Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > october 2007

IIS 6.0, ASP.NET, SQL 2000 on one server?
Posted by gcadmindude at 10/30/2007 7:19:01 AM
Hi gang! I need some help here...ok, I need a LOT of help here! I've just been informed that we will be building a new Win2003 based web server that will host our public web site. To my surprise I have been directed to put all of our SQL 2000 databases on this server. My first response...a...more >>


IIS5 - 'microsoft false logging weakness'
Posted by news.microsoft.com at 10/29/2007 1:04:00 PM
Please help, I've got an IIS machine that is failing PCI compliance due to the 'False Logging Weakness'. the resolution states to use URLScan to translate hex codes into characters, but I have no idea how to do this... Can anyone shed some light? Thanks. ...more >>

IIS 6 and system's object namespace
Posted by Roger Abell [MVP] at 10/26/2007 2:19:54 PM
This is perhaps a bit extreme, but I wonder if anyone might have a hint on this. I have to support multiuser/multiowner webs in multiple sites on IIS 6, which is no problem, except that they also require FPSE/Sharepoint extensions. As we know, those extensions are lame when it comes to ACL...more >>

Upgrading from IIS 5.1 to IIS 6.0
Posted by WJB at 10/26/2007 10:58:01 AM
Hi, I'm developing a web app using VS 2005 (C#) and SQL Server 2005 on Win XP Pro SP2. The app will be deployed under IIS 6.0, so I need to upgrade IIS on my machine from 5.1 to 6.0. My Windows CD has 5.1. 1. Are there any compatibility issues between IIS 6.0 and Win XP Pro, SP2? 2. Wher...more >>

IISReset for non-Admins
Posted by Paul DiGiorgio at 10/24/2007 8:27:00 AM
I have a group of IIS 6.0 servers (Windows 2003 Standard Edition), which are all managed by a support group. The members of the support group are not Admins on these IIS servers. I am managing these servers with a single GPO. The support would like to have rights to run IISRESET. What do I ne...more >>

Basic Authentication fails with Error 401.2 where Integrated succe
Posted by Jude Fisher at 10/24/2007 1:45:01 AM
Hi, I'm a developer rather than a server tech and I've run into some problems configuring a website. An external provider we're using requires that a specific script be in a directory that is protected by Basic Authentication. This isn't something I've had to do before so I've been stum...more >>

ssl cert in IIS 6 works for Firefox, fails for IE 6 & 7
Posted by Ben Conner at 10/23/2007 9:09:00 PM
Hi, I have a public server hosting multiple sites, some of which have secure certs. Recently had clients telling me they get a "Cannot find server or DNS Error" when trying to view a site in secure mode with IE, but have no problem viewing it with Firefox. Until a week or so ago, there wa...more >>

Anonymous User Password Sync
Posted by Usman Jamil at 10/23/2007 4:17:44 PM
Hi In IIS 5 , while creating websites programatically, i set the anonymous pass sync (Allow iis to control password) property to true, due to which I dont have to reset the password for anonymous user even if someone changes the password from user manager under windows. In IIS 6, I repeated...more >>



IIS6 - Directory Traversal in Active Server Pages - FSO
Posted by Patrick at 10/22/2007 3:39:14 PM
Hello I'm just doing some checks on the system, and we found out that directory traversal is possible with classic .asp. It is possible using the filesystemobject. Then i tried to add specific permissions to the application pool of this website, but it still was possible to access other ...more >>

SSL certificates and multiple websites
Posted by tandrist at 10/22/2007 1:23:00 PM
I have one web server housing multiple sites, can I use a single certificate for all the websites or do I need to apply the SSL certficate(s) to each site individually? Using the certificate creation wizard, it looks like it makes them based off a single website? Is there a way to create one...more >>

how to setup IIS to authenticate users via private key?
Posted by Mr. Macker at 10/22/2007 11:47:10 AM
All ~ I'm trying to setup authentication on my IIS 6.0 server to authenticate users only via using a private encrypted key. Does anyone know how to do this? Or is there documenation you can point me to? Thank you! ~M ...more >>

