all groups > iis security > april 2007
Getting 404 errors on files that are present
Posted by Tom Miller at 4/29/2007 6:00:58 PM
I run a website with over 770,000 files for downloading. I am getting 404
errors for files that you can clearly "see" because the page that your
seeing was created on the fly by the directory browsing feature. I don't
think I was having this much trouble with the Sever 2000/iis v? but I seem
t... more >>
You are not authorized to view this page
Posted by Bob at 4/28/2007 12:00:00 AM
Hi
I have two IIS servers with similar setups,
When I logon to the server and use IE to view the website, everything works
as expected on both servers
When I use a different computer to view the same pages, then one works OK,
and the other gives me the error in the subject line.
Lookin... more >>
KDC Service Account
Posted by Tony Holm at 4/27/2007 5:24:03 AM
I am trying to configure OWA with patch for KB 920209 to enable Smart Card
login to OWA.
Part of the KB is creating a KDC Service Account, which appears to require
using "setspn". The examples leave LOTS to be desired.
Do I run setspn on the OWA server or domain controller?
One of the co... more >>
Integrated Windows Authentication and Domain prefix on popup
Posted by Braulio Diez at 4/27/2007 1:52:02 AM
Hello,
first of all... "sorry in advance" I come from the development world and
I'm not quite good at the admin. Jargon :-).
In the web application that we have we are using "Integrated Windows
Authentication", what it happens for users that want to authenticate from
outside the doma... more >>
Security question (virtual directory)
Posted by Martijn_online at 4/26/2007 10:42:10 PM
I can not protect files that are in a virtual directory. What is wrong?
Situation:
- three Windows 2003 server:
S1: primary server
S2: Exchange + IIS 6 (with intranet)
S3: printer and file services. Including \\D3\Data share
- on S2:
1. intranet website with root in C:\inetpub\wwwroot... more >>
Using SSL with 2 WebSites
Posted by Eric at 4/26/2007 6:38:27 AM
I have installed Windows SharePoint Services and I am using SSL with
it.
We are going to have 2 domains, one internal and one external, but in
IIS they are still the same vitural site.
Is there a way I can get SSL to work with both domians?
Such as https://sharepoint (internal) and https:... more >>
Notify user of SSL 3 requirement
Posted by cats solutions at 4/25/2007 3:54:02 AM
We have enforced SSL v3.0 or TLS v1.0 on our server (Win 2003 Srv R2 with IIS
6). When I try to connect using only SSl v2.0 I just get a Page Cannot Be
Displayed error message.
What I want to do is this:
I want the user to connect an unsecured page which runs a script to see if
the clien... more >>
defacement by Turkish hacker
Posted by Jheer at 4/24/2007 8:20:00 PM
2007-04-20 01:59:43UTC 88.229.55.206 Hacked By Nið-DeLi
Defaced a page on just 1 of my sites. PUT /index.htm to plant the file using
Microsoft+Data+Access+Internet+Publishing+Provider+DAV+1.1,
was the method. I have since repaired this per MS KB 241520. prob should
suggest others disable the ... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
Access denied in subdirectory
Posted by Roman Mellenberger at 4/24/2007 1:11:58 AM
Hello,
i have a problem configuring IIS6 to enable http downloads. I have a
subdirectory on Inetpub\wwwroot called download. There I put some
files (.exe and .dll) for downloading. I also registered MIME types
(.dll and .exe) as Application/octet-stream.
The download via Browser from the ro... more >>
certificate problem
Posted by locoytravieso at 4/23/2007 5:06:01 PM
Hi All-
I repurposed a virtual server and an old certificate to a different CA is
stuck in IIS and I can't figure out any way to remove it. Additionally, when
I try to submit a new certificate it goes to the old location. Do I need to
just start over from scratch and reinstall Windows to ge... more >>
Enabling/disabling SSL via script
Posted by Shawn Hansen at 4/23/2007 3:59:19 PM
I have an situation where I'm trying to copy files via the Windows XP WebDAV
redirector to a Sharepoint server that has SSL enabled. Problem is that the
XP WebDAV redirector does not support SSL. If I temporarily disable SSL on
the site, the file copy works fine. I can then re-enable SSL an... more >>
IIS Certificate
Posted by fisherman152 at 4/23/2007 1:58:03 PM
I have a website and installed CA on the server, and created a SSL
connection, everything is fine until I enable the client require certificate.
