Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008


all groups > iis security > april 2006

Filter by week: 1 2 3 4 5

.exe file downloads return 404 in IIS6.0
Posted by Neil Barras at 4/28/2006 9:41:25 PM
Hi all, I set up an IIS6.0 server and have some downloads that are executable files. When I try to download them using both IE and FireFox, it returns a http404. I thought I had found a solution online http://blogs.msdn.com/david.wang/archive/2005/07/11/Allow_file_downloads_on_IIS_6.aspx, ...more >>

Multiple virtual SSL sites on 1 IIS6 server
Posted by Troy at 4/28/2006 9:11:01 PM
I host several virtual web sites on an IIS6 server utilizing the host header record for differentiating each site. I currently have 1 SSL site on this server but would like to configure a few more. I did some web searching and if I was understanding everything correctly, you can do this but ...more >>

IIS 6.0 Hide Domain Name during Authentication
Posted by Chris at 4/28/2006 9:47:01 AM
Hello, I am in the process of deploying out SQL Reporting Services. Is there a way that I can hide the domain name or the server name when the popup box appears during authentication?...more >>

Windows 2003 R2 and WSE 3.0 Kerberos issue
Posted by Niels Flensted-Jensen at 4/28/2006 6:52:02 AM
Running a Windows 2003 R2 Standard configured as a domain controller (the machine will be used as a stand alone demo machine) Working the Kerberos sample in %Program Files%Microsoft WSE\v3.0\Samples\CS\QuickStart\Security\WSSecurityKerberos\Policy It works fine with the service hosted by I...more >>

Access Databases & IIS 6.0
Posted by Gary at 4/28/2006 5:58:01 AM
Hello, I administer a Windows Server 2003 running IIS 6. I also administer multiple web sites that are hosted on this server. One of the end-users maintains some Access databases that are contained in one of the virtual webs. He gets the following error message from time to time: Unable ...more >>

Port 80 still works after "Require secure channel (SSL)"
Posted by Shifarad at 4/28/2006 4:51:01 AM
Hi all, After i locked down a Win2003 Server I installed a certificate, checked the "Require secure channel (SSL)" , but i can still logon to this web application over http. https is working also fine. Any Ideas? Thanks, Shif ...more >>

2 Websites with SSL - wrong certificates displaying for second sit
Posted by Jennifer at 4/27/2006 9:26:02 AM
We are running win 2K and IIS. We have 2 websites configured on the same box, each running on different IP addresses. THere are subdomains pointing to each of the IP addresses. We turned on SSL and have 2 different certificates for each site (running on 2 different IP addresses). Everythin...more >>

enable smart card authentication on iis with php
Posted by Wayne at 4/26/2006 10:02:51 PM
I have a website on an intranet that uses php and all of our users utilize smart cards for login to active directory. Can someone point me to something that shows how to implement smart card authentication on iis/php? Right now, the php page queries for the username/password and checks against...more >>



IIS IP and domain name restrictions - automated access denial
Posted by ChrisH at 4/26/2006 8:01:01 PM
Hello I've had some issues with IP addresses appearing to be automatically added to IP address restrictions (at the 'web sites' level) and being denied access on an exchange front end server. This is affecting OWA users as it prevents access to their email. Does anyone have any suggesti...more >>

Muliple Websites on Mutliple IP address with certicles [SSL]
Posted by Jennifer at 4/26/2006 4:33:01 PM
We are running win 2K and IIS. We have 2 websites configured, each running on different IP addresses. THere are subdomains pointing to each of the IP addresses. We turned on SSL and have 2 different certificates for each site (running on 2 different IP addresses). Everything seems to be w...more >>

Remote administration security group.....
Posted by CB at 4/26/2006 11:20:01 AM
We have single server that we are using for development, and have invited some 3rd party developers to create some aspnet content on the server. They have requested Terminal Services Login (remote desktop). WHAT is the minimal security group or Best Practice for giving outside users such permi...more >>

File permissions vary based on access method problem
Posted by Daniel Stratton at 4/26/2006 5:29:03 AM
I'm currently maintaining an intranet ASP based product for a small business, and I have run into an odd problem. I have a directory which is full of documents that need to be accessed via a central website, both internally from the office, and externally from home. The data sits on the se...more >>

