Archived Months
June 2003
July 2003
August 2003
September 2003
October 2003
November 2003
December 2003
January 2004
February 2004
March 2004
April 2004
May 2004
June 2004
July 2004
August 2004
September 2004
October 2004
November 2004
December 2004
January 2005
February 2005
March 2005
April 2005
May 2005
June 2005
July 2005
August 2005
September 2005
October 2005
November 2005
December 2005
January 2006
February 2006
March 2006
April 2006
May 2006
June 2006
July 2006
August 2006
September 2006
October 2006
November 2006
December 2006
January 2007
February 2007
March 2007
April 2007
May 2007
June 2007
July 2007
August 2007
September 2007
October 2007
November 2007
December 2007
January 2008
February 2008
March 2008
April 2008


all groups > iis security > january 2008

Filter by week: 1 2 3 4 5

IIS 6 | Delegation | Netapp | CIFS
Posted by Ariel at 1/30/2008 10:49:01 AM
Hello, I'm attempting to host a virtual directory that is a CIFS share on a Netapp. I've setup the virtual directory to "Always use the authenticated user's credentials when validating access to the network directory" After reading: "Deploying and Configuring Internet Information Servi...more >>

Permissions Help Needed
Posted by JTMZ at 1/29/2008 6:50:39 PM
I am an administrator on my own local box and am trying to access IIS locally (not over the network). If I goto my web app using http://localhost it works fine If I goto my web app using http://machinename or http://127.0.0.1 or http://TheValidIPAddress I get: 401.1 Access is denied due ...more >>

IIS6 - Can session id be manipulated?
Posted by Kim Hellan at 1/29/2008 12:59:41 PM
Hi, I have gotten a question about how IIS6 handles the session id (cookie). I've got a very persistent customer who claims, that you can just hijack another session by changing the session id in your own session cookie. I'm no security expert, but I find that very hard to believe. All though...more >>

IIS 5.1 SSL Cetificate Missing
Posted by Ming Dragon at 1/29/2008 12:08:00 PM
I recently did a system restore to recover from a driver installation catastrophic failure for my ATi video. (System Restore is a real MONSTER in a closet) In this process I ended up without an SSL Server Certificate for IIS 5.1. It installed fine when I built the machine and served its purp...more >>

'Error: Connection Error' when connecting to WSUS 3.0 (on IIS) via
Posted by Yuri GMT+1 at 1/29/2008 12:48:00 AM
Hi there, I get the above error message when I try to open the WSUS 3.0 console on the WSUS server (W2K3). It worked fine before. The problem occurred when I was testing on this production server (stupid me, I know, I know). I added tsweb for testing purposes on the same machine. Normall...more >>

Windows authentication with FQDN
Posted by Rob at 1/28/2008 10:57:02 AM
Is there a way to pass windows authentication on while using a FQDN name instead of regular server name while on the network/domain so as to not prompt for credentials? Like when logging into http://computer.domain.com instead of http://computer? It passes credentials properly when using jus...more >>

Access Denied
Posted by zz12 at 1/25/2008 5:20:13 PM
Hello, I have a domain user account which we've assigned it to the Local Administrators group on a w2k3 server machine in trying to allow this user to access and administrate the iis 6.0 manager. But when this user opens the iis manager console and tries to expand the local machine name it ...more >>

Problems with writing to a file on IIS 6.0
Posted by sarika.koganti@gmail.com at 1/24/2008 2:52:31 AM
I have an ASP.Net application which accesses a web server hosted on IIS. The web server creates a file in the application directory and writes to it. My application needs to run on 2K, 2K3 and XP, i.e. IIS 5.0, 5.1 and 6.0. I cannot use 'Inegrated Windows Authentication' (on my client's request...more >>



404 error when dowloading DLL files from IIS 6.0?
Posted by Usenet User at 1/22/2008 10:23:04 PM
Windows 2003 Server Standard SP1 IIS 6.0 ASP.NET 1.1 My ASP.NET page uses a client-side .NET control. The control is implemented as a .NET assembly which is located in the virtual directory root. This worked on IIS 5.0/Win 2000 server, bit IIS 6.0 refuses to serve the DLL file to the client ...more >>

