<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Search results matching tag 'administrator'</title><link>http://forums.iis.net/search/SearchResults.aspx?o=DateDescending&amp;tag=administrator&amp;orTags=0</link><description>Search results matching tag 'administrator'</description><dc:language>en-US</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>What to do for a rootkit...</title><link>http://forums.iis.net/p/1158419/1906905.aspx#1906905</link><pubDate>Sun, 14 Jun 2009 13:01:38 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1906905</guid><dc:creator>rgsnowman</dc:creator><cs:applicationKey>iis7_-_security--1</cs:applicationKey><description>&lt;p&gt;&amp;nbsp;I have recently found a rootkit on my computer through AVG and am wondering how to get this thing off. I tried to get AVG to delete it but it said it cannot. I heard you can re-install windows vista and also restore default settings but I am not sure if that deletes everything and I&amp;#39;ll have to get external hd and if the rootkit would get itself into there and I&amp;#39;d be re-installing a rootkit. This rootkit is screwing up my xps one it tiny ways, it changed all my security setting and turned my anti-viruses off and I can&amp;#39;t turn them back on, messed up background, screwed up start menu and toolbar, and the side panel. I just want to know the best way to get this off computer. Thanks in advance.&lt;br /&gt;&lt;/p&gt;</description></item><item><title>SQL Injection Attacks on IIS Web Servers</title><link>http://forums.iis.net/p/1149068/1868206.aspx#1868206</link><pubDate>Sat, 26 Apr 2008 03:41:33 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1868206</guid><dc:creator>bills</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;This thread will contain the latest information regarding&amp;nbsp;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyId=17&amp;amp;articleId=9080580&amp;amp;intsrc=hm_topic"&gt;recent&lt;/a&gt; &lt;a href="http://www.pcworld.com/article/id,145151-c,hackers/article.html"&gt;reports&lt;/a&gt; that have surfaced stating that web sites running on Microsoft’s Internet Information Services (IIS) 6.0 have been compromised. These reports allude to a possible vulnerability in IIS or issues related to &lt;a href="http://www.microsoft.com/technet/security/advisory/951306.mspx"&gt;Security Advisory 951306&lt;/a&gt; which was released last week.&lt;/p&gt;
&lt;p&gt;Microsoft has investigated these reports and determined that the attacks are &lt;u&gt;not&lt;/u&gt; related to the recent &lt;a href="http://www.microsoft.com/technet/security/advisory/951306.mspx"&gt;Microsoft Security Advisory (951306)&lt;/a&gt; or &lt;u&gt;any&lt;/u&gt; &lt;u&gt;known&lt;/u&gt; &lt;u&gt;security&lt;/u&gt; &lt;u&gt;issues&lt;/u&gt; related to IIS 6.0, ASP, ASP.Net or Microsoft SQL technologies.&lt;/p&gt;
&lt;p&gt;Instead, attackers have crafted an automated attack that can take advantage of SQL injection vulnerabilities in web pages that do not follow security best practices for web application development. While these particular attacks are targeting sites hosted on IIS web servers, SQL injection vulnerabilities may exist on sites hosted on any platform.&amp;nbsp; More information on SQL injection attacks can be found &lt;a href="http://msdn2.microsoft.com/en-us/library/ms161953.aspx"&gt;here&lt;/a&gt; and &lt;a href="http://msdn2.microsoft.com/en-us/library/bb671351.aspx"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Guidance from Microsoft for web application development best practices can also be found on &lt;a href="http://msdn2.microsoft.com/en-us/library/ms994921.aspx"&gt;this MSDN page&lt;/a&gt;. Best practices guidelines that developers may follow to mitigate SQL injection, can be located &lt;a href="http://msdn2.microsoft.com/en-us/library/ms998271.aspx"&gt;here&lt;/a&gt;. As we continue to make progress in our investigation on this attack, we will provide updated guidance and information on the &lt;a href="http://www.iis.net/"&gt;IIS.net&lt;/a&gt; site. For the latest information on this issue, please subscribe or visit the &lt;a href="http://forums.iis.net/p/1149068/1868206.aspx"&gt;IIS security forum&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For end-users, the investigation also shows no indication of an un-patched vulnerability in IIS, SQL Server, Internet Explorer or any other Microsoft client software, so we recommend customers apply the latest updates to be protected from these attacks.&lt;/p&gt;
