all groups > iis security > january 2008
Filter by week: 1 2 3 4 5
IIS 6 | Delegation | Netapp | CIFS
Posted by Ariel at 1/30/2008 10:49:01 AM
Hello,
I'm attempting to host a virtual directory that is a CIFS share on a Netapp.
I've setup the virtual directory to "Always use the authenticated user's
credentials when validating access to the network directory"
After reading:
"Deploying and Configuring Internet Information Servi... more >>
Permissions Help Needed
Posted by JTMZ at 1/29/2008 6:50:39 PM
I am an administrator on my own local box and am trying to access IIS
locally (not over the network).
If I goto my web app using http://localhost it works fine
If I goto my web app using http://machinename or http://127.0.0.1 or
http://TheValidIPAddress I get:
401.1 Access is denied due ... more >>
IIS6 - Can session id be manipulated?
Posted by Kim Hellan at 1/29/2008 12:59:41 PM
Hi,
I have gotten a question about how IIS6 handles the session id (cookie).
I've got a very persistent customer who claims, that you can just hijack
another session by changing the session id in your own session cookie.
I'm no security expert, but I find that very hard to believe. All though... more >>
IIS 5.1 SSL Cetificate Missing
Posted by Ming Dragon at 1/29/2008 12:08:00 PM
I recently did a system restore to recover from a driver installation
catastrophic failure for my ATi video. (System Restore is a real MONSTER in a
closet) In this process I ended up without an SSL Server Certificate for IIS
5.1. It installed fine when I built the machine and served its purp... more >>
'Error: Connection Error' when connecting to WSUS 3.0 (on IIS) via
Posted by Yuri GMT+1 at 1/29/2008 12:48:00 AM
Hi there,
I get the above error message when I try to open the WSUS 3.0 console on the
WSUS server (W2K3). It worked fine before.
The problem occurred when I was testing on this production server (stupid
me, I know, I know). I added tsweb for testing purposes on the same machine.
Normall... more >>
Windows authentication with FQDN
Posted by Rob at 1/28/2008 10:57:02 AM
Is there a way to pass windows authentication on while using a FQDN name
instead of regular server name while on the network/domain so as to not
prompt for credentials? Like when logging into http://computer.domain.com
instead of http://computer? It passes credentials properly when using jus... more >>
Access Denied
Posted by zz12 at 1/25/2008 5:20:13 PM
Hello, I have a domain user account which we've assigned it to the Local
Administrators group on a w2k3 server machine in trying to allow this user
to access and administrate the iis 6.0 manager. But when this user opens
the iis manager console and tries to expand the local machine name it
... more >>
Problems with writing to a file on IIS 6.0
Posted by sarika.koganti@gmail.com at 1/24/2008 2:52:31 AM
I have an ASP.Net application which accesses a web server hosted on
IIS. The web server creates a file in the application directory and
writes to it. My application needs to run on 2K, 2K3 and XP, i.e. IIS
5.0, 5.1 and 6.0.
I cannot use 'Inegrated Windows Authentication' (on my client's
request... more >>
Don't see what you're looking for? Search DevelopmentNow.com.
404 error when dowloading DLL files from IIS 6.0?
Posted by Usenet User at 1/22/2008 10:23:04 PM
Windows 2003 Server Standard SP1
IIS 6.0
ASP.NET 1.1
My ASP.NET page uses a client-side .NET control. The control is
implemented as a .NET assembly which is located in the virtual
directory root. This worked on IIS 5.0/Win 2000 server, bit IIS 6.0
refuses to serve the DLL file to the client ... more >>
Different web.config for Virtual Directories
Posted by Samuel at 1/22/2008 5:47:53 PM
Hi
I have two virtual directories, pointing to the same asp.net application. I
want to have different web.config files as I use different authentication
methods for those two virtual directories.
