Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008


all groups > iis security > september 2006

Filter by week: 1 2 3 4 5

IIS security with user and passwords stored in database
Posted by Scott Jones at 9/30/2006 6:42:01 PM
I am new to IIS. I have a microsoft sql server with user id and passwords stored in it. I need to get IIS to use the sql database for authentication. 1. Is this possible? 2. If so, can someone point me to documentation or an example. Thanks...more >>

Problem in mail enable web mail service
Posted by Mohamed Taher at 9/30/2006 12:00:00 AM
Dears, after I setup plesk hosting control panel its setup by default the mail enable standard version which free version from mail enable ,,, any how I decided to upgrade to mail professional edition because I want to use its web mail service on my existing server configuration any h...more >>

Integrated Windows Authentication
Posted by Justin Rich at 9/29/2006 12:23:44 PM
if i have this on and i go to my server (http://server) it will continuously reload the page. if i turn it off and use basic it prompts for creds and then works ok. It was working ok a few days ago. I dont think anything has been changed, but there are unfortunatelly a lot of people working on...more >>

IIS6.0 Integrated authentication w/multiple app pools
Posted by Zarborg at 9/29/2006 8:16:02 AM
So I've been reading a lot of posts about running a couple web sites on an IIS6.0 box where each web site has a separate application pool associated with it. One of the web sites is using Integrated Authentication only on it. When a user points their IE browser at the site, they get prompted...more >>

pb with application pools
Posted by Eric bouxirot at 9/28/2006 4:27:47 PM
hi, i have created a simple webservice (Helloworld example from VS2005) i have put this webservice on my server and i setup a virtual directory on IIS 6 (i have SBS 2003) i have set a new application pool for this vistual server, with standard identity (Network service) i have disabled ano...more >>

Event ID 560
Posted by Kevin Wheeler at 9/28/2006 2:14:02 PM
Can anyone tell me why I'm getting the following error in my security log. all of a sudden, my symantec reporting server isn't recieving updates. Event Type: Failure Audit Event Source: Security Event Category: Object Access Event ID: 560 Date: 9/28/2006 Time: 5:07:23 PM User: Server...more >>

IIS Security Question
Posted by abcd at 9/28/2006 12:52:22 PM
I have a web application in IIS 5.0 (W2K). I have annonymous access (IUSR) on for my web application. But my default web site have not enabled annonymouus access. The default web site only have Integrated Windows Security on. Whenever I access my web application I get windows user / name passwo...more >>

SSL entire web site
Posted by Doug at 9/27/2006 6:56:36 PM
We will be launching a new WWW site in the next few weeks, and for internal reasons (reasons I can't go into here), the new web site will need to be entirely https. I'm trying to determine what issues, if any, there will be when doing this. The new site is entirely different, so we expect i...more >>



Export Security Cert
Posted by JT at 9/27/2006 5:29:02 PM
Hi all, I have a Windows 2003 web server configured with a couple of production websites and a couple of non production test web sites. My prod sites have purchased security certificates. These have installed w/o problems. I would like to export the same security certs and then import...more >>

Strange CN (Common Name) format with \x00 ...
Posted by Polaris at 9/27/2006 4:22:38 PM
Hi Experts: I have a certificate (below). I just wonder, why the CN part (which is *.test.com) appear in the format of "\x00 ..."? Certificate Subject Name=/C=US/ST=CA/L=SanJose/O=Adobe/OU=Customer Support/CN=\x00*\x00.\x00t\x00e\x00s\x00t.\x00c\x00o\x00m I'd like to know WHY and WHEN ...more >>

ssl AD Domain not External Domain
Posted by DB at 9/27/2006 1:28:01 PM
I have a win2003 server with IIS that is on my active directory domain (company.internal.com) and is accessible from the Internet by the domain name (webserver.external.com). If I install an ssl certificate, will there be a problem that the server is in a different domain (AD Domain) than the ...more >>

