Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008
all groups > iis security > april 2007

Getting 404 errors on files that are present
Posted by Tom Miller at 4/29/2007 6:00:58 PM
I run a website with over 770,000 files for downloading. I am getting 404 errors for files that you can clearly "see" because the page that your seeing was created on the fly by the directory browsing feature. I don't think I was having this much trouble with the Sever 2000/iis v? but I seem t...more >>


You are not authorized to view this page
Posted by Bob at 4/28/2007 12:00:00 AM
Hi I have two IIS servers with similar setups, When I logon to the server and use IE to view the website, everything works as expected on both servers When I use a different computer to view the same pages, then one works OK, and the other gives me the error in the subject line. Lookin...more >>

KDC Service Account
Posted by Tony Holm at 4/27/2007 5:24:03 AM
I am trying to configure OWA with patch for KB 920209 to enable Smart Card login to OWA. Part of the KB is creating a KDC Service Account, which appears to require using "setspn". The examples leave LOTS to be desired. Do I run setspn on the OWA server or domain controller? One of the co...more >>

Integrated Windows Authentication and Domain prefix on popup
Posted by Braulio Diez at 4/27/2007 1:52:02 AM
Hello, first of all... "sorry in advance" I come from the development world and I'm not quite good at the admin. Jargon :-). In the web application that we have we are using "Integrated Windows Authentication", what it happens for users that want to authenticate from outside the doma...more >>

Security question (virtual directory)
Posted by Martijn_online at 4/26/2007 10:42:10 PM
I can not protect files that are in a virtual directory. What is wrong? Situation: - three Windows 2003 server: S1: primary server S2: Exchange + IIS 6 (with intranet) S3: printer and file services. Including \\D3\Data share - on S2: 1. intranet website with root in C:\inetpub\wwwroot...more >>

Using SSL with 2 WebSites
Posted by Eric at 4/26/2007 6:38:27 AM
I have installed Windows SharePoint Services and I am using SSL with it. We are going to have 2 domains, one internal and one external, but in IIS they are still the same vitural site. Is there a way I can get SSL to work with both domians? Such as https://sharepoint (internal) and https:...more >>

Notify user of SSL 3 requirement
Posted by cats solutions at 4/25/2007 3:54:02 AM
We have enforced SSL v3.0 or TLS v1.0 on our server (Win 2003 Srv R2 with IIS 6). When I try to connect using only SSl v2.0 I just get a Page Cannot Be Displayed error message. What I want to do is this: I want the user to connect an unsecured page which runs a script to see if the clien...more >>

defacement by Turkish hacker
Posted by Jheer at 4/24/2007 8:20:00 PM
2007-04-20 01:59:43UTC 88.229.55.206 Hacked By Nið-DeLi Defaced a page on just 1 of my sites. PUT /index.htm to plant the file using Microsoft+Data+Access+Internet+Publishing+Provider+DAV+1.1, was the method. I have since repaired this per MS KB 241520. prob should suggest others disable the ...more >>



Access denied in subdirectory
Posted by Roman Mellenberger at 4/24/2007 1:11:58 AM
Hello, i have a problem configuring IIS6 to enable http downloads. I have a subdirectory on Inetpub\wwwroot called download. There I put some files (.exe and .dll) for downloading. I also registered MIME types (.dll and .exe) as Application/octet-stream. The download via Browser from the ro...more >>

certificate problem
Posted by locoytravieso at 4/23/2007 5:06:01 PM
Hi All- I repurposed a virtual server and an old certificate to a different CA is stuck in IIS and I can't figure out any way to remove it. Additionally, when I try to submit a new certificate it goes to the old location. Do I need to just start over from scratch and reinstall Windows to ge...more >>

Enabling/disabling SSL via script
Posted by Shawn Hansen at 4/23/2007 3:59:19 PM
I have an situation where I'm trying to copy files via the Windows XP WebDAV redirector to a Sharepoint server that has SSL enabled. Problem is that the XP WebDAV redirector does not support SSL. If I temporarily disable SSL on the site, the file copy works fine. I can then re-enable SSL an...more >>

