all groups > iis security > march 2006 > threads for march 15 - 21, 2006
Filter by week: 1 2 3 4 5
DMZ and Domains
Posted by Tewhano at 3/21/2006 11:47:03 AM
I have a web server (2K3) sitting inside the DMZ which accesses data inside
the domain via the firewall. All the data, including the web site, resides on
the data server and is an in-house application. The executables runs on the
web server and fetches the data the customer requests. We have t... more >>
IIS rejects standard Authorization: Digest header
Posted by Maurits at 3/20/2006 11:57:05 AM
The IE team has announced that IE 7 will put warning messages on Basic
Authentication username/password prompts.
So, I'm trying to get Digest Authentication set up as an alternative to
Basic Authentication.
I'm finding that IIS is rejecting Authorization: Digest headers from
Firefox, but ac... more >>
IIS Manager Closes Unexpectedly
Posted by Stuart Fermenick at 3/20/2006 10:55:33 AM
Hello folks!
I have a Windows 2000 server with IIS 5.0. I need to install/import an
SSL certificate into one of the sites.
The problem is, when I click on a site, right-click to open Properties,
select the Directory Security tab, then click the Server Certificates...
button, IIS Manager ... more >>
Windows Authentication
Posted by jc at 3/19/2006 8:24:03 PM
I am using Windows 2003 Server and IIS 6. The website set up as Windows
Authentication. Is there a way I can only allow few users (managers) in my
company to access Website via Windows Authentication? All other company users
will be dennied access?
Thanks,
JimmyChang... more >>
Local Server Logon Required?
Posted by John A Kushwarra at 3/17/2006 12:25:30 PM
Hello
Here is a strange one. I have and asp 2.0 web site hosted on ServerA that
uses windows authentication. When I acces the site from a local pc
everything works the way taht it should. If I access the site from a
browser running on the server that is hosting it I get the windows logo... more >>
Understanding W3SVC1 logs
Posted by Vic at 3/17/2006 12:25:26 PM
Could anyone point me in the direction of a knowledge base or good book that
will help in understanding suspicious looking entries in the logs? I use iis
5, fully patched, anti-virus installed, updated daily and scanned daily.
For example, GET /webcalendar/tools/send_reminders.php
cmd.dat?... more >>
IIS Manager on remote computer
Posted by Drew at 3/17/2006 11:46:40 AM
I have installed IIS manager on a central machine and made an MMC with IIS
for several web servers. It connects and shows me everything including
websites. On some servers, when I click on a website it says "This site
cannot be started because another site running on this computer is already... more >>
Cross Site Scripting - Newbie Question
Posted by Steve Ray at 3/16/2006 7:04:56 PM
Guys
I've been informed today that one of my websites (at work) is allowing CSS.
Apart from Sp'ing and HF'ing the server is there a IIS security tool I can
install on Server 2003 that will prevent all known forms of attacks on the
box, such as a security roll up tool that used to exist for ... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Making ASPNET a Member of Administrator Group??
Posted by Ben at 3/16/2006 11:49:24 AM
I'm working on a C#.Net Web application involving a third party dll. Because
they use SoftLock in that dll, the Web app cannot access that dll at runtime,
and they told me to make "ASPNET" as a member of the Administrator Group.
That fixed the problem, but is that too risky? What might be the ... more >>
administer IIS but not local Admin
Posted by Drew at 3/16/2006 11:49:24 AM
I want to allow an IIS admin to do everything IIS but not be an admin on the
server. I will have them use MMC on a remote computer and open IIS. That
part works when they are in the admins group...looking to make that be a much
smaller group.
This site has some directions that don't qui... more >>
Delegation and IIS service account
Posted by T. Tyrone at 3/16/2006 5:46:18 AM
Hello;
I'm trying to set up a web app that accesses a SQL database on a second
server. I want to use integrated security and have set the computer account
as trusted for delegation. I know I need to use setspn to tell Active
Directory that there is an authorized instance of a service of c... more >>
Moved to new server, I_USR not showing
Posted by Joey Martin at 3/15/2006 12:22:18 PM
I moved web server (from Server 2003 Standard to Server 2003 Web
Edition).
I noticed that permissions hasve changed some under IIS. My asp page
uses FileSystemObject to write file. My old server, this worked fine.
I have verified that WRITE permission is enabled under IIS. But, Under
PERMI... more >>
IISADMPWD Vulerabilities
Posted by Mike B. at 3/15/2006 8:00:30 AM
What problems would be caused if the IISADMPWD page is accessed via
Anonymous access to the pages to the Internet? What kind of vulnerability
would Active Directory be in should this be configured this way? We need a
way for users who are on the road all the time and never come to the offic... more >>
|