Hacker Problem
Posted by Neil at 9/25/2006 11:37:45 AM
Hi, I have a website hosted on MS IIS. It has a news section fed by a database to allow the owners of the site the ability to update the news pages themslves. Last week a message was added by an Iranian hacker (see the end of this post.) What I don't understand is how they were able ...more >>

IIS 6 and Anonymous on Windows Server 2003
Posted by merkury1 NO[at]SPAM yahoo.com at 9/25/2006 7:52:33 AM
I have a brand spanking fresh install of IIS on Windows Server 2003 R2. It has anonymous access enabled on the default website and NOT integrated windows authentication. I only want anonymous access. I have made sure that the Anonymous account (IUSR_computername) has Read, "Read & Execute" and...more >>

FTP maximum password attempts
Posted by nx-2000 NO[at]SPAM winvoice.com at 9/25/2006 7:26:11 AM
I've done quite a bit of searching on this and I haven't found a satisfactory answer besides a few expensive add-on packages. I'm hoping someone has some ideas. Basically, I'm getting brute forced to death on my IIS FTP sites. They haven't found their way in yet, but, this weekend, I had 11 ...more >>

Integrated windows authentication problem
Posted by HDI at 9/24/2006 10:15:02 AM
Corporate intranet running on windows server 2003 web edition, IIS 6.0 When I turn on integrated windows authentication and turn off anonymous access, my allowed users can only access static content. When they try to access asp pages they get the message "You are not authorized to view this p...more >>

Security implications of Virtual Directories vs Root websites?
Posted by Leythos at 9/23/2006 1:28:53 AM
I would like to know if anyone has links related to the implications of running a SSL site as a virtual directory site rather than a root website. Thanks. -- spam999free@rrohio.com remove 999 in order to email me...more >>

Implications of a SSL site as a virtual directory rather than a root website?
Posted by Leythos at 9/22/2006 2:52:18 PM
I would like to know if anyone has links related to the implications of running a SSL site as a virtual directory site rather than a root website. Thanks. -- spam999free@rrohio.com remove 999 in order to email me...more >>

Internet Access on an SBS 2003 Install
Posted by Cranky Pants at 9/20/2006 3:51:02 PM
Since we moved to a new Dell server with SBS 2003, I have had no end of problems setting things up the way we want them. I am trying to set up a Sharepoint Site that we can access via the Internet - sounds pretty simple (it is in Server 2003) I can get as far as setting up the DNS, setting...more >>

SSL on a different IP
Posted by Chris D at 9/20/2006 3:38:02 PM
Hi - can I have a site on one ip and have SSL on a different IP or does the site have to be on the same ip as ssl? If I can, then how? Huge thanks ... Chris...more >>

Allow anonymous access between times
Posted by cc900630 NO[at]SPAM ntu.ac.uk at 9/20/2006 5:20:42 AM
Hi Is there any setting in Windows 2K3 or IIS 6 that can allow my public website only to be accessed between certain times/days. Rather than scedule the service teh stop is there anyway to serve a custom error and deny access to the pages. Thanks. ...more >>

Certificate Service Button
Posted by RAJ at 9/19/2006 12:08:02 PM
Hello, I have and OWA site that is configured with a Windows Certificate. I want to configure the site w/ a certificate from Thawte. However, when I to into the website properties/Directory Security tab the Server Certificate button is greyed out and not available. In an attempt to make th...more >>

Configuring SSL Host Headers in IIS 6 W2K3 SP1
Posted by Ryan at 9/18/2006 11:51:02 AM
Hi, I can't quite figure out why I am having such a hard time with this. I got it to work ONCE on about the 4th attempt, left it alone overnight and checked that it was still working in the morning, but then it stopped working when I attempted to add a third site and I haven't been able to...more >>

Accessing a web application anonymously
Posted by T-POT at 9/18/2006 6:09:51 AM
We have an internal web application that is soon going to be needed to be accessed by our members via the web. Internally it works fine (probably because there are no security restrictions). I am trying to configure a new IIS6 box to provide this web app without compromising security. The...more >>