I have followed the link and followed the instructions
http://msdn2.microsoft.com/en-us/library/aa302412.aspx, but when access the
page the certif... more >>
Disabling HTTP TRACE METHOD in IIS 6
Posted by wayne NO[at]SPAM piercedknob.co.uk at 4/23/2007 12:17:11 PM
Hi everyone,
I have spotted a few posts on this matter but still a little
confussed. Some people are saying that you need to install URLScan in
order to disable this however i don't really want to install this and
would much prefer to just disable it without the installation of
additional ... more >>
can't success on ssl
Posted by keyser soze at 4/20/2007 2:04:12 PM
hi
i'm trying to setup ssl
following some guides like
http://technet2.microsoft.com/WindowsServer/f/?en/library/c809b2b8-5558-421f-96d4-53d959e905c71033.mspx
but i can't make ssl work
if i browse the site with "http://"
the web server notifies me an "403.4 - write httpS:// instead"
but wh... more >>
Digest Authentication - IIS6
Posted by Pablo A. Allois at 4/19/2007 6:06:35 PM
Hi everybody,
First, I apology for my english.
I am fighting with a web site to setting up to use Digest
Authentication.
I set the domain correctly, DNS are ok, but I cant login to the
website.
If I setup the website with Basic authentication works fine (f... more >>
Adding SSL to a framed website
Posted by steve at 4/19/2007 3:12:37 PM
Hi all,
I have two websites (www.site1.com and www.site2.com) running on IIS on two
different machines. One of the pages on site1 uses frames, and the main
frame contains a page from site2. I wish to enable SSL on both sites, but am
concerned that when the frames-page on site1 is accessed t... more >>
IIS - Internet Explorer - Not Prompting for Credentials
Posted by Mark at 4/19/2007 8:52:01 AM
We have a website in IIS6 that we have protected using Integrated Windows
authentication with Anonymous access disabled. The normal behaviour in IE6
when hitting this site over the Internet is to prompt for credentials.
However, we have run across 3 IE6 installations (6.0.2900.2180) that do no... more >>
Cannot Get Anonymous Access to Work
Posted by Will at 4/18/2007 5:23:42 PM
I'm setting up an IIS 6.0 public server, and I've run into problems getting
anonymous access to work. We of course gave read access to the
IUSR_<MachineName> account to all of the application's files under InetPub,
but we are getting 401.3 errors indicating ACL problems.
If we select the... more >>
Purpose of IWAM Account IIS 6.0?
Posted by Will at 4/18/2007 5:20:55 PM
Is it right that the only purpose of the IWAM_<MachineName> account is to
run any process that is spawned from within the IIS 6.0 server process?
What is the security context of an ASP application that runs in the server
process without spawning a separate process? The IIS service appears t... more >>
Renew SSL Cert With New Company
Posted by Cy at 4/17/2007 8:21:16 AM
I am in the process of renewing my existing SSL cert with Network
Solutions. It is currently with Verisign. I would like the current
cert to be valid until I install the new one. Is there a way to
generate the CSR without removing the current certificate? In IIS 6.0
do I:
- Renew the current ... more >>
Is it dangerous to use a local administrator account for anonymous access to a secure site?
Posted by Paulaner at 4/16/2007 9:48:52 AM
We have a web application that uses asp pages and javascript to
display information to users. We want the data to be secure, so the
login page will redirect http:// users from port 80 to https:// on
port 443. We prompt for a username a password, then use an isapi
filter to authenticate the... more >>
Urgent help: Possible security breach
Posted by Gaspar at 4/13/2007 9:10:06 AM
When I arrived this morning to my office I noticed that the intranet's
home page was modified: Some images where erased, others changed, etc.
The strange thing is that the modification time is 20:15 and no IT users
work at this hours (work time is 9:00 to 17:00).