Is there a simple way to solve this? so that i can have different web.config
for each virtua... more >>
IIS to IIS using kerberos and non-standard web port
Posted by Pom at 1/22/2008 4:37:02 PM
I have implemented kerberos in 3 tiers environnmnet where IIS 6.0 access a
web services on a separate IIS server. I have properly setup all my SPNs,
service account etc.. and it work fine. My problem is I have a requirement to
run my webservices server on 8080 web port. I try every combination... more >>
Kerberos, SETSPN, GET & POST
Posted by raymond_b_jimenez@yahoo.com at 1/21/2008 1:41:28 PM
I have a web application that uses Integrated Windows Authentication.
Had been having a peculiar problem, where every request to the Web
server would give an 401 error, despite using HTTP/1.1 and the same
socket.
Discovered that having an application pool, I would have to register
it with SETSP... more >>
Internet Security and E-mail
Posted by low88deb@hotmail.cominvalid at 1/17/2008 9:07:02 PM
I'm not sure exactly what to ask so I'll just describe something that
happened I believe should be impossible.
There are only two people that access my computer: me and my husband. My
husband has been out of town for the last week. Today he found an e-mail from
me with a document attached t... more >>
IIS 6 und Kerberos
Posted by Tobia at 1/17/2008 4:42:34 PM
Hi!
I've a problem. I don't no it's my problem or a problem of IIS.
The scenario:
We have a member server with IIS in a W2K3 domain. There is only one website
on it, one Applpool, only one default.htm (simple HTML, no script).
Authentication isn't allowed anonym and Authentication methode is W... more >>
Change password popup window/option
Posted by JR at 1/17/2008 3:00:01 PM
I have an intranet setup on IIS 6.0. When users access it automatically
requires logon to proceed into the site. I want IIS to notify the users that
there password will expire within 12 days of expiring and give them the
option to change there password. I would also like IIS to allow the user... more >>
how long it took MS to come out with patch
Posted by tony at 1/17/2008 11:29:49 AM
since 2003 or the release of IIS6, there has been 3 advisories for IIS6
1. MS04-030 is a WebDAV XML vulnerability that could lead to DoS -
released 10/12/2004
2. MS04-034 is an ASP vulnerability that could lead to remote code
execution - released 7/11/2006
What was the tim... more >>
IIS on DMZ
Posted by tony at 1/15/2008 10:47:00 PM
how secure is it to have IIS 6 on dmz? do i need to be using apache web
proxy at all?
... more >>
IIS6 asp.net 2.0 and Verisign
Posted by Janet at 1/15/2008 1:53:06 PM
I'm investigating a Wildcard Verisign certificate for my server (intranet,
internet, special app websites). What I'm wondering about is forcing the
user to have 128bit encryption on the pages I've designated as https. If I
try to use "In the Secure Communications dialog box, click the Requir... more >>
Creating Virtual Directory on shared drive
Posted by vasimo at 1/15/2008 7:31:01 AM
Hi,
HELP!!!!!!!!!!!!!
XP Desktop with IIS 5 doing web class development. Virtual directories are
required for .Net apps.
Our root folder for the web site is located on a drive share.
I am trying to create virtual directories using VB script on all developer
machines.
The following creates... more >>
hiding IIS 6.0 signatures
Posted by tony at 1/14/2008 8:51:44 PM
How do i hide IIS 6 signatures from a scan or netcraft?
... more >>
Issue Digital Cert for NetBIOS name
Posted by Scott at 1/14/2008 7:06:03 PM
I'm using Certification Services on my W2K3 server, and wondered if it's
possible to issue a certificate to a NetBIOS name for the sake of
Internal/Intranet web page.
In other words, because the web server will never be access via the Internet
can I create a CSR and issue a .cer on a websit... more >>
Guest account with write and script execute access - how dangerous
Posted by Jeff Dunlap at 1/14/2008 6:46:01 PM
Dear IIS Users:
I would like to know is if the following configuration is secure from
hackers.
Assume that my application is at MyDomain/myPerlApp/cgi-bin/app.pl and that
this is my IIS configuration:
1) Removed anonymous authentication from myPerlApp and enabled Windows
Authentic... more >>
Access to Site Via WindowsMobile 2006 - Keeps asking for Password
Posted by Scooter at 1/14/2008 5:10:00 PM
We have a few Webs that dont seem to want Windows Mobile users access it.