SPN for SSL over common name
Posted by Daniel at 9/14/2006 8:00:46 PM
Dear all, I've created an alias (CName) in DNS for my web server running on IIS 6.0. Web Server FQDN : myweb.domain.com (not using host header) Alias for Web Server : kirk.domain.com A SSL cert has been created from the alias. Clients will be accessing the backend server, SQL2K, Using...more >>

error message
Posted by hoss at 9/14/2006 6:05:19 PM
i do have web application on my local machine and when i run the application i get in the default page which is that the main page and after that i getting error message saying that INVALID URL ACCESS but every thing seem fine to me and i am sure that the problem with the IIS configration so an...more >>

Security options for IIS6, SQL2005
Posted by DaveA at 9/14/2006 2:45:01 PM
Hi I've built a .NET application server running SQL 2005 and the default version of IIS on Server 2003, that's IIS6, correct? Would be able to tell me if Server SP1's Security Configuration Wizard is also compatible with this setup? ...more >>

Can't save password if Integrated Authentication is used
Posted by smith777 at 9/14/2006 1:12:02 PM
I'm running Windows 2003 sp1 and have Sharepoint running. I have Integrated Authentication turned on. If i go to the web site and enter in domain\username and password and check off 'remember password', i'll initally log into the site fine for the first time. If i close the browser and go t...more >>

Block IP by "Group Of Computers"
Posted by DBLWizard at 9/14/2006 6:27:32 AM
Hello, I am having problems with certain companies that are "scraping" data from websites and I want to block the IP ranges owned by those companies. How do you figure out what the subnet mask to block a range of computers? Lets say that I want to block 10.10.32.0 - 10.10.63.255 and yes I ...more >>

ftp server access
Posted by msw at 9/13/2006 5:50:33 PM
Can anyone tell me what configuration I need to do on IIS 6 Windows 2003 server to be able to access the server as well as to access through a ftp tools as well as dreamweaver MX Thank you ...more >>

Verisign Certificate
Posted by christy at 9/13/2006 4:01:02 PM
We bought and installed "True 128-Bit SSL Certificates" package from Verisign on our IIS server. We currently use it for our webstore. Our contractor is developing another webstore (as addition to the exiting one) for us. They're developing the store at their site. They are asking us to pr...more >>

IIS 6.0 Bug?
Posted by Morten Wennevik at 9/13/2006 12:33:49 PM
Hi, I apologize for the extensive cross-posting but I'm getting desparate. We have a web page calling one or another web service. Both web service communicate with Sharepoint 2003, and both temporarily change impersonation using WindowsImpersonationContext class and then revert back with ...more >>

HTTP Error 401.3 - Unauthorized: Access is denied due to an ACL set on the requested resource
Posted by ashtek NO[at]SPAM gmail.com at 9/13/2006 3:28:00 AM
Hi, I have a web application hosted on a Win2K3 server. This is the Default Web Site on the server (I have right cliked on Default Web Site and pointed to a directory within the server). So users can access the application by typing http://servername. I have checked "Integrated Windows Authen...more >>

IIS Hosting Webservice which accesses a COM server
Posted by Aidan Lawless at 9/12/2006 2:51:01 AM
Hi, I have an XML web service which exports a method that allows consumers of the service to update a backend system using an out of process com server. The only way I can get this to work is to set the Anonymous access user to administrator or another high access user which is obviously no...more >>

SSL and XML
Posted by tolgay at 9/11/2006 3:33:39 PM
Recently our web service provider changed its web site platform HTTP to HTTPS and before we got some data from the internet site with our web service( XML ) affter the changes somehow our code doesn't work. When we call the link via internet browser everthing works well but if we connect the s...more >>

file protection
Posted by beachboy at 9/11/2006 12:00:00 AM
any setting can protect the special folder that not allow user to download from browser/url, but the files/directories can access by aspx/asp script(Content Management System), how i can setup this up? use NTFS permission or IIS can do this?? e.g: userA type http://localhost/website1/download...more >>

