Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > june 2006

Filter by week: 1 2 3 4 5

Change Password Site in IIS 6.0
Posted by Fred Yarbrough at 6/30/2006 5:22:55 PM
We are running a Change Password site using Windows 2000 with IIS 5.0 using the standard IISADMPwd files. I am trying to build up a new Windows 2003 IIS 6.0 version and it is not working. I have done lots of reading about the switch to .asp based code instead of .htr code. When I run the s...more >>


IE does not offer to open item downloaded via https
Posted by Richard Glanville at 6/30/2006 10:07:01 AM
Hi, I'm trying to investigate a problem wher IE does not offer to open a item downloaded via https. So far can only reproduce on Windows 2003 Server _Enterprise Edition_ with SP1 installed. Could not repro with Standard Edition. Can be reproduced like this: On some other server: Cre...more >>

IIS logs show domain laptop logging into WEBDAV
Posted by FD at 6/30/2006 8:18:04 AM
Hi, I have a curious problem that I hope someone can shed some light on. The log below shows a domain laptop logging in to our webserver's webdav. This incident occurs after business hours. The bad news is it is my laptop's IP address. (I leave my laptop on to run the virus scanner, et...more >>

Can i make personal ssl cert from verisign's one?
Posted by heingray NO[at]SPAM gmail.com at 6/30/2006 12:36:07 AM
I tryed it until yesterday. I think i'm almost succeed. it's so easy. set openssl SSLCACertificateFile to verisign's one. cert tree appear to follow. VeriSign Class 3 Public Primary CA | ---> www.verisign.com/CPS incorp.by Ref. LIABILITY LTD. (c)97 VeriSign | ----->www.yourdoma...more >>

IIS on Vista & IISLockdown/UrlScan
Posted by Stephen at 6/29/2006 7:41:02 PM
Does anyone have any suggestions for what security steps need to be taken to secure a basic web server in Vista running ASP.NET 2.0 pages with some VB.NET?IISLockdown doesn't list Vista in supported products so am I right to assume it isn't needed in Vista? Should I take it URLScan functions a...more >>

SSLCertHash through ADSI in C#
Posted by Raghu at 6/29/2006 1:33:17 PM
I am trying to set the SSLCertHash property to the byte array that contains the SSL certificate's thumbnail with following code: string path = "IIS://localhost/W3SVC/" + webSiteNumber; DirectoryEntry site = new DirectoryEntry(path); X509Certif...more >>

monitor access to docs on IIS
Posted by WES at 6/29/2006 7:41:20 AM
I have an automated job on an IIS 4&5 server that generates .pdf reports to users directories. The users each have seperate unique logins to their respective directories. The users logins ARE NOT Windows domain accounts. The user accounts are assigned through a proprietary application that also...more >>

Filtering Query String
Posted by West, I at 6/29/2006 12:00:00 AM
Hi, I have a client site who runs IIS5 as his web server with Filemaker 6 as there backend database. There is a major security flaw with the Filemaker web publishing engine and with a simple url string (e.g. fmpro?-format=-dso_xml&-dbnames) you can then view all the published databases, ...more >>



login problem with iis and webdav.
Posted by Allan Bentsen at 6/28/2006 9:16:30 PM
Hi there My setup is as follows. A Windows 2003 Server, IIS 6, WebDav, and a website (aspx/C#) A Windows XP Pro sp2 ie6 sp2. Problem: From a webpage it is possible to choose between opening a folder in a virtual directory with file://... or http:// (WebDav). When a user opens the folde...more >>

Is there a way to avoid/security alert box from redirecting to HTTP to HTTPS?
Posted by Jayanthv at 6/28/2006 2:45:25 PM
I saw some questions and answers which says we cannot supress the security alert box when redirecting from HTTP to HTTPS? But i saw many sites are easily redirecting from HTTP to HTTPS without security alert box.. How can i code such that i should not get alert box from HTTP to HTTPS? p...more >>

IIS6 HTTPS POST not being returned to .ASP file...
Posted by Sean at 6/28/2006 8:39:02 AM
Using IIS6 on 2003 SP1. What I am doing is submitting a credit card approval request to an HTTPS (ssl) site. The response is being redirected to an .ASP file - which is set up to accept the fields being returned. Problem is I never get anything returned to the file. I have illiminated the ...more >>

Can Somone Tell Me If We Have a Hacker?
Posted by razor at 6/27/2006 9:26:02 AM
Hello-- I am pasting an event log from our IIS/web server that repeats about 50 times every day during non-business hours. Our SQL administrator seems to believe that somone is trying to hack into our system via FTP. Can somone tell me if the below is a hacker, and what we can do about it?...more >>

