hello, We have three environments test, acceptance and production. On the test and production environment everything works fine, but acceptance is something different. So you should say make acceptance the same as test and production. So I did but it still doesn't work. When I open my webse...more >>

run cgi in localhost without SSL?
Posted by jdinares at 3/30/2006 3:05:02 AM
hi, sorry by my bad english in advance. Configured server with IIS 6 and one Certificate SSL in default web. All run ok. I need one .cgi of this web to run locally without SSL : Configured additional virtual web in the server for access locally without SSL to the website via http://loc...more >>

Website unable to download *.exe's
Posted by Brian at 3/29/2006 1:09:01 PM
I have a webiste where the web master would like to have others download exe off the site. Righth now when I try to click on the link it will not download the file. If I chage it to a zip file it works just fine... Any thought or ideas Thanks, Brian...more >>

IIS Version and Interanl IP being Revealed
Posted by DoktorWho at 3/28/2006 11:20:02 AM
During a recent security scan of our IIS 6 box, it was shown that the II Version, 6 in this case, and the Internal IP address of the box were being shown externally. Why would this be and how can I fix this. The box is natted behind a firewall....more >>

Anonymous Account not working
Posted by Ishmealm at 3/28/2006 7:27:05 AM
Hi, I recently built a new webserver to replace an existing server. I copied the data to the new server and rebuilt all of the IIS directories by hand. I replaced the broken SID of the old IUSR account on all of the folders with the new IUSR account from the new server. Now when I try...more >>

IIS 5 allows anonymous editing via Frontpage
Posted by Tim100873 at 3/27/2006 5:12:01 PM
Greetings, We are running IIS 5, and have run the lockdown tool (2.1) using the FPEx template. We have noticed that anyone that opens the website inside Frontpage can edit the contents of all websites on this server without being prompted for a password. We hope this is a simple misconfigu...more >>

Passing form credentials to windows security
Posted by Doug at 3/27/2006 12:23:01 PM
Ok to explain my scenario here is my goal I have an intranet site that is available internally as well as externally. Currently it is just html files on the intranet (that change may come later which will make it easy to secure via an application, unfortunately right now that is not an opt...more >>

IIS6 'forgets' "Connect As" password for Virtual Directory
Posted by Richard Manion at 3/27/2006 10:55:02 AM
I have a website that contains a virtual directory mapped to a UNC using a domain account under "Connect As." Users are normally able to browse the virtual directory without incident. The site exist on an NLB cluster. Occasionally, one or two of the servers will forget the "Connect As" Passw...more >>

Cannot connect to Web Server from Different Domain
Posted by nai at 3/27/2006 2:14:02 AM
Hi all, We have two domains in here and are currently migrating users from Domain A to Domain B. We have a trust relationship setup between the two and are using Windows Integrated Security for Authentication. My IIS Server is in Domain A. I can connect to the webserver using User X ...more >>

403 (Forbidden) after setting up SSL Redirect
Posted by AHoff at 3/24/2006 10:51:03 AM
I've gone through the steps of redirecting HTTP requests to HTTPS for OWA as outlined in KB-839357. I've checked, rechecked, and checked again that all steps were followed but I still get: HTTP Error 403 - Forbidden You are not authorized to view this page My head hurts from banging it on...more >>

Single authentication for multiple IIS 6 servers
Posted by news.microsoft.com at 3/24/2006 10:29:56 AM
Thanks in advance for your help ... Environment: .. We have several IIS servers, one for each of the following: Exchange 2003 OWA, Sharepoint 2003, and CRM 3. .. All are Windows 2003 and part of the same domain .. Web access is set to integrated on all servers. .. Network is behind a Symant...more >>

HTTP_AUTHORIZATION header
Posted by AWillemsen at 3/24/2006 7:33:02 AM
I am running IIS 5.1 on XP SP2. I have two virtual directories in the same Web site that have anonymous access disabled - one contains HTML pages and the other contains a CGI executable. One of the HTML pages has a form which executes the CGI. If I open a new browser window, and then ope...more >>

Can't audit security events
Posted by Vic at 3/23/2006 9:16:32 AM
Heres my problem: There is a webserver at work, win2k, that originally was joined to the domain, but is always logged on locally. We can't get it to audit security events - domain policies override local policies. We logged on with an admin account from the domain to attempt to look at the...more >>

Multiple SSL certs on virtual servers - again
Posted by justageezer at 3/23/2006 4:15:28 AM
Hi all, I've read the posts on multiple SSL certs on virtual servers, as well as the kb articles (again) and I'm wondering if anyone has had the same issue I'm getting now. In the past I've always managed to get multiple certs working by either using a different port or a different IP address...more >>