IIS Certificate
Posted by fisherman152 at 4/23/2007 1:58:03 PM
I have a website and installed CA on the server, and created a SSL connection, everything is fine until I enable the client require certificate. I have followed the link and followed the instructions http://msdn2.microsoft.com/en-us/library/aa302412.aspx, but when access the page the certif...more >>

Disabling HTTP TRACE METHOD in IIS 6
Posted by wayne NO[at]SPAM piercedknob.co.uk at 4/23/2007 12:17:11 PM
Hi everyone, I have spotted a few posts on this matter but still a little confussed. Some people are saying that you need to install URLScan in order to disable this however i don't really want to install this and would much prefer to just disable it without the installation of additional ...more >>

can't success on ssl
Posted by keyser soze at 4/20/2007 2:04:12 PM
hi i'm trying to setup ssl following some guides like http://technet2.microsoft.com/WindowsServer/f/?en/library/c809b2b8-5558-421f-96d4-53d959e905c71033.mspx but i can't make ssl work if i browse the site with "http://" the web server notifies me an "403.4 - write httpS:// instead" but wh...more >>

Digest Authentication - IIS6
Posted by Pablo A. Allois at 4/19/2007 6:06:35 PM
Hi everybody, First, I apology for my english. I am fighting with a web site to setting up to use Digest Authentication. I set the domain correctly, DNS are ok, but I cant login to the website. If I setup the website with Basic authentication works fine (f...more >>

Adding SSL to a framed website
Posted by steve at 4/19/2007 3:12:37 PM
Hi all, I have two websites (www.site1.com and www.site2.com) running on IIS on two different machines. One of the pages on site1 uses frames, and the main frame contains a page from site2. I wish to enable SSL on both sites, but am concerned that when the frames-page on site1 is accessed t...more >>

IIS - Internet Explorer - Not Prompting for Credentials
Posted by Mark at 4/19/2007 8:52:01 AM
We have a website in IIS6 that we have protected using Integrated Windows authentication with Anonymous access disabled. The normal behaviour in IE6 when hitting this site over the Internet is to prompt for credentials. However, we have run across 3 IE6 installations (6.0.2900.2180) that do no...more >>

Cannot Get Anonymous Access to Work
Posted by Will at 4/18/2007 5:23:42 PM
I'm setting up an IIS 6.0 public server, and I've run into problems getting anonymous access to work. We of course gave read access to the IUSR_<MachineName> account to all of the application's files under InetPub, but we are getting 401.3 errors indicating ACL problems. If we select the...more >>

Purpose of IWAM Account IIS 6.0?
Posted by Will at 4/18/2007 5:20:55 PM
Is it right that the only purpose of the IWAM_<MachineName> account is to run any process that is spawned from within the IIS 6.0 server process? What is the security context of an ASP application that runs in the server process without spawning a separate process? The IIS service appears t...more >>

Renew SSL Cert With New Company
Posted by Cy at 4/17/2007 8:21:16 AM
I am in the process of renewing my existing SSL cert with Network Solutions. It is currently with Verisign. I would like the current cert to be valid until I install the new one. Is there a way to generate the CSR without removing the current certificate? In IIS 6.0 do I: - Renew the current ...more >>

Is it dangerous to use a local administrator account for anonymous access to a secure site?
Posted by Paulaner at 4/16/2007 9:48:52 AM
We have a web application that uses asp pages and javascript to display information to users. We want the data to be secure, so the login page will redirect http:// users from port 80 to https:// on port 443. We prompt for a username a password, then use an isapi filter to authenticate the...more >>

Urgent help: Possible security breach
Posted by Gaspar at 4/13/2007 9:10:06 AM
When I arrived this morning to my office I noticed that the intranet's home page was modified: Some images where erased, others changed, etc. The strange thing is that the modification time is 20:15 and no IT users work at this hours (work time is 9:00 to 17:00). I'm now thinking of some sec...more >>

