all groups > iis security > october 2007
IIS 6.0, ASP.NET, SQL 2000 on one server?
Posted by gcadmindude at 10/30/2007 7:19:01 AM
Hi gang! I need some help here...ok, I need a LOT of help here! I've just
been informed that we will be building a new Win2003 based web server that
will host our public web site. To my surprise I have been directed to put
all of our SQL 2000 databases on this server. My first response...a... more >>
IIS5 - 'microsoft false logging weakness'
Posted by news.microsoft.com at 10/29/2007 1:04:00 PM
Please help,
I've got an IIS machine that is failing PCI compliance due to the 'False
Logging Weakness'. the resolution states to use URLScan to translate hex
codes into characters, but I have no idea how to do this...
Can anyone shed some light?
Thanks.
... more >>
IIS 6 and system's object namespace
Posted by Roger Abell [MVP] at 10/26/2007 2:19:54 PM
This is perhaps a bit extreme, but I wonder if anyone might have a hint on
this.
I have to support multiuser/multiowner webs in multiple sites on IIS 6,
which is no problem, except that they also require FPSE/Sharepoint
extensions. As we know, those extensions are lame when it comes to ACL... more >>
Upgrading from IIS 5.1 to IIS 6.0
Posted by WJB at 10/26/2007 10:58:01 AM
Hi,
I'm developing a web app using VS 2005 (C#) and SQL Server 2005 on Win XP
Pro SP2. The app will be deployed under IIS 6.0, so I need to upgrade IIS on
my machine from 5.1 to 6.0. My Windows CD has 5.1.
1. Are there any compatibility issues between IIS 6.0 and Win XP Pro, SP2?
2. Wher... more >>
IISReset for non-Admins
Posted by Paul DiGiorgio at 10/24/2007 8:27:00 AM
I have a group of IIS 6.0 servers (Windows 2003 Standard Edition), which are
all managed by a support group. The members of the support group are not
Admins on these IIS servers. I am managing these servers with a single GPO.
The support would like to have rights to run IISRESET. What do I ne... more >>
Basic Authentication fails with Error 401.2 where Integrated succe
Posted by Jude Fisher at 10/24/2007 1:45:01 AM
Hi,
I'm a developer rather than a server tech and I've run into some problems
configuring a website.
An external provider we're using requires that a specific script be in a
directory that is protected by Basic Authentication. This isn't something
I've had to do before so I've been stum... more >>
ssl cert in IIS 6 works for Firefox, fails for IE 6 & 7
Posted by Ben Conner at 10/23/2007 9:09:00 PM
Hi,
I have a public server hosting multiple sites, some of which have secure
certs. Recently had clients telling me they get a "Cannot find server or DNS
Error" when trying to view a site in secure mode with IE, but have no problem
viewing it with Firefox. Until a week or so ago, there wa... more >>
Anonymous User Password Sync
Posted by Usman Jamil at 10/23/2007 4:17:44 PM
Hi
In IIS 5 , while creating websites programatically, i set the anonymous pass
sync (Allow iis to control password) property to true, due to which I dont
have to reset the password for anonymous user even if someone changes the
password from user manager under windows. In IIS 6, I repeated... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
IIS6 - Directory Traversal in Active Server Pages - FSO
Posted by Patrick at 10/22/2007 3:39:14 PM
Hello
I'm just doing some checks on the system, and we found out that directory
traversal is possible with classic .asp. It is possible using the
filesystemobject.
Then i tried to add specific permissions to the application pool of this
website, but it still was possible to access other ... more >>
SSL certificates and multiple websites
Posted by tandrist at 10/22/2007 1:23:00 PM
I have one web server housing multiple sites, can I use a single certificate
for all the websites or do I need to apply the SSL certficate(s) to each site
individually? Using the certificate creation wizard, it looks like it makes
them based off a single website? Is there a way to create one... more >>
how to setup IIS to authenticate users via private key?
Posted by Mr. Macker at 10/22/2007 11:47:10 AM
All ~ I'm trying to setup authentication on my IIS 6.0 server to
authenticate users only via using a private encrypted key.
Does anyone know how to do this? Or is there documenation you can point me
to?
