Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
May 2008
June 2008
all groups > iis security > june 2006 > threads for june 15 - 21, 2006

Filter by week: 1 2 3 4 5

MS Incident Response Plan
Posted by softtrain at 6/20/2006 3:21:02 PM
According to a white paper entitled MS Incident Response Plan, MS states that you should never load IIS on a domain controller. Does anyone have any experience with a fully updated windows 2003 server and a fully updated IIS install having security problems? Thanks, -- P Cully...more >>


Securing static files
Posted by Jon Haakon Ariansen at 6/20/2006 12:12:53 PM
Hi, In short my problem is securing static pages, so that unauthorized (anonymous) people doesn't get access to these files. You'll find a detailed description below. I have a websolution that is made in Dotnet 2.0. The solution send the user to a correct module based on the users credentia...more >>

What encryption method and strength is the password in the metabas
Posted by Harold Miles at 6/20/2006 8:20:01 AM
Does anyone know the method and strength IIS encrypts the anonymousUserName password in the metabase.xml? Thanks!...more >>

How can make HTTPS secure connection to only IIS virtual directory & Few files under that virtual directory?
Posted by jayanth.vishnuvardhan NO[at]SPAM gmail.com at 6/20/2006 7:31:19 AM
Hi, How are you all? I need information regarding SSL using IIS5.0 Server. I got the CA certificate and i want to setup the SSL connection to my Virtual Directory. Please note that if i assign this certificate to the Web Site then it's enabling the Virtual Directory's "Server Certificate" ...more >>

Mirror ftp sites and user accounts in IIS
Posted by Matt_UK at 6/20/2006 4:58:01 AM
Hi We have 2 ftp servers in seperate DMZs in different parts of the country both running W2003 Server and IIS running with users isolated using local accounts and individual ftp sites - has to be this way due to the nature of our business and also the files get copied to remote sites aroun...more >>

IIS WebDAV Long Filename Support?
Posted by bradwiseathome NO[at]SPAM hotmail.com at 6/19/2006 10:40:52 AM
I am trying to use the Novell NetDrive freeware to connect to an IIS 6.0 WebDAV directory. I tried to copy a file to the server, and got an "error" saying that the server did not support long file names. Is there a security setting on the Windows 2003 server that could make this happen? Thank...more >>

Reports of IIS 6.0 Defacements
Posted by me at 6/19/2006 8:56:03 AM
Hi, I was wondering if anyone at Microsoft is able to confirm the defacement of Microsoft France as well as other websites running IIS 6.0 as described at http://www.zone-h.org/content/view/4767/31/ and http://isc.sans.org/diary.php?storyid=1429 If the defacement was real, has it been de...more >>

Windows Server Hardeing
Posted by Eng.Rana NO[at]SPAM gmail.com at 6/19/2006 1:33:51 AM
Hi all, I was wondering why do we need to harden Windows server 2003 by applying rules like: 1.Remove any unneeded Services 2.Close unneeded ports 3.Rename Administrator account 4.Prevent users from installing printer drivers 5.Restrict CD-ROM and floppy access to locally logged-on user o...more >>



IIS and client certificate
Posted by spiazzi67 NO[at]SPAM gmail.com at 6/18/2006 1:04:07 AM
Hi, I have SBS2003. I would expose exchange web in internert and intranet. For intranet I would secure with IP filter. For internet I would secure witch client certificate. Now can I combine this methods? That is a person in my intranet that haven't the certificate can access , because the I...more >>

SSL using Microsofts CA
Posted by Jeniffer K at 6/18/2006 12:00:00 AM
I would like to configure SSL for OWA as well as for Outlook clients using RPC-over-HTTP, so i installed Certificate Services (in Add/Remove windows components), then in IIS I went to the default web site, under server certificate i selected 'Assign an existing certificate' and used the new ...more >>

workgroup vs domain recommendation
Posted by BLMuzzy at 6/15/2006 6:20:29 PM
Does anyone know the pros & cons of having public servers in a workgroup vs in a domain? My situation is I have a couple Win2003 IIS servers, a SQL server, and a document mgmt server (SQL + doc storage) that's also an Active Directory DC. The latter is used for LDAP validation of user logons. ...more >>

System Stored Procedures
Posted by Eng.Rana NO[at]SPAM gmail.com at 6/15/2006 12:10:38 AM
Hello All, i was wondering if there exists some way to disable all system stored procedures, as they are vulnerable to attacks specially if they r not needed within any of my applications. something like, xp_cmdshell may cause attacks. i need ur help plz and will appreciate ur response and su...more >>


DevelopmentNow Blog