Server Hardening breaks APPCMD?
At my job, I am taking on the role of doing .NET build & deploys. I did that at a previous job where the servers were Win2003 and my new boxes are Win2008R2SP1 but the new corporate standard has...
View Articleurlscan not logging any hits
Hi All: I have urlscan 3.1 runing on IIS7.5. I modified the URLScan.ini to log to a separate location "e:\urlscan".URLscan is writing a daily log file to that directory, but nothing's being logged. All...
View ArticleDynamic IP Restriction IIS 7.5
I have an IIS 'Farm' (two servers in a shared configuration) behind a load balancer. The servers are both running Windows Sever 2008 R2 and IIS 7.5. This is a hosted virtual (vmWare) environment.We...
View ArticleReg Vulnerability status
Hi,I am getting 'Microsoft Internet Information Services Remote DoS' vulnerability after scanning a prod server with IIS 6.0. Post installation of URLScan 3.1 in the server , will i get the...
View ArticleSSL Certificate Binding Disappearing For Team Foundation Server Site
I've got a dedicated Win 2008 R2 box with Team Foundation Server. The site is bound at 8080 to a specific IP address and 443 https for external access to the same IP address. port 8080 is blocked to...
View ArticleAllow file rename while it is being Uploaded, despite File Handling Settings.
Hi everyone.Problem description: Our propietary software is able to rename a file while it is being Uploaded by a user, despite "IIS File Handling Settings" that are all set to "False". This ends up...
View ArticleTroubleshooting access problems with Windows Authentication
I'm installing a web application on an IIS 7.5 server (Win Server 2008 R2) and having problems with windows authentication. I've done this install dozens of times but this one has me stuck, so any...
View ArticleKerberos Setup
Good day everyone,I am a Kerberos expert and I'm very well versed in how to set up Kerberos.I have a scenario with three servers now where other people are suggesting that Kerberos Authentication will...
View ArticleHTTP Error 500.19 - Internal Server Error in IIS 7.5
Hi Sir/Mam,Please help me with my IIS Settings as it is showing me error "The requested page cannot be accessed because the related configuration data for the page is invalid." and the detail message...
View Articlewindows 2012 server app pool permission changed
Here's something I do not understand.I recently moved my website to a Windows 2012 Server (Virtual Machine). I logged into the CMS of the website and executed an export button (which saves data from...
View Articleauthorization configuration in location path didn't take precedence over...
Hi all, Sorry for spam. I’m currently struggling with an authorization configuration for our service hosted upon IIS8.0. Basically we have a service site that has two endpoint entries: CertSvc.svc and...
View Articleanother windows auth question
Just moved a site from old win2k3 server to win2012 R2 (iis 8.5)The site uses windows authentication.Old server... automatically authenticates, no popup. New server... shows authentication popup. If...
View ArticleBest practice for locking down administrators
Hi,Some of my staff need to have access to IIS on our servers in order to create and manage websites. Unfortunately, for some reason, Windows Server 2008R2 does not allow gradual setting of IIS...
View ArticleIIS7 - Can I allow anonymous access on a folder of content but still have it...
In IIS7 mgmt console, if I select a folder under a website, I can then select "Authentication" and enable/disable Anonymous authentication. This affects just that folder correct?Im trying to figure...
View ArticleWindows Authentication Problem in ARR
I have two sites localsite.a,localsite.b ,But clients only know that localsite endpoint. I use iis application request routing metod to route these sites.I want to make windows authentication so I...
View ArticleWindows 2008 R2, Internet Information Services: Changing security settings to...
<div class="body">Hello, I would like to ask if somebody's there who could help me: I am a PHP developer from Stuttgart, Germany. In my PHP web application I want to edit text files...
View Article404.3 Denied by mime map
<configuration><connectionStrings><add name="StudentsConnectionString1" connectionString="Data Source=(LocalDB)\v11.0;AttachDbFilename=|DataDirectory|\Students.mdf;Integrated...
View Articlepenetration recommendations
Hello,I am looking into Penetration testing services. Can anyone recommend a good Pen test service? I know of Trustwave, does anyone have experience with them? Any suggestions are welcomed.Joe
View ArticleWhere to find Security section in IIS 7.5?
Hi Guys,Where can I find Security section in IIS 7.5? I was trying to tighten our IIS server security following these steps but I cant seem to find the Security section in our IIS. Any idea where to...
View ArticleRequestFiltering - Server Level
Hello..I have rules and other features configured at the website level for request filtering. I'd like to move these to the server level so it covers all websites configured within IIS.I added a couple...
View Article