WebDav with OWA
Posted by Tony at 10/19/2007 12:25:02 PM
I am trying to implement WEBDAV in an OWA server. I created a virtual directory with unc to a share in another server. I gave full access to the user who need to access the folder https://server1/webdav/testa. I keeps prompting me to logon each time I do something. when I want to open a ...more >>

Prevent a ISAPI DLL to be accessed externally in IIS 6
Posted by toolsandcomps NO[at]SPAM gmail.com at 10/19/2007 10:56:52 AM
Hello: I have a ISAPI DLL in my server and I want to prevent people to access it externally, only from the server itself. Ex: someone has a website on server X and their HTMLs are accessing a DLL hosted on my server. Can I prevent it? Thanks in advance... Jackson Gomes ...more >>

HTTP Error 401.1 - Unauthorized: Access is denied due to invalid c
Posted by Adam N. at 10/19/2007 8:45:01 AM
I am getting this error, when trying to access any of the sites hosted on our IIS server..... HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials. Internet Information Services (IIS) I created a new site that I can fine, I have attempted to compare the security / ...more >>

"SSL Server Allows Anonymous Authentication Vulnerability"
Posted by criechton at 10/18/2007 7:02:01 AM
I have two windows 2003/IIS 6.0 servers that are load balanced thru an F5 networks device, an ISS security scan of the URL that is shared by the two servers is showing "SSL Server Allows Anonymous Authentication Vulnerability". How do I address and remediate this vulnerability. Thanks in ...more >>

can't install user certificcate from other ad domains
Posted by Fadoul at 10/17/2007 4:43:45 PM
Hi I have a certificate server running on a W2k3 SP2 server. this server is a global catalog. All user certificates are processed correctly when accessed by main root ad domain but when i tried to ask a user certificate from the web interface (certsrv), users from the second domain on my A...more >>

Remote administration
Posted by Arne Garvander at 10/17/2007 6:07:01 AM
I am trying to administer IIS with mmc for a remote computer. I don't have the right security for that. What does my admin need to change on my behalf? -- Arne Garvander Certified Geek Professional Data Dude...more >>

FTP directory security setup.
Posted by tdr at 10/17/2007 5:04:01 AM
I'm trying to stop hackers from trying to accessing my ftp server. I've tried to use the 'directory serurity' tab and "denied all" but the few users I want to access my ftp site. I've select "denied all but" and entered the ip address of one system and the domain of the other ex. "mydomain...more >>

Redirect problems
Posted by me at 10/16/2007 1:56:03 PM
Hi All... I know that this may seem very trivial, but I just can't get this to work! I'm trying to set up a redirect on one of our servers to go from a non-https page to https. The https site is already on the server. I created a second site with a redirect page running on port 80 with the ...more >>

WebDav Permissions for Operators groups
Posted by Roman at 10/15/2007 11:27:20 AM
I have a standalone Windwos 2003 Server SP1 with IIS 6.0 and WebDav enabled (a AD integraded server has the same behaviour). A Folder on the server is mounted as Virtual Directory, which has the following NTFS permissions: User1: Read & Execute, List Folder Contents, Read User2: Full Contro...more >>

Cross site scripting issue in IIS 5.0
Posted by criechton at 10/15/2007 8:34:00 AM
I have a Windows 2003 server SP4 running IIS and a PCI scan shows up with a Cross site scripting vulnerability. The Standard M$ response was to install MS02-018.mspx but this was from 2002 and must have been installed already years ago because since the server is on SP4. Please advise if ther...more >>

write a file to as subfolder of a InetServer location
Posted by Thanh-Nhan Le at 10/14/2007 2:43:04 PM
Hi, I have an ASP application on IIS server: http://localhost/myApp I use ASP and a my own VB activex DLL to create a pdf file and write this file to a subfolder of the Application folder: http://localhost/myApp/pdfs 1- Over IIS I have set the "write permission" for this subfolder. But ea...more >>

HELP-Domain Controller reboot causes session loss
Posted by JJ at 10/13/2007 8:58:00 PM
Please forgive my IIS ignorance when reading this question....I am a Windows Admin and we have developers that have developed an application with asp.net. They have front end web servers that tie to a back-end database (SQL). All servers (including domain controllers) are windows 2003. ...more >>

need certificate that works for external name and internal name
Posted by Jordan at 10/9/2007 6:16:22 PM
Is there a way to get a certificate from MS Cert Server installed on IIS for Win 2003 so that it works for both external and internal names without coming up with a warning on one of them about the name? I have an Exchange 2003 server that I want to use OWA and OMA on, but securely as possi...more >>