Different web.config for Virtual Directories
Posted by Samuel at 1/22/2008 5:47:53 PM
Hi I have two virtual directories, pointing to the same asp.net application. I want to have different web.config files as I use different authentication methods for those two virtual directories. Is there a simple way to solve this? so that i can have different web.config for each virtua...more >>

IIS to IIS using kerberos and non-standard web port
Posted by Pom at 1/22/2008 4:37:02 PM
I have implemented kerberos in 3 tiers environnmnet where IIS 6.0 access a web services on a separate IIS server. I have properly setup all my SPNs, service account etc.. and it work fine. My problem is I have a requirement to run my webservices server on 8080 web port. I try every combination...more >>

Kerberos, SETSPN, GET & POST
Posted by raymond_b_jimenez@yahoo.com at 1/21/2008 1:41:28 PM
I have a web application that uses Integrated Windows Authentication. Had been having a peculiar problem, where every request to the Web server would give an 401 error, despite using HTTP/1.1 and the same socket. Discovered that having an application pool, I would have to register it with SETSP...more >>

Internet Security and E-mail
Posted by low88deb@hotmail.cominvalid at 1/17/2008 9:07:02 PM
I'm not sure exactly what to ask so I'll just describe something that happened I believe should be impossible. There are only two people that access my computer: me and my husband. My husband has been out of town for the last week. Today he found an e-mail from me with a document attached t...more >>

IIS 6 und Kerberos
Posted by Tobia at 1/17/2008 4:42:34 PM
Hi! I've a problem. I don't no it's my problem or a problem of IIS. The scenario: We have a member server with IIS in a W2K3 domain. There is only one website on it, one Applpool, only one default.htm (simple HTML, no script). Authentication isn't allowed anonym and Authentication methode is W...more >>

Change password popup window/option
Posted by JR at 1/17/2008 3:00:01 PM
I have an intranet setup on IIS 6.0. When users access it automatically requires logon to proceed into the site. I want IIS to notify the users that there password will expire within 12 days of expiring and give them the option to change there password. I would also like IIS to allow the user...more >>

how long it took MS to come out with patch
Posted by tony at 1/17/2008 11:29:49 AM
since 2003 or the release of IIS6, there has been 3 advisories for IIS6 1. MS04-030 is a WebDAV XML vulnerability that could lead to DoS - released 10/12/2004 2. MS04-034 is an ASP vulnerability that could lead to remote code execution - released 7/11/2006 What was the tim...more >>

IIS on DMZ
Posted by tony at 1/15/2008 10:47:00 PM
how secure is it to have IIS 6 on dmz? do i need to be using apache web proxy at all? ...more >>

IIS6 asp.net 2.0 and Verisign
Posted by Janet at 1/15/2008 1:53:06 PM
I'm investigating a Wildcard Verisign certificate for my server (intranet, internet, special app websites). What I'm wondering about is forcing the user to have 128bit encryption on the pages I've designated as https. If I try to use "In the Secure Communications dialog box, click the Requir...more >>

Creating Virtual Directory on shared drive
Posted by vasimo at 1/15/2008 7:31:01 AM
Hi, HELP!!!!!!!!!!!!! XP Desktop with IIS 5 doing web class development. Virtual directories are required for .Net apps. Our root folder for the web site is located on a drive share. I am trying to create virtual directories using VB script on all developer machines. The following creates...more >>

hiding IIS 6.0 signatures
Posted by tony at 1/14/2008 8:51:44 PM
How do i hide IIS 6 signatures from a scan or netcraft? ...more >>

Issue Digital Cert for NetBIOS name
Posted by Scott at 1/14/2008 7:06:03 PM
I'm using Certification Services on my W2K3 server, and wondered if it's possible to issue a certificate to a NetBIOS name for the sake of Internal/Intranet web page. In other words, because the web server will never be access via the Internet can I create a CSR and issue a .cer on a websit...more >>

Guest account with write and script execute access - how dangerous
Posted by Jeff Dunlap at 1/14/2008 6:46:01 PM
Dear IIS Users: I would like to know is if the following configuration is secure from hackers. Assume that my application is at MyDomain/myPerlApp/cgi-bin/app.pl and that this is my IIS configuration: 1) Removed anonymous authentication from myPerlApp and enabled Windows Authentic...more >>