&lt;p&gt;To further protect themselves from reported attacks, we encourage all customers to apply our most recent security updates to help ensure that their computers are protected from attempted criminal attacks. For more information about security updates, visit: &lt;a href="http://www.microsoft.com/protect"&gt;www.microsoft.com/protect&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;Anyone believed to have been affected can visit: &lt;a href="http://www.microsoft.com/protect/support/default.mspx"&gt;http://www.microsoft.com/protect/support/default.mspx&lt;/a&gt; and should contact the national law enforcement agency in their country.&amp;nbsp; Those in the United States can contact Customer Service and Support at no charge using the PC Safety hotline at 1-866-PCSAFETY.&amp;nbsp; Additionally, customers in the United States should contact their local FBI office or report their situation at: &lt;a href="http://www.ic3.gov/"&gt;www.ic3.gov&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;font face="Calibri" size="3"&gt;Subscribe to this thread, or check back later for the latest information from the community.&lt;/font&gt;&lt;/p&gt;</description></item><item><title>IIS 5.1 not manageable by non-Administrators?!</title><link>http://forums.iis.net/p/1148482/1865640.aspx#1865640</link><pubDate>Tue, 18 Mar 2008 17:34:11 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1865640</guid><dc:creator>Techie_Jones</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;I have a problem that has been killing my I.T. support team for some time now.&amp;nbsp; We are currently fighting off an internal development team that is pushing for local Administrator privileges for their staff.&amp;nbsp; Their contention is that they cannot run IIS 5.1 (XP Pro SP2) without having local Administrator privileges.&lt;/p&gt;
&lt;p&gt;Help!&amp;nbsp; I have not come across any built-in security groups or IIS-installed security groups to manage IIS 5.1.&amp;nbsp; This is frustrating.&amp;nbsp; In an effort to&amp;nbsp;delegate two main functions (IIS service restarting and the ability to view installed virtual directories) I have given Full Control NTFS permissions to C:\Inetpub and C:\Windows\System32\inetsrv and C:\Windows\System32\iisreset.exe to the Development Team.&amp;nbsp; No luck.&amp;nbsp; I have also added the Development Team to the Power Users group.&amp;nbsp; No luck.&lt;/p&gt;
&lt;p&gt;Has anyone seen this before.&amp;nbsp; I will happily accept ridicule, degradation and/or uncertain punishment if someone can please explain to me how to get around this - or better yet, WHY Microsoft has restricted this ability so.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;THANK YOU!&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Techie_Jones&lt;/p&gt;</description></item><item><title>Security Files for IIS6.0</title><link>http://forums.iis.net/p/1147053/1859594.aspx#1859594</link><pubDate>Thu, 22 Nov 2007 07:08:06 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1859594</guid><dc:creator>makeshn</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;Hi Everybody,&lt;/p&gt;
&lt;p&gt;For my project I need to collect all the security settings informations (key/value) for IIS6.0&lt;/p&gt;
&lt;p&gt;I want&amp;nbsp;to know&amp;nbsp;the list of IIS6.0 security related files&amp;nbsp;and their locations for both default as well as .Net. And also need to collect registry entries related to security settings for IIS6.0&lt;/p&gt;
&lt;p&gt;Reference URLs, Books also welcome.&lt;/p&gt;
&lt;p&gt;Thanks in advance.&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Makesh&lt;/p&gt;</description></item><item><title>Cannot able to login the Application</title><link>http://forums.iis.net/p/1144424/1849371.aspx#1849371</link><pubDate>Tue, 14 Aug 2007 13:50:03 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1849371</guid><dc:creator>rakeshvarma21</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;Hi, iam getting a problem and need some help.&lt;/p&gt;
&lt;p&gt;I installed .net application in windows 2003 server and IIs6.0, the file server is located in another server.&amp;nbsp;Under security Iam giving&amp;nbsp;&amp;nbsp;full permissions to Network Service for that shared folde. the error iam getting is &amp;quot;&lt;strong&gt;Temporary location path is not accessible. Please Contact your Administrator&lt;/strong&gt;&amp;quot;. If i give permission to everyone it works fine, or if i give permission to Domain Computers or only that particular system name i can login, but i don&amp;#39;t want to give permissions to that users coz those are not secured.&lt;/p&gt;