Thank you! ~M
... more >>
WebDav with OWA
Posted by Tony at 10/19/2007 12:25:02 PM
I am trying to implement WEBDAV in an OWA server. I created a virtual
directory with unc to a share in another server. I gave full access to the
user who need to access the folder https://server1/webdav/testa. I keeps
prompting me to logon each time I do something. when I want to open a
... more >>
Prevent a ISAPI DLL to be accessed externally in IIS 6
Posted by toolsandcomps NO[at]SPAM gmail.com at 10/19/2007 10:56:52 AM
Hello:
I have a ISAPI DLL in my server and I want to prevent people to access
it externally, only from the server itself.
Ex: someone has a website on server X and their HTMLs are accessing a
DLL hosted on my server.
Can I prevent it?
Thanks in advance...
Jackson Gomes
... more >>
HTTP Error 401.1 - Unauthorized: Access is denied due to invalid c
Posted by Adam N. at 10/19/2007 8:45:01 AM
I am getting this error, when trying to access any of the sites hosted on our
IIS server.....
HTTP Error 401.1 - Unauthorized: Access is denied due to invalid credentials.
Internet Information Services (IIS)
I created a new site that I can fine, I have attempted to compare the
security / ... more >>
"SSL Server Allows Anonymous Authentication Vulnerability"
Posted by criechton at 10/18/2007 7:02:01 AM
I have two windows 2003/IIS 6.0 servers that are load balanced thru an F5
networks device, an ISS security scan of the URL that is shared by the two
servers is showing "SSL Server Allows Anonymous Authentication
Vulnerability". How do I address and remediate this vulnerability.
Thanks in ... more >>
can't install user certificcate from other ad domains
Posted by Fadoul at 10/17/2007 4:43:45 PM
Hi
I have a certificate server running on a W2k3 SP2 server. this server is a
global catalog. All user certificates are processed correctly when accessed
by main root ad domain but when i tried to ask a user certificate from the
web interface (certsrv), users from the second domain on my A... more >>
Remote administration
Posted by Arne Garvander at 10/17/2007 6:07:01 AM
I am trying to administer IIS with mmc for a remote computer.
I don't have the right security for that. What does my admin need to change
on my behalf?
--
Arne Garvander
Certified Geek
Professional Data Dude... more >>
FTP directory security setup.
Posted by tdr at 10/17/2007 5:04:01 AM
I'm trying to stop hackers from trying to accessing my ftp server.
I've tried to use the 'directory serurity' tab and "denied all" but the few
users I want to access my ftp site.
I've select "denied all but" and entered the ip address of one system and
the domain of the other ex. "mydomain... more >>
Redirect problems
Posted by me at 10/16/2007 1:56:03 PM
Hi All...
I know that this may seem very trivial, but I just can't get this to work!
I'm trying to set up a redirect on one of our servers to go from a non-https
page to https. The https site is already on the server. I created a second
site with a redirect page running on port 80 with the ... more >>
WebDav Permissions for Operators groups
Posted by Roman at 10/15/2007 11:27:20 AM
I have a standalone Windwos 2003 Server SP1 with IIS 6.0 and WebDav enabled
(a AD integraded server has the same behaviour).
A Folder on the server is mounted as Virtual Directory, which has the
following NTFS permissions:
User1: Read & Execute, List Folder Contents, Read
User2: Full Contro... more >>
Cross site scripting issue in IIS 5.0
Posted by criechton at 10/15/2007 8:34:00 AM
I have a Windows 2003 server SP4 running IIS and a PCI scan shows up with a
Cross site scripting vulnerability. The Standard M$ response was to install
MS02-018.mspx but this was from 2002 and must have been installed already
years ago because since the server is on SP4. Please advise if ther... more >>
write a file to as subfolder of a InetServer location
Posted by Thanh-Nhan Le at 10/14/2007 2:43:04 PM
Hi,
I have an ASP application on IIS server:
http://localhost/myApp
I use ASP and a my own VB activex DLL to create a pdf file and write this
file to a subfolder of the Application folder:
http://localhost/myApp/pdfs
1-
Over IIS I have set the "write permission" for this subfolder.
But ea... more >>
HELP-Domain Controller reboot causes session loss
Posted by JJ at 10/13/2007 8:58:00 PM
Please forgive my IIS ignorance when reading this question....I am a Windows
Admin and we have developers that have developed an application with asp.net.
They have front end web servers that tie to a back-end database (SQL).