Strange issue with Integrated authentication and 3G
Posted by Sunny at 4/25/2006 2:13:18 PM
Hi All, (I am hoping for some inspiration here) We have a problem which has appeared in the past few weeks where our laptop users remotely connect with XP SP1 and SP2 laptops to Windows 2003 SP1 AD network using Cisco VPN client. Transport is one of: 1) modem PSTN connection 2) broadband...more >>

scripts only runs wehn AppPool Identity = LocalSystem
Posted by John C at 4/25/2006 1:03:01 PM
Our dev team is in the midst of a code migration from old ASP to PHP. In the process of migration, we need an ASP form to run a php-win command in the background. This works fine if the AppPool identity is LocalSystem, but the php-win quietly does nothing if I set AppPool identity to NetworkSe...more >>

integrated authentication only work when I use ip address
Posted by zolar25 NO[at]SPAM gmail.com at 4/25/2006 7:30:41 AM
I have a problem with a accessing sharepoint web site using integrated authenication, If i use http://ip address it works fine. If I add a entry to the host file of the client machine ip address sitename it works fine But if i try to access it via http://servername or http://servername.domai...more >>

Problems with IIS 5 default domain
Posted by davelj at 4/21/2006 8:02:01 AM
I have a W2000 server running IIS 5 for my local intranet and a help desk website. We use basic authentication and I have set the default domain to my local domain name. When a user attempts to login the login is rejected unless the user enters his login as domain\username. When the user only ...more >>

IE prompts for username password when saving excel file opened in
Posted by dave at 4/20/2006 9:11:01 PM
Hi all, I'm having a problem with IIS server. I'm got a collection of excel spreadsheets and word documents available on a website. The files are for viewing only (i.e., read only). When I click on a link to download a word file it prompts me whether I want to save it or open it. If I save...more >>

IIS auth. problem with 2003 SP1
Posted by Jan Nielsen at 4/20/2006 1:18:52 PM
On a 2003 stand alone server I'm running Citrix webinterface on top of the IIS. This web interface implements it's own authentication for regular users, and as such IIS sees user sessions as anonymous. But a subdirectory of the IIS allows for administration of the web interface, and because...more >>

Active Directory check with login details on DB
Posted by Jono Jones at 4/20/2006 9:09:03 AM
Hi there, We have 500 users on our network. I'm writing a web system (asp.net) where you can create a user and give them access to various sections of the site. To create a user you select and existing Active Directory user and just attach their permissions (to see different web pages/opti...more >>

Integrated windows authentication problems
Posted by warhen at 4/19/2006 8:23:01 PM
Hi. I was wondering if anyone has any insight to the following problem. I use a DNS connection service to run public websites from my home computer. Recently I created a website that uses Integrated Windows Authentication for access. I created the virtual directory in IIS 5.1 and gave all the r...more >>

Access denied logging to event log on Windows Server 2003
Posted by Matt Adamson at 4/19/2006 1:22:17 PM
Were using the microsoft exception management application block to log .NET exceptions from an ASP application to the event log. However on Windows Server 2003 were getting an access denied error which is outlined below. As per other recommendations I've done the following 1) Made sure t...more >>

default scripts and manuals
Posted by Kevin1aB at 4/19/2006 11:13:02 AM
Hello, I have a LAN 2003 server running IIS for WSUS and DeskNow WebMessenger jabber server. No public exposure for the IIS. On a recent security audit by outside consultant, they recommended the following: .... the default scripts and manual pages are installed and should be removed fro...more >>

Certificates on .local domain
Posted by Juha Kalliola at 4/18/2006 9:05:03 AM
Hi, we are using SBS2003 with outlook web access and active sync. I have been trying to make working certificate with more or less success. How should it be made. Our sbs domain is with suffix .local. We have a public IP address for our server. I can connect to OWA with public IP address....more >>

kb917072 on Http.sys cookie problem
Posted by Dinis Cruz at 4/17/2006 3:02:44 PM
quick question on the recent KB article "An ASP.NET page is stored in the HTTP.sys kernel cache in IIS 6.0 when the ASP.NET page generates an HTTP header that contains a Set-Cookie response" (http://support.microsoft.com/kb/917072) Does this affect Forms Authentication Cookies? Dinis Cruz ...more >>