CLR calling a web service and AppPool impersonation - weird issue
Posted by Sergei Shelukhin at 10/8/2007 9:17:22 AM
Hi. Crossposted because the issue seems bizzare and I have no idea where the problem lies. We have a CLR that calls ASP.NET Web Service using NetworkCredentials to pass in login, passowrd and domain of a domain user. Application and apppool housing the webservice run under network service; II...more >>

Standard User using IIS 5.0 - XP
Posted by MarcioHunecke at 10/8/2007 9:15:07 AM
We want to restrict our developers to a standard user (no administrator rights) but they need to use the full features of IIS from Windows XP SP2. Does anybody know how to do it? Please let me know. Thanks....more >>

Possible to retrieve password of current application pool
Posted by Dylan Nicholson at 10/4/2007 8:10:57 AM
Running as an administrator, I can retrieve the account password stored by IIS for any application pool (using the WAMUserPass property). But, unsurprisingly, an ASP.NET application running inside an application pool that is does not have administrator privileges can't even enumerate the list o...more >>

from Windows2000 (IIS5) to Windows2003 (IIS6)
Posted by Mike at 10/4/2007 7:21:01 AM
The application is a pair of ISAPI dlls running under IIS which in turn call some COM components, etc... They are set as high isolation in the IIS admin settings. This issue I saw when setting up our stuff on Server2003 is that I would get a windows login prompt while hitting the ISAPI si...more >>

PRØVESENDING !!!!!!!
Posted by thoralf.renslo NO[at]SPAM dabb.no at 10/3/2007 11:59:57 AM
sennder en prøve svar tilbake på N O R S K !!!!!! ...more >>

Web Folders and Integrated Authentication
Posted by neil662 NO[at]SPAM yahoo.com at 10/3/2007 9:52:42 AM
Hi all, I'm having an issue with Web Folders and Integrated Authentication. Basically I've an IIS 6 website setup that contains some web folders. Inside the web folders are a collection of file types including Office documents, text files and images. The website is setup to use Integrated Au...more >>

IIS 5.0 and disabling the indexing service.
Posted by criechton at 10/3/2007 6:46:03 AM
I had a scan done to my server and this came up. "Microsoft Internet Information Server Hit Highlighting Authentication Bypass Vulnerability" The suggested fix is to upgrade to IIS6.0 , I can't because it's Win2000 std svr, it also says to disable the indexing service.. How do I do this? ...more >>

Allow only url forwarding source IP
Posted by kazi at 10/2/2007 6:10:00 PM
I want to use an application which enables 2 factor authentication on IIS websites i.e(http://www.phonefactor.net). Unfortunately I'm already using a portal application which does not run on IIS but am interested to protect via phonefactor. So far I'm able to do a workaround to apply 2 factor ...more >>

WMI Security Problems
Posted by Nuno Magalhaes at 10/2/2007 12:06:23 PM
Hello, I've done a small web application that uses WMI wrapper (System.Management) and everything works fine on Cassini's development web server from VS2005, while retrieving the device id and model from the Win32_DiskDrive object. Under IIS native ASP.NET server I'm experiencing security p...more >>

Multiple SSLs on the same IIs server
Posted by super1 at 10/1/2007 9:58:08 AM
I have a wildcard ssl that most of my sites use. I need to add a site that doesn't fit the wildcard naming scheme. I have read that I need a unique IP address for the site so the users will be given the right ssl cert when they browse the site. I created the site, applied the cert, and as...more >>

Mapped Client Certs Don't work on my domain member web server
Posted by JSDBrian at 10/1/2007 7:49:02 AM
I have a web service that I want to protect using client certificates. I want to be able to map the certificate using IIS mapping to a windows user. I have successfully done this on my development server which is a 2003/IIS 6 server that is not connected to a domain. However when I try to set ...more >>


DevelopmentNow Blog