Copy website to same server
Posted by Anthony at 9/8/2006 10:12:41 AM
I want to run two versions of a web application on the same server, on two different websites. The only difference is that I want to run one with Windows Integrated authentication, and one with Basic plus SSL. The first website already exists. The server is W2K3. I can export the configuratio...more >>

Q: asp script error
Posted by Eco at 9/8/2006 12:11:42 AM
A web site w/ ASP script was running normal on Web Server w/ win2k Server at the beginning stage few years ago. Then found it was hacked or homepage was changed by hacker occassionally last years. The outsource webpage designer suspected that internal network computers were infected by such...more >>

security between serving files from a fileshare
Posted by Ian Jagger at 9/7/2006 9:36:02 AM
Hi, I have two machines that are on the internet that can share files between them. They are otherwise firewalled.They are not on the same domain, but they can see each other and share files in windows. They are p1 and p2. p1 shares the directory pics with p2. p2 logs in as p1\pics to se...more >>

Windows Integrated Authentication - weird issue
Posted by smith777 at 9/6/2006 8:20:03 AM
I have Windows 2003 in a domain and running a web application on it (Sharepoint). I have IIS's authentication set to Windows Integrated Authentication. I was looking for users to be able to login automatically to the web application using the credentials that they used to login to their com...more >>

Get a new CRL every 1h with IIS6 ?
Posted by Yogz at 9/6/2006 2:36:02 AM
Hi everybody, I'm running a windows 2003 server with IIS6. My server’s certificate has some CRL distribution point defined. By default the CRL is valid for 1week. I would like to know how to get the a new CRL every 1 hour ? I tried with some variable in the metabase but it's a bit confuse...more >>

anonymous access group perms
Posted by Matt at 9/5/2006 4:46:48 PM
hello, We have a win2k3/iis6 member server. I've created a new anonymous user which works fine. I've created a group on the member server, not a domain group, for all accounts that need anonymous access including the new anon user, but when I remove explicit perms for the new anon users a...more >>

HTTPS site only
Posted by jb6000 at 9/5/2006 10:25:01 AM
Hello, I am managing a secure site using IIS running on Windows server 2003. I noticed that my secure site is also accessable via HTTP. How do I disable HTTP and force users to only use HTTPS when logging in? Thanks....more >>

Is it possible to use the Windows 2003 user names instead of pre-Windows 2000 user names in Windows Authentication?
Posted by MaURiCe at 9/5/2006 6:27:58 AM
Hello, I am trying to get username information by using User.Identity.Name.ToString, if i logged in with username to given network place, it is ok! It returns SERVERNAME/username. Otherwise if I logged in with "name.surname@SERVERNAME.com" it again returns SERVERNAME/username although i want it...more >>

IIS 6 authentication problem
Posted by Franz Schenk at 9/4/2006 4:51:59 PM
Have a Windows 2003 SP1 server with Virtual Server 2005 R2 installed. Have the problem, that Windows Authentication doesn't work at all when connecting to the Virtual Server Administration Website: Getting Error 500 - internal Server error. When configuring the site with "Basic Authentication"...more >>

Recommendations for securing IIS 6.0 as a public web server
Posted by Rob Gordon at 9/2/2006 7:14:02 PM
I am planning on posting our public website on IIS running under Windows Server 2003 R2. Can anyone point me at any good sites or white papers for the best practices for securing the site for public access? I am planning on making the server a member of our corporate domain for access to i...more >>

iis6 password protected file issue
Posted by Matt at 9/1/2006 10:55:32 AM
We recently migrated from a Win2k/iis5 web server to another server with Win2k3/iis6. For a virtual directory we have password protected an individual file, disabled Anonymous access in iis for the file, removed the anonymous user from NTFS perms on the file and added a new user in the NTFS ...more >>


DevelopmentNow Blog