Problem Configure my Web Site to Use SSL
Posted by thecoolone at 4/17/2006 10:47:42 AM
I want my site to use SSL, so I followed the following instructions posted on the http://support.microsoft.com/kb/324069/ 1. Log on to the Web server computer as an administrator. 2. Click Start, point to Settings, and then click Control Panel. 3. Double-click Administrative Tools, and then do...more >>

New Virus or Something
Posted by Fred Yarbrough at 4/17/2006 9:08:48 AM
We have had 3 separate Windows 2000 servers running IIS come down with something. This started about 2 weeks ago and it has the following symptoms. The server is very slow to login to. Once up, if you go to the Event Viewer you can see entries but cannot go into an entry to view the details ...more >>

HTTP Link to .xls file returns 404 - IIS 6
Posted by Robert at 4/17/2006 8:32:02 AM
I have IIS 6.0 on Windows 2003 Standard Edition. I have an html page that links to an Excel file on a virtual directory, but when I click on the link, it returns a 404 error. I know there were some new security measures in IIS 6 that caused this, but have not been able to find out how to c...more >>

Cross Site authentication ?
Posted by E-Double at 4/17/2006 5:44:01 AM
What is the best way to set-up cross site authentication ? Ideally we would like users who have authenticated into a secure section of one (local) site to be able to click on a link and somehow pass the authentication credentials to another (remote, not on same domain) site without prompting t...more >>

IUSR Account Question
Posted by Michael Kujawa at 4/14/2006 6:24:36 PM
Can I have more than one IUSR_ account per site If the main site has the default account can I specify a different one for a folder in the site and still maintain the default for the rest of the site? ...more >>

log in problem to a link
Posted by h gregorian at 4/14/2006 12:11:02 PM
Our apps developers created a website with a link for comments. When users click on the link to enter comments it asks them to enter username, password and domain name. I checked the settings for this page and the windows autentication is selected (I should mention that this website is inter...more >>

Radius with IAS
Posted by randy.ling NO[at]SPAM arktech.com.tw at 4/13/2006 7:46:35 PM
Dear Sir, Can anyone help me on this topic. 1. How secure is Internet Authentication Service (IAS) that support Remote Authentication Dial-In User Service(RADIUS)? 2. Advantage & disadvantage of IAS&RADIUS compare with DMZ? I really appreaciate your help and time Thank you so much ...more >>

Err.Number 5232, Err.Description = Word did not save the document.
Posted by Gemma M at 4/13/2006 1:05:24 PM
Hi all, I have a Web site, on the server side, a Word compatible document is created. On the client side, an instance of Word opens this document, applies some headers and footers, and attempts a Save-As. However, I get the above error on the following call : Call doc.SaveAs(docName,...more >>

Certificate By Multiple names
Posted by mackdaddy315 at 4/13/2006 9:31:41 AM
I have a certifcate set on my one of my servers set as issued to something like myserver.local which works fine. But when I goto the site by another name it is known by (ie othername.local ) I get the security warning that the cert was registered under the other name. Is there a way to have the ...more >>

ftp users
Posted by Bad Beagle at 4/13/2006 9:13:01 AM
I have a windows 2003 stand alone iis server that has a ftp server running. I have 2 virtual directories that are on other servers. I am trying to setup an ftp user so that they can access these virtual directories. What I have already created a user on both servers so it does passthrough ...more >>

FTP Admin Attack
Posted by kpg at 4/13/2006 7:05:00 AM
Hi, I'm hosting an Anonymous FTP server (read only) on IIS 5.0 I often get attacks lasting about 20 minutes of a user attempting to login as Administrator. I have a strong Administrator password so it always fails, but at first, the event log would fill up with Security Autit Failures, so...more >>

IIS 6.0 SSL problem
Posted by Joshua Bright at 4/13/2006 6:08:02 AM
Environment: Windows 2003 SP1 Exchange 2003 SP2 Problem: I'm trying to install a SSL certificate for OWA (default site). I've used SelfSSL out of the IIS Resource Kit. I installed the certificate through the CLI, and went to edit the options under the Directory Security Tab in the ...more >>

ftp brute force.
Posted by Henok Girma at 4/12/2006 12:41:06 PM
Is there a way to stop a brute force attack on IIS 5.0, my log file shows a lot of attempts to login as Admin on my FTP site.. ...more >>

