Home All Groups Group Topic Archive Search About

IIS Security

microsoft.public.inetserver.iis.security
Score Anonymous access Vulnerabilities
Jayhawktuba - 1 Apr 2005 10:59 PM - 5 messages
I am trying to dig up any documented issues where having IIS sites set for anonymous access causes the webs or server to be more vulnerable to attack. From what I can tell, if an attacker penetrated your firewall and got in, ...
Score Change in ASP.Net authentication between Win2000 and Win2003
Craig Banks - 1 Apr 2005 3:42 PM - 5 messages
We are in the process of migrating an intranet web server from a Windows 2000 box to a Windows 2003 box. In migrating OSs and from IIS 5 to IIS 6, we've noticed a significant difference in how Windows integrated security ...
Score IE browser "NO COOKIES" is ignored for 1 site; works for another; same scripts (Cross-posted to inet
l.woods - 1 Apr 2005 1:30 PM - 2 messages
This was cross-posted to inetserver.iss.  Sorry, but I HAVE to get an answer to this problem! I have a simple ASP stript that writes a cookie.  I have set IE to "No Cookies - Prompt".  I run the script from a site and I get the prompt.  This ...
Score Cannot renew certificate in Microsoft IIS 6.0
Fons Smit - 1 Apr 2005 6:07 AM - 1 message
Cannot renew certificate in Microsoft IIS due to the Organizational Unit fields being combined. IIS 6.0 is running on a Windows 2003 server. Symptom: Error: Invalid CSR Organizational Unit fields being combined Renewal Wizard generates renewal request that has all existing ...
Score W2003 SP1 - IIS CRL Check
Mark Pfeifer - 31 Mar 2005 8:52 PM - 4 messages
Can anyone tell me (as I didn't see it in the big list) if the CRL Checking Timeout option actually made it into SP1.  I remember reading a knowledge base document stating the IIS CRL check timeout would be added in SP1. ...
Score Re: IIS 6 CreateObject premissions issue
Cicero Galdino - 31 Mar 2005 12:53 PM - 1 message
Hi Yogita, After upgraded my web server machine to windows 2003, I tried the option #1 and #2 but my application didn't work. In my web server machine, the application works but if I try to access it by other machine the error:  ASP ...
Score How to configure IIS to use IAS?
dc3dog - 31 Mar 2005 3:22 AM - 1 message
How to configure IIS 6.0 in DMZ to use IAS to authenticate to W2K AD? or better to open ports on ISA 2000? Thanks for any info. ...
Score Re: Web Application cannot create folder in wwwroot\
N Thorell - 30 Mar 2005 7:41 PM - 1 message
Suddenly, today, I could not access anything on my local web. Not even a static html-page under the wwwroot.   I have spent the entire day troubleshooting. I wish there was a button to turn off all the security crap. It drives me ...
Score 405.1 error
j1c - 30 Mar 2005 7:39 PM - 4 messages
I have a site running on IIS 6 that uses Windows File Replication. I have set the permissions to allow anonymous and gave IWAM & IUSR read & execute perms. I am still however getting a 405.1 error. Any ideas? ...
Score IIS Admin Service - changing Logon account
fwrs - 30 Mar 2005 7:11 PM - 2 messages
Within IIS 6, I am trying to change the Logon account for all of the IIS services (IIS Admin, HTTP SSL, and WWW) from the Local System account to a custom account in the Administrators group. Whenever I try to start IIS ...
Score Executables won't run in IIS 5.1 on XP pro
rtrammell - 30 Mar 2005 3:53 PM - 4 messages
I'm having problems getting my executables to run in IIS 5.1.  I have moved my website from a Windows 2K server platform(where everthing runs perfectly) to a PC running XP Pro.  I have set up the website with the exact same ...
Score IIS and .NET State
dm4714 - 30 Mar 2005 3:37 PM - 3 messages
Hello -- I'm using IIS on four W2K3 servers in a network load balancing server farm. There is one back-end state server running the .NET State Server.  Each IIS server is configured with "StateServer" parameter pointing to the state ...
Score turn this off NTAuthenticationProviders : (STRING) "Negotiate,NTLM
sun - 30 Mar 2005 2:47 PM - 4 messages
I ran this on my IIS box and now no one can access any website on it. how to I undo this and get IIS back to it's default settings NTAuthenticationProviders : (STRING) "Negotiate,NTLM" ...
Score IIS 6.0 and Integrated Security - restricting logins
Sandy Wood - 30 Mar 2005 12:29 AM - 8 messages
I want to restrict user access to certain parts of my web site by creating local groups and adding those groups to the data folders that have the web content. Right now, when I create a new local user, and not add them to any ...
Score Re: New SSL Certificate not showing on browsers?
aqcccis - 29 Mar 2005 4:36 PM - 1 message
I'm running into the exact same problem on one of my servers. Just renewed the Certificate, and from within the MMC on the webserver I see that it thinks it's serving up the new certificate. But when you visit the site it give a Security Alert about using its expired cert. ...
Score Problems with IUSR after installing security templates
Raymond - 29 Mar 2005 8:31 AM - 2 messages
We have a webfarm with 6 webservers. Three of them run Win2k, the other three have recently been upgraded to Win2k3. After installing windows 2003, we applied the Windows 2003 Security Guide templates. ([link]). ...
Score IIS 5.0 Directory Settings help
TheSonOfKrypton - 29 Mar 2005 2:32 AM - 16 messages
I'm a college student and I've got my computer hosted by my university so that I can set up generally viewable websites and all that. Since I'm moving around a lot, I've set up RDC, but there are some times when ...
Score Install a certificate on IIS 4
totomaster - 28 Mar 2005 8:53 PM - 5 messages
Hi I want to install a web certificate for a site configured on IIS 4.0  This server is the last Nt4 in the network, all others servers are on Windows 2000 or 2003.  My enterprise CA is on a Windows 200 server. ...
Score IIS6 to block someone from sharing files
Backup - 28 Mar 2005 7:58 PM - 6 messages
I am looking for a way, perhaps with ISAPI filters, in IIS6 to block someone from sharing files / "porn" pic's under their website.  I have users with their [link] and they are hosting pics and files under their ...
Score AD user name changed, IIS still sees old user name
Aaron - 28 Mar 2005 7:49 PM - 5 messages
We have an ASP.NET application running on Windows Server 2003, using IIS 6.0, and integrated windows authentication with SQL Server 2000 on the back-end.  We store active directory user names in the SQL Server database for use in ...
Score DMZ access for internal and external users
Susan - 28 Mar 2005 2:27 PM - 2 messages
I need to put a 2003 Web Edition server on a DMZ, but it has to be accessible by both internal LAN users from multiple world-wide subnets and by Employees on the outside. I configured it on the internal LAN, then moved it to the DMZ, but I did not ...
Score Consuming ASP.NET Web Service
Thom Little - 27 Mar 2005 10:33 AM - 5 messages
I am trying to access the HelloWorld method compiled in one project using a consuming C# code-behind method compiled in a separate project. Both run on localhost.  The test drivers provided in Visual Studio .NET 2003 can invoke the method. ...
Next »