| Thread | Last Post | Replies |
|
| IIS 6.0 leaks internal IP address in Content-Location header | 31 Jul 2006 12:14 GMT | 1 |
I have an IP leak problem running IIS 6.0 on W2K3 SP1. I have followed recomendations in KB218180 and KB834141 and configured SetHostName so that my websites do not return internal IP addresses. I have also configured host headers for
|
| Network service default permissions | 28 Jul 2006 22:11 GMT | 4 |
I was digging around the default permission for "network service" user and got myself quite confused. In the servers I've checked the default ACL permission on any new folder for this user is "Read & Execute","List folder contents" and "Read". However when I check the NTFS ...
|
| Application Pool Identity | 28 Jul 2006 11:06 GMT | 3 |
I am planning to host mulitple web site's on a single server with each web site/applicaiton being assigned a seperate applicaiton pool. For secutiry and auditing reasons I would like to assign each applicaiton pool a specific identity to for the worker process's to run under.
|
| always being prompted for username/password??!!?? | 27 Jul 2006 17:47 GMT | 2 |
hi there, this has got to be a complete noob questions but it is driving me insane. I have a win2k3 server box and winxp box on a network - very simple setup. win2k3 is dc, dhcp, dns, iis and winxp is client on this domain. everytime i attempt to view webpage on server from ie ...
|
| changing "CN" name | 26 Jul 2006 13:02 GMT | 5 |
I setup a CA server on Server 2003 (active Directory) with exchange. When I access exchange through Outlook from home, I get the error "The server you are connected to is using a security certificate that could not be verified and certificate's CN name does not match the passed ...
|
| User security? | 26 Jul 2006 08:14 GMT | 1 |
I have created a web service name "TestWS" using VS.NET 2 and published it to my SBS2003 server that uses IIS6 as a web server. I have set NO anonymous access to TestWS virtual directory and I have created a simple user account from the User template with the name of
|
| iis problems with some xp clients - kerberos issue? | 25 Jul 2006 23:30 GMT | 5 |
I'm the web dev for a 200 person company, everything herein is in our corporate domain. We use Kerberos authentication - the domain controler is a win2k server.
|
| IIS 5.0 vs IIS 6.0 | 25 Jul 2006 00:07 GMT | 3 |
I have an asp page that allows me to start and stop services on my windows 2000 server and run some batch files as well. Now that we are upgrading to windows 2003 this page is not working. I have changed the security parameters on IIS 6.0 but still I cant run my batch (I am using ...
|
| Microsoft URL Scan | 21 Jul 2006 03:53 GMT | 4 |
Our web servers run IIS5 and we also make use of the Microsoft URL Scan utility: (http://www.microsoft.com/technet/security/tools/urlscan.mspx). By default Microsoft's URL scan utility blocks a number HTTP Methods including "HEAD". We have a number of clients concerned that ...
|
| HTTP 405: The HTTP verb used to access this page is not allowed | 20 Jul 2006 21:32 GMT | 3 |
I started to get this error after I inserted tables into my index.htm page. I have a small form (username/password) that runs to a small .asp page which then redirect based on information provided. I read a couple of post regarding this situation and it talks about
|
| Integrated Windows Authentication results in -2146893052 (0x80090304) | 20 Jul 2006 04:56 GMT | 3 |
I have a website on Windows 2000 server with only IWA enabled. I can log into the site just fine, but if I type a bad password I get an HTTP 500 error. I can't figure out why I'm not reprompted for the password at least another time or two.
|
| - How to setup AD authentication when IIS in in the DMZ? | 20 Jul 2006 03:20 GMT | 1 |
I need to be able to access AD to authenticate users coming to a .NET application running on an IIS which is in the DMZ... Here are the details: My .NET app resides on a Win 2003 Server with IIS6 in the DMZ of the
|
| SSL warning message for Intranet site | 19 Jul 2006 02:11 GMT | 2 |
Hi, I have an intranet site that is set up using ssl 128bit encryption (using my own certificate server- windows 2003 server (so thats iis 6.0) The name i used set for the 'issued to' part is its fqdn
|
| suppressing http banner in IIS 6.0 | 18 Jul 2006 23:25 GMT | 2 |
I know you can suppress the ftp banner in IIS 6.0 - but how do you suppress the http banner from displaying the web version? I was able to do it back in IIS 5, but it no longer works in IIS 6.0 (W2K3 SP1). We usually get written up about this during Security Assessments but the
|
| Problem with Anonymous Access | 18 Jul 2006 15:35 GMT | 3 |
I have a new Windows 2003 server with IIS. I have set up the default web page with anonymous access. Everything works fine for a day, but something happens overnight and my anonymous access quits working. When I try accessing the site, I am asked for the user id, password, and ...
|