I'm now thinking of some sec... more >>
How to pass user credentials to IE
Posted by kanes NO[at]SPAM ims.com.au at 4/13/2007 1:15:31 AM
Hi,
My application needs to call a IIS web based application that requires
Windows based authentication. The user credentials that our
application will use is not the same as the user logged onto the
workstation. When calling the web page, IE prompts for a user ID and
password. I would like t... more >>
IIS 6 and IE6 sending authentication via URL?
Posted by Transam388 at 4/12/2007 5:34:04 AM
Not sure if this is IIS or IE but I tyhink it may be both. Anyway, we have a
SharePoint web site that requires a log in to access. The issue is we also
need to monitor this web site to make sure it is available. MOM has a
utility to check web pages but with this page requesting a login of c... more >>
How to disable HTTP trace in IIS 5
Posted by yklee at 4/11/2007 8:24:01 PM
i'm not familiar with iis or http and its jargon. my iis5 server (windows
2000 sp4) is currently hosting our website & owa. it is a requirement to
ensure that the http trace is disabled on the server. i have try but still
could not understand what or how to configure the urlscan.ini to just d... more >>
Certificate authority
Posted by Jim in Cleveland at 4/10/2007 1:08:06 PM
I'm trying to Implement the Change Password feature with Outlook Web Access
(Q297121). I followed the procedure documented in Q228821 about generating a
Certificate Request file. I created the file but now it says I have to
submit this file to a Certificate Authority. Where do I find one to... more >>
can someone explain this weird behaviour?
Posted by Mich at 4/10/2007 11:33:22 AM
Hi,
The situation: windows xp pro sp2 (IIS 5.1).
In the windows of IIS management, all virtual maps are under "Default
website".
The property "Map security" is first set on "Windows Integrated
Authentification".
There is a virtual map with property "Map security" set to "Anonymous
a... more >>
server certificate greyed out
Posted by locoytravieso at 4/9/2007 9:06:04 PM
Hello-
I completely screwed up my OWA so I uninstalled Exchange and IIS both. Now
when I go under the properties of the directory I want to secure the "Server
Certificate" button is greyed out and if I go to View Certificate it shows a
certificate I don't even HAVE installed any more. How d... more >>
IIS IUSR_ PROBLEM
Posted by in da club at 4/5/2007 2:03:09 PM
I have installed iis 6.0 on my win 2003 server..
I created a web site and give IUSR_MAchinename account to access web site
with only integrated windows authentication.
I put my files into into wwwroot folder and give the all permission for
iusr_machinename account.
When i try to access ... more >>
UNC Virtual Directories; NTFS permission authentication not accept
Posted by Jason Carter at 4/4/2007 7:42:05 AM
This one is driving me crazy. Here is the environment:
I have one web server, Windows 2003 R2; IIS 6.0, and a files server running
Windows 2003 R2. Both servers are part of a Windows 2003 native Active
Directory domain.
Virtual directories have been created on the web server pointing to a... more >>
Convert Self-Signed Certificate?
Posted by lucius at 4/3/2007 11:41:12 AM
Using an internal Microsoft Certificate Authority server, I have
created a root CA and signed many web site certificates. The latest
version of IE makes these IIS/MS-CA SSL sites look "criminal" because
the certificates were not signed by Verisign. I give up. How can I
convert my root CA certifi... more >>
How to disable SSL v2 support on IIS 6.0?
Posted by Ray Yan at 4/2/2007 9:16:03 PM
Hi there,
We're running a website on a IIS6.0 / Windows2003 SP1 server, with a Thawte
web server certificate installed to enable HTTPS access. Now we want to force
client connections use SSL v3 or SLT 1.0 or SLT 1.1 or better, so we decided
to stop supporting SSL v2 on this server. But we w... more >>
User Accounts Locked Out!
Posted by Adotek at 4/2/2007 1:21:01 AM
Hi All,
I have this morning put a new IIS 6 server live, since which I am
getting reports that user accounts are being locked out as soon as
they visit the site on the new server (Intranet). We are using
intergrated auth.
I havent fully investigated this yet, just wondering if anyone can
h... more >>
|