SSL issue OWA 2003
Posted by The_Bar at 6/27/2006 8:41:38 AM
Dear Reader, I have installed an Windows exchange server 2003 with my own CA. I have made my own webserver certificate that will be used by OWA. Now I have one issue, when I connect to my e-mail using OWA I see at the bottem of my screen the secured ssl icon, but when I was logged on the ic...more >>

A little help (kerberos, netbios, and SPN... oh my!)
Posted by Craig Carrigan at 6/27/2006 12:00:00 AM
I have a custom intranet that I have setup for our company. The access is secured using IWA and when the site is access by server name (QSERVER\internal) the domain user's credentials are passed automatically and everything is fine. This is good because we don't want internal users (people p...more >>

The IIS service does not seem to be serving up .asmx or .asp pages
Posted by idaliac at 6/26/2006 6:04:01 PM
Hope someone help me , The IE error that is presented is "Cannot find server or DNS Error" and t# Fields: date time s-sitename s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) sc-status sc-substatus sc-win32-status 2006-06-26 15:23:19 W3SVC2 3.131.90.64 GET /fpad...more >>

IIS Access
Posted by phill at 6/26/2006 7:49:02 AM
Hello, We have had a request off developers to have access to some servers. I can achieve everything I need by assigning a group to log on locally and Allow RDP. This just allows them to look. One of the requests is to have read ability for IIS but you need admin rights to run this. ...more >>

IIS5: Renew certificate
Posted by Andrew Hodgson at 6/25/2006 11:24:46 AM
Hi, I wish to renew a certificate with IIS 5, but the provider of the new certificate should idealy be another issuer. If I follow the renew wizard to generate the CSR, will this work by sending the CSR to the new supplier, then installing the certificate? Will it effect the old certificate...more >>

security error in IIS logs (401.2 error)
Posted by Alexander Ferrugia at 6/23/2006 5:23:01 PM
Hi: I'm trying to deploy my VisualStudio2003 ASP.NET application on Windows Server 2003 w/ SP-1. When I navigate to my site (locally or from another network computer) in Internet Explorer I'm being prompting for a network username/password. I believe have configured the server properly in...more >>

file security/authentication
Posted by Carl Hilton at 6/23/2006 2:10:10 PM
OK, I thought I had tackled this before a while a ago but forgot what I did... I am running IIS6 on a W2K3 server. for most of my site I have Anonymous access authorized. I have one file that I want to use the local system ACLs to authenticate with... I have turned off Anonymous access, I h...more >>

New HTTPS web site and certificate installation
Posted by instrument_programmer at 6/23/2006 11:34:02 AM
While I am a very experienced developer I am new to the whole IIS secure server stuff. We had created a locally generated "test" cerrificate and installed it and it works with that. But we wanted to expose this outside our firewall with a real certificate. We have an ISA server acting as ou...more >>

Keeping a particular intruder out
Posted by Peter at 6/23/2006 9:35:51 AM
If this is OT, then I apologise. I'm running 2003 Standard, basically to host my wife's hobby sites. I monitor the logs for intrusion attempts, and persistent offenders get barred using a simple IPSEC implementation. However, I cannot stop a plague of visits from msnbot/0.9 supposedly o...more >>

Security Tab Missing On Specific File Extensions - 2003
Posted by Chase D at 6/22/2006 8:26:01 PM
Okay so I am on a windows 2003 server. I first found that these certain types of files (.wpd) Corel files could not be downloaded from the web. I first thought it was a security issue so I right clicked the files and was going to look at the permissions. The security tab is missing. In fact on...more >>

Stop HTTP Access
Posted by Thom Little at 6/22/2006 6:32:45 AM
I have an ASP.NET 1.1 application on a Windows 2000 Server that can be accessed as ... http://name.tld or https://name.tld . How can I force it to disallow the http access and only permit the https access? -- -- Thom Little -- www.tlanet.net -- Thom Little Associates, Ltd. -- ...more >>

II6.0 ISAPI & MIME types
Posted by Ibrahim. at 6/22/2006 5:49:01 AM
Hello, following are my questions with regard to ASP.NET 2.0, II6.0 & Win2003 server running a Internet Application.; 1. What is the difference between MIME types & ISAPI filter. 2. How can I restrict a file (*.pdf) from being accessed directly from the URL through ISAPI filter. 3. H...more >>