How to pass user credentials to IE
Posted by kanes NO[at]SPAM ims.com.au at 4/13/2007 1:15:31 AM
Hi, My application needs to call a IIS web based application that requires Windows based authentication. The user credentials that our application will use is not the same as the user logged onto the workstation. When calling the web page, IE prompts for a user ID and password. I would like t...more >>

IIS 6 and IE6 sending authentication via URL?
Posted by Transam388 at 4/12/2007 5:34:04 AM
Not sure if this is IIS or IE but I tyhink it may be both. Anyway, we have a SharePoint web site that requires a log in to access. The issue is we also need to monitor this web site to make sure it is available. MOM has a utility to check web pages but with this page requesting a login of c...more >>

How to disable HTTP trace in IIS 5
Posted by yklee at 4/11/2007 8:24:01 PM
i'm not familiar with iis or http and its jargon. my iis5 server (windows 2000 sp4) is currently hosting our website & owa. it is a requirement to ensure that the http trace is disabled on the server. i have try but still could not understand what or how to configure the urlscan.ini to just d...more >>

Certificate authority
Posted by Jim in Cleveland at 4/10/2007 1:08:06 PM
I'm trying to Implement the Change Password feature with Outlook Web Access (Q297121). I followed the procedure documented in Q228821 about generating a Certificate Request file. I created the file but now it says I have to submit this file to a Certificate Authority. Where do I find one to...more >>

can someone explain this weird behaviour?
Posted by Mich at 4/10/2007 11:33:22 AM
Hi, The situation: windows xp pro sp2 (IIS 5.1). In the windows of IIS management, all virtual maps are under "Default website". The property "Map security" is first set on "Windows Integrated Authentification". There is a virtual map with property "Map security" set to "Anonymous a...more >>

server certificate greyed out
Posted by locoytravieso at 4/9/2007 9:06:04 PM
Hello- I completely screwed up my OWA so I uninstalled Exchange and IIS both. Now when I go under the properties of the directory I want to secure the "Server Certificate" button is greyed out and if I go to View Certificate it shows a certificate I don't even HAVE installed any more. How d...more >>

IIS IUSR_ PROBLEM
Posted by in da club at 4/5/2007 2:03:09 PM
I have installed iis 6.0 on my win 2003 server.. I created a web site and give IUSR_MAchinename account to access web site with only integrated windows authentication. I put my files into into wwwroot folder and give the all permission for iusr_machinename account. When i try to access ...more >>

UNC Virtual Directories; NTFS permission authentication not accept
Posted by Jason Carter at 4/4/2007 7:42:05 AM
This one is driving me crazy. Here is the environment: I have one web server, Windows 2003 R2; IIS 6.0, and a files server running Windows 2003 R2. Both servers are part of a Windows 2003 native Active Directory domain. Virtual directories have been created on the web server pointing to a...more >>

Convert Self-Signed Certificate?
Posted by lucius at 4/3/2007 11:41:12 AM
Using an internal Microsoft Certificate Authority server, I have created a root CA and signed many web site certificates. The latest version of IE makes these IIS/MS-CA SSL sites look "criminal" because the certificates were not signed by Verisign. I give up. How can I convert my root CA certifi...more >>

How to disable SSL v2 support on IIS 6.0?
Posted by Ray Yan at 4/2/2007 9:16:03 PM
Hi there, We're running a website on a IIS6.0 / Windows2003 SP1 server, with a Thawte web server certificate installed to enable HTTPS access. Now we want to force client connections use SSL v3 or SLT 1.0 or SLT 1.1 or better, so we decided to stop supporting SSL v2 on this server. But we w...more >>

User Accounts Locked Out!
Posted by Adotek at 4/2/2007 1:21:01 AM
Hi All, I have this morning put a new IIS 6 server live, since which I am getting reports that user accounts are being locked out as soon as they visit the site on the new server (Intranet). We are using intergrated auth. I havent fully investigated this yet, just wondering if anyone can h...more >>


DevelopmentNow Blog