All servers (including domain controllers) are windows 2003.
... more >>
need certificate that works for external name and internal name
Posted by Jordan at 10/9/2007 6:16:22 PM
Is there a way to get a certificate from MS Cert Server installed on IIS for
Win 2003 so that it works for both external and internal names without
coming up with a warning on one of them about the name?
I have an Exchange 2003 server that I want to use OWA and OMA on, but
securely as possi... more >>
CLR calling a web service and AppPool impersonation - weird issue
Posted by Sergei Shelukhin at 10/8/2007 9:17:22 AM
Hi. Crossposted because the issue seems bizzare and I have no idea
where the problem lies.
We have a CLR that calls ASP.NET Web Service using NetworkCredentials
to pass in login, passowrd and domain of a domain user.
Application and apppool housing the webservice run under network
service; II... more >>
Standard User using IIS 5.0 - XP
Posted by MarcioHunecke at 10/8/2007 9:15:07 AM
We want to restrict our developers to a standard user (no administrator
rights) but they need to use the full features of IIS from Windows XP SP2.
Does anybody know how to do it? Please let me know. Thanks.... more >>
Possible to retrieve password of current application pool
Posted by Dylan Nicholson at 10/4/2007 8:10:57 AM
Running as an administrator, I can retrieve the account password
stored by IIS for any application pool (using the WAMUserPass
property). But, unsurprisingly, an ASP.NET application running inside
an application pool that is does not have administrator privileges
can't even enumerate the list o... more >>
from Windows2000 (IIS5) to Windows2003 (IIS6)
Posted by Mike at 10/4/2007 7:21:01 AM
The application is a pair of ISAPI dlls running under IIS which in turn call
some COM components, etc...
They are set as high isolation in the IIS admin settings. This issue I saw
when setting up our stuff on
Server2003 is that I would get a windows login prompt while hitting the
ISAPI si... more >>
PRØVESENDING !!!!!!!
Posted by thoralf.renslo NO[at]SPAM dabb.no at 10/3/2007 11:59:57 AM
sennder en prøve svar tilbake på N O R S K !!!!!!
... more >>
Web Folders and Integrated Authentication
Posted by neil662 NO[at]SPAM yahoo.com at 10/3/2007 9:52:42 AM
Hi all,
I'm having an issue with Web Folders and Integrated Authentication.
Basically I've an IIS 6 website setup that contains some web folders.
Inside the web folders are a collection of file types including Office
documents, text files and images. The website is setup to use
Integrated Au... more >>
IIS 5.0 and disabling the indexing service.
Posted by criechton at 10/3/2007 6:46:03 AM
I had a scan done to my server and this came up.
"Microsoft Internet Information Server Hit Highlighting Authentication
Bypass Vulnerability"
The suggested fix is to upgrade to IIS6.0 , I can't because it's Win2000 std
svr, it also says to disable the indexing service.. How do I do this?
... more >>
Allow only url forwarding source IP
Posted by kazi at 10/2/2007 6:10:00 PM
I want to use an application which enables 2 factor authentication on IIS
websites i.e(http://www.phonefactor.net). Unfortunately I'm already using a
portal application which does not run on IIS but am interested to protect via
phonefactor. So far I'm able to do a workaround to apply 2 factor ... more >>
WMI Security Problems
Posted by Nuno Magalhaes at 10/2/2007 12:06:23 PM
Hello,
I've done a small web application that uses WMI wrapper
(System.Management) and everything works fine on Cassini's development
web server from VS2005, while retrieving the device id and model from
the Win32_DiskDrive object.
Under IIS native ASP.NET server I'm experiencing security p... more >>
Multiple SSLs on the same IIs server
Posted by super1 at 10/1/2007 9:58:08 AM
I have a wildcard ssl that most of my sites use. I need to add a site that
doesn't fit the wildcard naming scheme. I have read that I need a unique IP
address for the site so the users will be given the right ssl cert when they
browse the site.
I created the site, applied the cert, and as... more >>
Mapped Client Certs Don't work on my domain member web server
Posted by JSDBrian at 10/1/2007 7:49:02 AM
I have a web service that I want to protect using client certificates. I want
to be able to map the certificate using IIS mapping to a windows user. I have
successfully done this on my development server which is a 2003/IIS 6 server
that is not connected to a domain. However when I try to set ... more >>
|