Request Filtering - Denied Verbs are not logged consistently
I am running IIS 7.5. I have configured Request Filtering to NOT allow unlisted verbs and have listed just a few verbs I want to allow. My question has to do with how denied requests are logged. When...
View Articlewebdav issue
hi experts.<br> I have a problem with webdav and I hope I'll find solution here.<br> I set up the webdave in my site, then in my windows 8.1<br> everything work fine and I can access...
View ArticleGet Home error:... IIS
We get this error: i iis?Line 89846: 2015-04-21 15:01:15 46.254.16.99 GET /home/Lulu - 80 - 108.162.254.142...
View ArticleRun IIS 7 Without Admin
We have people that are using IIS 7 on a network account with local admin permissions, now IT want to remove all local admin permissions but that then mean people can't run IIS on their local...
View ArticleIIS Authentication Problems.... Which Authentication Method is Preferred for...
We have a Win2012 Server and want to have users Authenticate with their Active Directory account. Its Currently setup with Windows Authentication and NTLM.This works Most of the time with IE while...
View ArticleIIS Certificate authentication non domain joined device
Hi All,I'm trying to setup a IIS website with certificate authentication. I managed to do this with a domain joined device.But is it also possible with an iOS device? I imported the certificates. But...
View ArticleStrange Problem Renaming Some Files
We have a number of web sites that run ColdFusion that we have been migrating from Server 2003 to Server 2012 recently and have run into a problem with the ColdFusion code on one of the sites. We are...
View ArticleTwo questions about IIS permissions
Good day to you! And sorry for my English.I am using IIS for some time and now I noticed two things that looks strange for me. I tested it on clean Windows and I think that this is probably normal, but...
View ArticleWindows Server FTP - Block / Deny All IP's Except Allow Entries
I'm using Microsoft IIS FTP on Server 2012 R2. I need to configure the FTP IP Address and Domain Restrictions to deny all IP's except specific Allow Entries that I create.I've tried setting up several...
View ArticleIIS Encryption using RSA
I have a few questions regarding the encryption process. I am planning on implementing the encryption, and I know I'll be challenged on these items.1. What is the default RSA key size in IIS7.5?2....
View ArticleUpdating a config file using appcmd.exe question
We had a security audit and one of the items they identified using WebInspect is this:"IIS Missing Host Header Internal IP Address Disclosure. Apply the configuration changes described in Microsoft...
View ArticleVirtual Directory IP Security
Hi,I am trying to script up the creation of a website and its pretty much complete. However I have the need to restrict access to one virtual directory, which is fine and I have scripted this. However...
View ArticleWebsite failing to acquire proper permission to write to a folder under...
HelloI am having specific issues in regards to IIS 8.5, Permissions, and Auditing. I have a PHP application running under KanboardPool identity and I've properly set permssions on the application...
View ArticleDisabling sslv3 in 2012 r2 (iis 8.5) doesn't work
I cant disable sslv3 in my Server.sslv3 is disabled in registry and IIScrypto show me that it's disabled but any of scan sites show that sslv3 is still enabled.Does anyone have any idea why?Here are...
View ArticleIntegrated windows authentication - ASP.NET MVC app on IIS 7.5
Hi ,We are working on an ASP.NET website. We are using the windows login id of the user to authenticate the users. Now the website is being migrated to ASP.NET MVC5 and we are trying to host on IIS...
View ArticleIIS 7.5 Windows Authentication (NTLM) Fail with 401.3 15 minutes a day
I have setup the IIS website in windows 2008 R2 64bits server to allow user to get the file from UNC path.Setting:Only Windows authentication enabled (NTLM only).Path credentials : Application user...
View ArticleManaging .Net Authorization Rules with a powershell script
Hello,I'd like to simply add some .Net Authorization rules in IIS (7.5 / win 2008 R2) using a powershell script with PS snap in. So far I was able to add some "allow" rules but not any deny ones.Each...
View ArticlePHP SSO Service with Integrated Windows Authentication: Too Simple to be Secure?
Hey Everybody,I apologize if this is a silly question, but I'm totally new to the IIS world. I've worked with Apache and nginx before, but this is my first foray into Windows-based web servers. I'm...
View ArticleProblem with Client Certificates, iis7
Hi. I've gone crazy trying to figure this out. I have a Windows WebServer 2008 with IIS 7.0 where I have set up a test web site that mimics the IIS 6.0 site it is going to replace. This site uses...
View ArticleIIS 8.5 Authentication
I had a question about authentication with IIS 8.5. Let's say I have a website named example.com, and in the website I have two pages...one that is example.com/page1 and example.com/page2. I want the...
View Article