The Windows Mobile users Range from WM2003, to WM5 WM6 using Sprint, AT&T,
T-Mobile and WiFi
THe Servers are Win2003R2 IIS6 latest Service Packs.
Running Some ASP.Net and Sharepoint (WSS3.0) Sites.
Both Sites Pro... more >>
ASP.NET 2.0 // IIS Authentication
Posted by Samuel at 1/14/2008 4:21:54 PM
Hi
I'm trying to build a kind of small intranet page. We have some Intranet
users which are member of the active directory, others which aren't.
The main idea is that the users can go to http://intranet and if they are
authenticated automatically, the just get the page content, if not, the... more >>
lockdown tool and IIS 6
Posted by tony at 1/14/2008 3:10:56 PM
Is it necesary to run IIS lockdown tool on IIS 6?
... more >>
C F S 3 THE END????????????????????????????????
Posted by sabredog at 1/12/2008 5:14:00 AM
WHATS GOING ON????? CFS3 HAS ENDED!!! THERE IS NO SERVER ANY MORE!!!
THIS CANT HAPPEN!! WE MUST STAND TOGETHER OVER THIS ISSUE AND FIGHT FOR THE
GAME TO RETURN!! IF THIS IS THE CASE AS IT NOW APPEARS TO BE SO WHAT ABOUT
ALL THE MONEY WE HAVE SPENT ON THE GAME AND EQUIPMENT? AND WHY THEREFORE IS... more >>
URLScan
Posted by Kenny at 1/9/2008 6:50:57 AM
Hello,
URLScan breaks the formatting of the IIS 5.0 logs by including a
single space character in it's entry in the IIS log, for example, the
following entry:
/<Rejected-By-UrlScan> ~/
As each column in the IIS 5.0 log is delimited by the space character,
I can find no way to load the II... more >>
Authentication Security Problem WSS and OWA - Possible Bug?
Posted by TomT at 1/8/2008 7:42:01 PM
Windows Server 2003 being connected to through Windows VPN using RMA. Shared
remote Panasonic ToughBooks running XPP. generic Windows logon, VPN uses
shared non-wss or exchange fake user, and once logged on users enter their
user/password in IE logon window.
The problem is that one or two... more >>
SSL 2.0
Posted by Smurfman at 1/7/2008 1:07:02 PM
What is the best practice for suring up the security related to IIS and the
protocols that a website accepts?
Thanks
... more >>
Cannot upload file - 501
Posted by Kevin at 1/7/2008 11:54:45 AM
Hi,
First, I'm fairly new to using/administrating IIS. So, speak slow and in a clear
voice ;-)
I'm writing a mobile application (currently testing on a PC) where I need to
send a potentially large file (up to 2MB) to the web server. The web server is
IIS 5.1 on Windows Server 2003 R2 (SP... more >>
CERTSRV - error 500 internal server error
Posted by Vsevolod V Shevchuk at 1/6/2008 12:37:51 AM
Hello, dear all,
I have a problem with IIS 6^
On domain server installed Windows Server 2003 R2 SP2. I installed
Certification Authority few months ago. After that I installing some web
applications (Sharepoint services) - and delete it. After that site
http://<servername>\certsrv give me... more >>
infected IIS
Posted by Kevin at 1/5/2008 11:55:00 AM
I have a Windows 2003 server running Citrix. The server has been infected
with a virus. I'm not sure what virus. I'm scanning now. What has happened is
as follows:
when I attempt to log on to the citrix server remotely, the normal login has
been replaced with a website "discount pharmacy". ... more >>
Is possible to create CSRs for IIS 6 and use certs resulting wo "Organization Unit" ?
Posted by Rob at 1/3/2008 5:51:51 AM
Is possible to create CSRs for IIS 6 and use certs resulting wo
"Organization Unit" ?
Perhaps there is a registry hack or OS Policy change, or even if IIS 6
still uses a Metabase perhaps there is a way to tweak IIS to allow an
empty field for "Organization Unit" which is optional on other
serv... more >>
|