Is there a way of downloading .cer files like you would do with .doc or .MP3
Posted by Lion at 3/23/2006 12:00:00 AM
I'm using IIS 6.0 on a Windows 2003 Std, I have created Virtual Directory called test\ and in there I have index.htm and also web.cer (web.cer is the certificate that I want my users to download for there PDA's) the index.htm displays OK but when I click on to the link that points to web.cer I...more >>

DMZ and Domains
Posted by Tewhano at 3/21/2006 11:47:03 AM
I have a web server (2K3) sitting inside the DMZ which accesses data inside the domain via the firewall. All the data, including the web site, resides on the data server and is an in-house application. The executables runs on the web server and fetches the data the customer requests. We have t...more >>

IIS rejects standard Authorization: Digest header
Posted by Maurits at 3/20/2006 11:57:05 AM
The IE team has announced that IE 7 will put warning messages on Basic Authentication username/password prompts. So, I'm trying to get Digest Authentication set up as an alternative to Basic Authentication. I'm finding that IIS is rejecting Authorization: Digest headers from Firefox, but ac...more >>

IIS Manager Closes Unexpectedly
Posted by Stuart Fermenick at 3/20/2006 10:55:33 AM
Hello folks! I have a Windows 2000 server with IIS 5.0. I need to install/import an SSL certificate into one of the sites. The problem is, when I click on a site, right-click to open Properties, select the Directory Security tab, then click the Server Certificates... button, IIS Manager ...more >>

Windows Authentication
Posted by jc at 3/19/2006 8:24:03 PM
I am using Windows 2003 Server and IIS 6. The website set up as Windows Authentication. Is there a way I can only allow few users (managers) in my company to access Website via Windows Authentication? All other company users will be dennied access? Thanks, JimmyChang...more >>

Local Server Logon Required?
Posted by John A Kushwarra at 3/17/2006 12:25:30 PM
Hello Here is a strange one. I have and asp 2.0 web site hosted on ServerA that uses windows authentication. When I acces the site from a local pc everything works the way taht it should. If I access the site from a browser running on the server that is hosting it I get the windows logo...more >>

Understanding W3SVC1 logs
Posted by Vic at 3/17/2006 12:25:26 PM
Could anyone point me in the direction of a knowledge base or good book that will help in understanding suspicious looking entries in the logs? I use iis 5, fully patched, anti-virus installed, updated daily and scanned daily. For example, GET /webcalendar/tools/send_reminders.php cmd.dat?...more >>

IIS Manager on remote computer
Posted by Drew at 3/17/2006 11:46:40 AM
I have installed IIS manager on a central machine and made an MMC with IIS for several web servers. It connects and shows me everything including websites. On some servers, when I click on a website it says "This site cannot be started because another site running on this computer is already...more >>

Cross Site Scripting - Newbie Question
Posted by Steve Ray at 3/16/2006 7:04:56 PM
Guys I've been informed today that one of my websites (at work) is allowing CSS. Apart from Sp'ing and HF'ing the server is there a IIS security tool I can install on Server 2003 that will prevent all known forms of attacks on the box, such as a security roll up tool that used to exist for ...more >>

Making ASPNET a Member of Administrator Group??
Posted by Ben at 3/16/2006 11:49:24 AM
I'm working on a C#.Net Web application involving a third party dll. Because they use SoftLock in that dll, the Web app cannot access that dll at runtime, and they told me to make "ASPNET" as a member of the Administrator Group. That fixed the problem, but is that too risky? What might be the ...more >>

administer IIS but not local Admin
Posted by Drew at 3/16/2006 11:49:24 AM
I want to allow an IIS admin to do everything IIS but not be an admin on the server. I will have them use MMC on a remote computer and open IIS. That part works when they are in the admins group...looking to make that be a much smaller group. This site has some directions that don't qui...more >>

Delegation and IIS service account
Posted by T. Tyrone at 3/16/2006 5:46:18 AM
Hello; I'm trying to set up a web app that accesses a SQL database on a second server. I want to use integrated security and have set the computer account as trusted for delegation. I know I need to use setspn to tell Active Directory that there is an authorized instance of a service of c...more >>

Moved to new server, I_USR not showing
Posted by Joey Martin at 3/15/2006 12:22:18 PM
I moved web server (from Server 2003 Standard to Server 2003 Web Edition). I noticed that permissions hasve changed some under IIS. My asp page uses FileSystemObject to write file. My old server, this worked fine. I have verified that WRITE permission is enabled under IIS. But, Under PERMI...more >>

IISADMPWD Vulerabilities
Posted by Mike B. at 3/15/2006 8:00:30 AM
What problems would be caused if the IISADMPWD page is accessed via Anonymous access to the pages to the Internet? What kind of vulnerability would Active Directory be in should this be configured this way? We need a way for users who are on the road all the time and never come to the offic...more >>

