Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008


all groups > iis security > march 2006 > threads for march 15 - 21, 2006

Filter by week: 1 2 3 4 5

DMZ and Domains
Posted by Tewhano at 3/21/2006 11:47:03 AM
I have a web server (2K3) sitting inside the DMZ which accesses data inside the domain via the firewall. All the data, including the web site, resides on the data server and is an in-house application. The executables runs on the web server and fetches the data the customer requests. We have t...more >>

IIS rejects standard Authorization: Digest header
Posted by Maurits at 3/20/2006 11:57:05 AM
The IE team has announced that IE 7 will put warning messages on Basic Authentication username/password prompts. So, I'm trying to get Digest Authentication set up as an alternative to Basic Authentication. I'm finding that IIS is rejecting Authorization: Digest headers from Firefox, but ac...more >>

IIS Manager Closes Unexpectedly
Posted by Stuart Fermenick at 3/20/2006 10:55:33 AM
Hello folks! I have a Windows 2000 server with IIS 5.0. I need to install/import an SSL certificate into one of the sites. The problem is, when I click on a site, right-click to open Properties, select the Directory Security tab, then click the Server Certificates... button, IIS Manager ...more >>

Windows Authentication
Posted by jc at 3/19/2006 8:24:03 PM
I am using Windows 2003 Server and IIS 6. The website set up as Windows Authentication. Is there a way I can only allow few users (managers) in my company to access Website via Windows Authentication? All other company users will be dennied access? Thanks, JimmyChang...more >>

Local Server Logon Required?
Posted by John A Kushwarra at 3/17/2006 12:25:30 PM
Hello Here is a strange one. I have and asp 2.0 web site hosted on ServerA that uses windows authentication. When I acces the site from a local pc everything works the way taht it should. If I access the site from a browser running on the server that is hosting it I get the windows logo...more >>

Understanding W3SVC1 logs
Posted by Vic at 3/17/2006 12:25:26 PM
Could anyone point me in the direction of a knowledge base or good book that will help in understanding suspicious looking entries in the logs? I use iis 5, fully patched, anti-virus installed, updated daily and scanned daily. For example, GET /webcalendar/tools/send_reminders.php cmd.dat?...more >>

IIS Manager on remote computer
Posted by Drew at 3/17/2006 11:46:40 AM
I have installed IIS manager on a central machine and made an MMC with IIS for several web servers. It connects and shows me everything including websites. On some servers, when I click on a website it says "This site cannot be started because another site running on this computer is already...more >>

Cross Site Scripting - Newbie Question
Posted by Steve Ray at 3/16/2006 7:04:56 PM
Guys I've been informed today that one of my websites (at work) is allowing CSS. Apart from Sp'ing and HF'ing the server is there a IIS security tool I can install on Server 2003 that will prevent all known forms of attacks on the box, such as a security roll up tool that used to exist for ...more >>



Making ASPNET a Member of Administrator Group??
Posted by Ben at 3/16/2006 11:49:24 AM
I'm working on a C#.Net Web application involving a third party dll. Because they use SoftLock in that dll, the Web app cannot access that dll at runtime, and they told me to make "ASPNET" as a member of the Administrator Group. That fixed the problem, but is that too risky? What might be the ...more >>

administer IIS but not local Admin
Posted by Drew at 3/16/2006 11:49:24 AM
I want to allow an IIS admin to do everything IIS but not be an admin on the server. I will have them use MMC on a remote computer and open IIS. That part works when they are in the admins group...looking to make that be a much smaller group. This site has some directions that don't qui...more >>

Delegation and IIS service account
Posted by T. Tyrone at 3/16/2006 5:46:18 AM
Hello; I'm trying to set up a web app that accesses a SQL database on a second server. I want to use integrated security and have set the computer account as trusted for delegation. I know I need to use setspn to tell Active Directory that there is an authorized instance of a service of c...more >>

Moved to new server, I_USR not showing
Posted by Joey Martin at 3/15/2006 12:22:18 PM
I moved web server (from Server 2003 Standard to Server 2003 Web Edition). I noticed that permissions hasve changed some under IIS. My asp page uses FileSystemObject to write file. My old server, this worked fine. I have verified that WRITE permission is enabled under IIS. But, Under PERMI...more >>

IISADMPWD Vulerabilities
Posted by Mike B. at 3/15/2006 8:00:30 AM
What problems would be caused if the IISADMPWD page is accessed via Anonymous access to the pages to the Internet? What kind of vulnerability would Active Directory be in should this be configured this way? We need a way for users who are on the road all the time and never come to the offic...more >>


DevelopmentNow Blog