MS Incident Response Plan
Posted by softtrain at 6/20/2006 3:21:02 PM
According to a white paper entitled MS Incident Response Plan, MS states that you should never load IIS on a domain controller. Does anyone have any experience with a fully updated windows 2003 server and a fully updated IIS install having security problems? Thanks, -- P Cully...more >>

Securing static files
Posted by Jon Haakon Ariansen at 6/20/2006 12:12:53 PM
Hi, In short my problem is securing static pages, so that unauthorized (anonymous) people doesn't get access to these files. You'll find a detailed description below. I have a websolution that is made in Dotnet 2.0. The solution send the user to a correct module based on the users credentia...more >>

What encryption method and strength is the password in the metabas
Posted by Harold Miles at 6/20/2006 8:20:01 AM
Does anyone know the method and strength IIS encrypts the anonymousUserName password in the metabase.xml? Thanks!...more >>

How can make HTTPS secure connection to only IIS virtual directory & Few files under that virtual directory?
Posted by jayanth.vishnuvardhan NO[at]SPAM gmail.com at 6/20/2006 7:31:19 AM
Hi, How are you all? I need information regarding SSL using IIS5.0 Server. I got the CA certificate and i want to setup the SSL connection to my Virtual Directory. Please note that if i assign this certificate to the Web Site then it's enabling the Virtual Directory's "Server Certificate" ...more >>

Mirror ftp sites and user accounts in IIS
Posted by Matt_UK at 6/20/2006 4:58:01 AM
Hi We have 2 ftp servers in seperate DMZs in different parts of the country both running W2003 Server and IIS running with users isolated using local accounts and individual ftp sites - has to be this way due to the nature of our business and also the files get copied to remote sites aroun...more >>

IIS WebDAV Long Filename Support?
Posted by bradwiseathome NO[at]SPAM hotmail.com at 6/19/2006 10:40:52 AM
I am trying to use the Novell NetDrive freeware to connect to an IIS 6.0 WebDAV directory. I tried to copy a file to the server, and got an "error" saying that the server did not support long file names. Is there a security setting on the Windows 2003 server that could make this happen? Thank...more >>

Reports of IIS 6.0 Defacements
Posted by me at 6/19/2006 8:56:03 AM
Hi, I was wondering if anyone at Microsoft is able to confirm the defacement of Microsoft France as well as other websites running IIS 6.0 as described at http://www.zone-h.org/content/view/4767/31/ and http://isc.sans.org/diary.php?storyid=1429 If the defacement was real, has it been de...more >>

Windows Server Hardeing
Posted by Eng.Rana NO[at]SPAM gmail.com at 6/19/2006 1:33:51 AM
Hi all, I was wondering why do we need to harden Windows server 2003 by applying rules like: 1.Remove any unneeded Services 2.Close unneeded ports 3.Rename Administrator account 4.Prevent users from installing printer drivers 5.Restrict CD-ROM and floppy access to locally logged-on user o...more >>

IIS and client certificate
Posted by spiazzi67 NO[at]SPAM gmail.com at 6/18/2006 1:04:07 AM
Hi, I have SBS2003. I would expose exchange web in internert and intranet. For intranet I would secure with IP filter. For internet I would secure witch client certificate. Now can I combine this methods? That is a person in my intranet that haven't the certificate can access , because the I...more >>

SSL using Microsofts CA
Posted by Jeniffer K at 6/18/2006 12:00:00 AM
I would like to configure SSL for OWA as well as for Outlook clients using RPC-over-HTTP, so i installed Certificate Services (in Add/Remove windows components), then in IIS I went to the default web site, under server certificate i selected 'Assign an existing certificate' and used the new ...more >>

workgroup vs domain recommendation
Posted by BLMuzzy at 6/15/2006 6:20:29 PM
Does anyone know the pros & cons of having public servers in a workgroup vs in a domain? My situation is I have a couple Win2003 IIS servers, a SQL server, and a document mgmt server (SQL + doc storage) that's also an Active Directory DC. The latter is used for LDAP validation of user logons. ...more >>

System Stored Procedures
Posted by Eng.Rana NO[at]SPAM gmail.com at 6/15/2006 12:10:38 AM
Hello All, i was wondering if there exists some way to disable all system stored procedures, as they are vulnerable to attacks specially if they r not needed within any of my applications. something like, xp_cmdshell may cause attacks. i need ur help plz and will appreciate ur response and su...more >>