How to provide IIS to Developers
Posted by SwatSoftwareDev at 4/12/2006 12:00:00 AM
Hi all, I am managing local network of about 10 systems. All the system are used by ..Net Developers. They all require IIS for developing & testing web applications. What I hav to do is to give them administrator permissions. Because below that don't work. And when developers debug their appli...more >>

PORT 80 ALWAYS IS CLOSED.
Posted by marmenboy at 4/11/2006 1:09:01 PM
Hello everyone, How are you? Strangely I have the problem with closed port 80,,. I read many problems about opened port 80 but not like mine port 80 always i9s closed. My web server with Win 2003 enterprise worked fine for more than 2 years and suddenly last 10 days my web pages do not sh...more >>

ADODB.Stream error '800a0bbc'
Posted by Matt at 4/11/2006 9:46:02 AM
ADODB.Stream error '800a0bbc' Write to file failed. I know this usually means I don't have the correct user access setup on the directory I am trying to write to, but I have added "everyone" w/ full permission and it still doesn't work. Im wondering if there is something wrong w/ IIS a...more >>

Question: Security concerns enabling iisadmpwd for PWD change?
Posted by Bluehades at 4/11/2006 8:47:02 AM
Hello's We are in the process of evaluating whether to enable password change via IIS on our Intranet site which is accessible to the outside world after presenting valid Domain credentials. What security concerns should i be aware of by turning on the Enable password change property in the ...more >>

SSL redirects to other SSL
Posted by Ben at 4/11/2006 2:51:02 AM
Hi, I have a server having the HTTPS or SSL but I like to redirect it to other SSL/HTTPS in other serverS. is there a way to do it in IIS in windows 2000 server? regards, IIS help...more >>

Self signed standalone CA gives: "Windows does not have enough information to verify this certificate"
Posted by Lars Bonnesen at 4/10/2006 5:10:28 PM
I have set up a website with SSL on machine "A" and requested a certificate - Installed Stand alone CA on machine "B" and invoked the certifikate on this and imorted that to machina "A". It works, but clients cannot accept the certificate. They get a "Windows does not have enough informatio...more >>

IIS using old SSL Certificate
Posted by James at 4/10/2006 1:36:02 PM
We have requested and installed a new public certificate for this server however when a page is requested the old certificate is offered. This gives a warning pop-up that the certificate has expired. According to the IIS Administration Snap-in the correct certificate is installed. Why this ...more >>

IUSR problem
Posted by Linda at 4/10/2006 12:41:48 PM
We are using a Win 2003 server, running IIS 6.0. We have company blogs on this server, using Moveable Type. We are trying to restrict access to some of our Blogs by password-protecting them at the server level. However, we have found if we take the IUSR_Webservices user off the list, the Blogs d...more >>

disabling ssl v2.0
Posted by mike at 4/10/2006 12:30:01 PM
I have implemented MS Article ID 187498 to do this. However, when we run open ssl against our win2003 IIS server to check that the change is made it detects 2.0 as still enabled. Has any one had this issue? IS there another process specifically for IIS 6? I'd appreciate any info. Thnx ...more >>

One-way trust, Kerberos & IIS
Posted by Jim at 4/10/2006 1:49:02 AM
Hi, I have the following configuration Two Active Directory Domains in two separate forests. Domain A Windows 2000 Domain B Windows 2003 I have a one-way trust between them such that B trusts A I have a web application running on a Windows Server 2003 installation using IIS in Do...more >>

server security testing apps
Posted by tomrue at 4/9/2006 10:07:49 AM
Can anyone recommend any programs (freeware preferred, but not necessarily) for testing one's own server for security holes - particularly with respect to permissions, but also more generally? Thanks. ...more >>

Any third-party tool to deny IP on IIS 5?
Posted by Alexey Smirnov at 4/7/2006 4:28:20 PM
Is there any good tool to block IPs on IIS 5 on multiple sites in the same time? I know that I can use WWW Services Master Properties to deny IP on all sites, I don't like it very much because I cannot paste IP into list, without typing it manually. Thanks! ...more >>

XMLHTTP no longer works after updates
Posted by Lewis at 4/7/2006 10:49:02 AM
We recently installed some updates on our Windows 2000 server machine. It is running IIS 5.0. Ever since we did, one of our web pages no longer works. Here is a snippet of the code that no longer works: Function GetHTML(strURL) Dim objXMLHTTP, strReturn Set objXMLHTTP = Server.Create...more >>


DevelopmentNow Blog