Access to Site Via WindowsMobile 2006 - Keeps asking for Password
Posted by Scooter at 1/14/2008 5:10:00 PM
We have a few Webs that dont seem to want Windows Mobile users access it. The Windows Mobile users Range from WM2003, to WM5 WM6 using Sprint, AT&T, T-Mobile and WiFi THe Servers are Win2003R2 IIS6 latest Service Packs. Running Some ASP.Net and Sharepoint (WSS3.0) Sites. Both Sites Pro...more >>

ASP.NET 2.0 // IIS Authentication
Posted by Samuel at 1/14/2008 4:21:54 PM
Hi I'm trying to build a kind of small intranet page. We have some Intranet users which are member of the active directory, others which aren't. The main idea is that the users can go to http://intranet and if they are authenticated automatically, the just get the page content, if not, the...more >>

lockdown tool and IIS 6
Posted by tony at 1/14/2008 3:10:56 PM
Is it necesary to run IIS lockdown tool on IIS 6? ...more >>

C F S 3 THE END????????????????????????????????
Posted by sabredog at 1/12/2008 5:14:00 AM
WHATS GOING ON????? CFS3 HAS ENDED!!! THERE IS NO SERVER ANY MORE!!! THIS CANT HAPPEN!! WE MUST STAND TOGETHER OVER THIS ISSUE AND FIGHT FOR THE GAME TO RETURN!! IF THIS IS THE CASE AS IT NOW APPEARS TO BE SO WHAT ABOUT ALL THE MONEY WE HAVE SPENT ON THE GAME AND EQUIPMENT? AND WHY THEREFORE IS...more >>

URLScan
Posted by Kenny at 1/9/2008 6:50:57 AM
Hello, URLScan breaks the formatting of the IIS 5.0 logs by including a single space character in it's entry in the IIS log, for example, the following entry: /<Rejected-By-UrlScan> ~/ As each column in the IIS 5.0 log is delimited by the space character, I can find no way to load the II...more >>

Authentication Security Problem WSS and OWA - Possible Bug?
Posted by TomT at 1/8/2008 7:42:01 PM
Windows Server 2003 being connected to through Windows VPN using RMA. Shared remote Panasonic ToughBooks running XPP. generic Windows logon, VPN uses shared non-wss or exchange fake user, and once logged on users enter their user/password in IE logon window. The problem is that one or two...more >>

SSL 2.0
Posted by Smurfman at 1/7/2008 1:07:02 PM
What is the best practice for suring up the security related to IIS and the protocols that a website accepts? Thanks ...more >>

Cannot upload file - 501
Posted by Kevin at 1/7/2008 11:54:45 AM
Hi, First, I'm fairly new to using/administrating IIS. So, speak slow and in a clear voice ;-) I'm writing a mobile application (currently testing on a PC) where I need to send a potentially large file (up to 2MB) to the web server. The web server is IIS 5.1 on Windows Server 2003 R2 (SP...more >>

CERTSRV - error 500 internal server error
Posted by Vsevolod V Shevchuk at 1/6/2008 12:37:51 AM
Hello, dear all, I have a problem with IIS 6^ On domain server installed Windows Server 2003 R2 SP2. I installed Certification Authority few months ago. After that I installing some web applications (Sharepoint services) - and delete it. After that site http://<servername>\certsrv give me...more >>

infected IIS
Posted by Kevin at 1/5/2008 11:55:00 AM
I have a Windows 2003 server running Citrix. The server has been infected with a virus. I'm not sure what virus. I'm scanning now. What has happened is as follows: when I attempt to log on to the citrix server remotely, the normal login has been replaced with a website "discount pharmacy". ...more >>

Is possible to create CSRs for IIS 6 and use certs resulting wo "Organization Unit" ?
Posted by Rob at 1/3/2008 5:51:51 AM
Is possible to create CSRs for IIS 6 and use certs resulting wo "Organization Unit" ? Perhaps there is a registry hack or OS Policy change, or even if IIS 6 still uses a Metabase perhaps there is a way to tweak IIS to allow an empty field for "Organization Unit" which is optional on other serv...more >>


DevelopmentNow Blog