SSL redirect to non-SSL
Posted by Daniel Kaplan at 3/14/2006 9:35:40 PM
Not sure if I am in the right group, but question. If I am going from an SSL page to a non-SSL page (like after loggin on) is there a way to get the browser to NOT give that "you are being redirected to a non-secure page" ? Thanks ...more >>

ASP app upgrade to IIS6 with new Authentication scheme
Posted by pwarda NO[at]SPAM gmail.com at 3/14/2006 3:37:10 PM
Hello all, we have an existing ASP 3 based application that use to run perfectly with SQL Server 7. We have been mandated to migrate the site over to the following configuration: WebServer (server 1) Windows 2003 (with IIS 6 of course) Database (server 2) SQL Server 2000 Windows 200...more >>

IIS requires credentials all the time....PART II
Posted by Lobo at 3/14/2006 2:29:38 PM
Yesterday's post: I have IIS server on Server 2003 and Anonymous Access and Windows Integrated Security are checked but when some users wants to access site IIS requires credentials ... If I turn off Integrated Security then I get message "You are not autorized to view this page" I tr...more >>

SSL Posting question
Posted by Poker Man at 3/14/2006 9:26:32 AM
Hello All, Curious about something. Am using SSL on one of my pages to process payments with a credit card. Now when the user doesn't fill out all the info properly I repost the form to ask for the missing fields. My question is this, since the page is reposting to itself, and is under ...more >>

access when I use my ip address
Posted by Dooma at 3/13/2006 5:50:23 PM
When I try to access my local SharePoint site I get an error http 500 but when I use my local IP address I can logon fine. Is there a problem. I am using windows 2003 AD with local DNS server. Please help ...more >>

IIS requires credentials all the time....
Posted by Lobo at 3/13/2006 3:09:35 PM
I have IIS server on Server 2003 and Anonymous Access and Windows Integrated Security are checked but whwn some users wants to access site IIS requires credentials ... If I turn off Integrated Security then I get message "You are not autorized to view this page" I tried to change Home Di...more >>

Intermittent login issue
Posted by Bill at 3/13/2006 9:21:30 AM
Hello, We are using MBS Business Portal 2.5 on a 2003 server (also domain controller). We are using Basic authentication with SSL. (Integrated Authentication is not an option due to clients not being part of the Windows domain). We also have a Novell NDS network and sync accounts to AD u...more >>

Problems with IIS6 / SSL
Posted by Lajus Norvejikus at 3/13/2006 9:11:32 AM
Hi all, I recently installed one Windows 2003 Server and after I installed IIS 6. I have 2 web sites configured: one I want to answer to port 80, the other will listen 443. I install a certificate (ok) using the acticle id 816794 as reference. Everything seems ok. Only... SSL do not work! T...more >>

Locking down FPSE
Posted by psychogenic at 3/13/2006 8:20:58 AM
Does Visual Interdev use an account to gain access to a remote web server or does IIS treat it as an anonymous guest user? We have web developers who insist on having FPSE installed on the production server but the problem is we also have other people in our WAN who have Interdev installed (othe...more >>

Getting Server SSL Cert Expiration Info
Posted by Jul.Genis NO[at]SPAM gmail.com at 3/13/2006 8:12:35 AM
Hello, I am trying to come up with a solution which will help me gather ssl certificacte expiration date remotelly. So far the only solution that i caould come up with is running the following command on remote servers: certmgr.exe /s -r localmachine my >> \\server\share\exp_date.txt I trie...more >>

Lock user in website folder
Posted by ttopholm at 3/12/2006 4:10:27 PM
How can I lock an iusr_ so it can't go out of it's wwwroot folder... Because I found a script, which can show my whole C-drive with fso in asp, but I want to disable that so it only can see the wwwroot and not outside that. in the php-engine you have open_basedir, do you also have that in ...more >>

Help me to install IIS
Posted by dkedia NO[at]SPAM gmail.com at 3/11/2006 4:19:26 AM
I have windows XP professional, no service pack, FAT32. I have installed IIS. it is showing in Control Panel- Admin.Tools-IIServices. Inetpub, wwwroot folders have been created. But any .asp file doesn't work. Now i went in Control P.-admin.tools-iis-website-default w.site-right click on All T...more >>

Page Access based on Computer Name
Posted by Jeff at 3/10/2006 7:56:29 AM
Can access to a web page on a Windows 2003 standard server running iis 6 be granted permissions based on computer name. This will all take place on the companies local intranet in a WIndows AD enviroment. Thanks, ...more >>


DevelopmentNow Blog