IIS Snap-In rights question
Posted by dusty at 6/14/2006 1:44:02 PM
Is there a way for a non admin to run the IIS 6 admin snap in tool? We would like for our web admin to continue administering IIS, but because of AD policies, he is pulled out of the local admin group and can't connect to IIS. TIA...more >>

SSL Certificate Help
Posted by Gerry at 6/14/2006 7:51:02 AM
We have applied a "test" certificate on a production server, and now the certificate has expired. We have install the MS CA on a domain controller and want to request a new certificate from that CA. However, the certificate is still "in use" on the IIS server, so I cannot request a new certi...more >>

Authentication
Posted by Eng.Rana NO[at]SPAM gmail.com at 6/14/2006 7:33:25 AM
Hello All, i was wondering what is the main difference between the windows authentication and mixed mode authentication?? according to security recommendations, we should enable windows authentication, rather than mixed one, i don get the point why do we refuse the mixed mode authentication...more >>

SSL and IIS 5.0
Posted by Ed Sitz at 6/13/2006 12:27:32 PM
Interesting issue with a site that uses SSL and IIS 5.0. All of a sudden today, we couldn't browse to the site using SSL. All attempts simply timeout. Nothing in the logs. Take SSL off of the site and it works fine. Certificate is good through September of 2006. I even removed the certi...more >>

FTP Server
Posted by Jake at 6/13/2006 9:12:02 AM
I am looking at setting up an external facing FTP server. Are there any guides on how to secure on FTP using IIS 6? Or are there better solutions?...more >>

SSL using locally generated certificate
Posted by Lonnie Massey at 6/12/2006 5:05:01 PM
I'm getting ready to secure my Outlook Web Access 2003 with SSL. The web server is running Windows 2000 (IIS 5.0), and the Certificate Server is on the Exchange server (Win2003). I've set up a test folder, created a certificate using Certificate Authority, and installed it on my web server. ...more >>

Anyone know about streaming .wmv ?
Posted by JethroUK© at 6/11/2006 10:25:45 PM
I've asked before without success but: How do you protect streaming video (.wmv) from being stored (saved as a file) I have to make hundreds of teaching aids via streaming video (from my pc) and i would obviously like to prevent end user from stealing them all I've been told previously th...more >>

test a web service?
Posted by JethroUK© at 6/11/2006 9:35:59 PM
is it possible to test your own web service from the host machine? first time i set up a web service i couldn't access it via web browser and i tried lots of things, thinking it wasn't working - but when i tried it from remote pc's it was actually working fine it does make it difficult to te...more >>

IIS 6.0 Integrated Security
Posted by Bradley Morris at 6/8/2006 2:13:02 PM
Can someone please explain to how to configure IIS 6.0 for the following scenario and requirements? And, if it cannot be done, can you tell me why? This was easy to do in IIS 4.0 and 5.0. All you had to do was set the web site and connection string to use Integrated Security. Scenario 1....more >>

problem downloading exe file on server 2003 iis with sp1
Posted by techy at 6/8/2006 1:03:44 PM
i am having problems setting up a page to allow the download or run of an EXE to do an installation routine with IIS 6.0 on windows 2003 server msi runs fine Internet Explorer cannot download esinst.exe from myserver Internet Explorer was not able to open this Internet site. The requ...more >>

SSL on an IIS cluster
Posted by Jacob Hahn at 6/8/2006 5:29:02 AM
I have a active-passive cluster on Windows 2003 servers that is running IIS, I am having problems installing the SSL certificate on both nodes. The SSL certificate was created for the cluster name resource, “www2.mydomain.edu” and that cert was installed on node A without a problem. Using ...more >>

IIS 6.0 .bat File no access
Posted by Ben at 6/7/2006 12:15:03 PM
I installed a W2003 Server with ASP. The ASP File has to start a .bat File. But it don't work. Has someone a guideline or can help me? On IIS 5.0 it works without a problem...more >>

Obtaining a Machine Certificate via Web Enrollment
Posted by bkmonroe at 6/7/2006 12:00:47 PM
I have an Windows 2003 Enterprise CA setup to auto-enroll domain computers with a machine certificate for the purpose of L2TP VPN. This works great. The problem is getting a machine certificate for non-domain computers. When going to enroll for a certificate via web http://servername/certsr...more >>

child Folder named system disappears then cant delete its parent
Posted by Mark S at 6/6/2006 3:30:51 PM
When I create a folder on our windows 2003 server IIS 6 web server, and create another folder inside that one called "System", it changes it back to "New Folder", then disappears. When I try and delete the parent folder it wont allow me to delete it and says the folder is not empty. I have view ...more >>


DevelopmentNow Blog