&lt;p&gt;I found where the error is occuring exactly, its just my expection.&lt;/p&gt;
&lt;p&gt;when i right click the folder click on properties and security tab&amp;nbsp;and Advanced button Advanced Security Settings window will appear, under that in permission entries Network Service is in Inherited form with full permissions and it applies to this folder only. I want to change it to this folder,subfolders and files but when click on edit buttion that feature is disabled. If i uncheck the inherit and set the permissions to this folder,subfolders and files and again check the inherit another Network user is adding&amp;nbsp;and under inherit form &amp;quot;not inherited&amp;quot; message is displaying. the parent object i mean&amp;nbsp; Network service user does not change. I want to change that parent object and set the permnission to the folder,subfolders and files.&lt;/p&gt;
&lt;p&gt;So can any one help me in this....&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Rakesh.&lt;/p&gt;</description></item><item><title>Recovering IIS Password</title><link>http://forums.iis.net/p/1133316/1802847.aspx#1802847</link><pubDate>Fri, 13 Jul 2007 17:31:29 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1802847</guid><dc:creator>kkevlar14</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;p&gt;We have a server that runs IIS 5.0.&amp;nbsp; Unfortunately, when we try to access&amp;nbsp;IIS it says that we do not have sufficient priveledges to access it and gives us a dialog to enter a username and password.&amp;nbsp; We have tried logging in with all the logins and passwords that we know, but nothing is working.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Is it possible to recover a lost password?&amp;nbsp; Do I just need to give one of the users sufficient priveledges, and if so, how?&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Thanks in advance,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Ken&lt;/p&gt;</description></item><item><title>IUSR account - Administrator rights?</title><link>http://forums.iis.net/p/1100589/1671872.aspx#1671872</link><pubDate>Wed, 18 Apr 2007 22:05:42 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1671872</guid><dc:creator>subterfuge</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;P&gt;We had a .NET (1.1) application installed on a webserver by a third party on a Windows Server 2003 SP2 server.&amp;nbsp; What I've discovered is that in order to get their application to work properly, instead of tracking down all the permissions errors for their application, they&amp;nbsp;made the ASPNET and IUSR account part of the local administrators group on the webserver.&lt;/P&gt;
&lt;P&gt;Is this ok?&amp;nbsp; Everything about this screams security risk, but I need some hard evidence that this is completely and totally wrong..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description></item><item><title>SharePoint (WSSv2) local restricted account users get 401.5 or repeated 401.1/2</title><link>http://forums.iis.net/p/1100041/1669895.aspx#1669895</link><pubDate>Tue, 17 Apr 2007 21:49:05 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:1669895</guid><dc:creator>ACrush</dc:creator><cs:applicationKey>security--1</cs:applicationKey><description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;Got a problem here.&lt;/P&gt;
&lt;P&gt;Having installed and configured an intranet SharePoint v2 on a server with &lt;U&gt;local user accounts&lt;/U&gt;, I showed everything to the &lt;U&gt;site administrators&lt;/U&gt; and everything worked fine using &lt;U&gt;Windows Authentication&lt;/U&gt; with &lt;STRIKE&gt;Anonymous&lt;/STRIKE&gt; turned off. However, the &lt;U&gt;restricted users&lt;/U&gt; have to &lt;U&gt;repeatedly enter&lt;/U&gt; their &lt;U&gt;credentials&lt;/U&gt; every time they access any SharePoint &lt;U&gt;item, list or library&lt;/U&gt; within a &lt;U&gt;single session&lt;/U&gt;. When a user has entered their username/password correctly at least once per site, they can press &lt;STRONG&gt;Cancel&lt;/STRONG&gt; in the logon box which helps get to the content more quickly. The IIS logs show ISAPI authentication errors when trying to GET /_vti_bin/&lt;U&gt;owssvr.dll&lt;/U&gt; (&lt;U&gt;401.5&lt;/U&gt;) for users running&amp;nbsp;&lt;U&gt;Internet Explorer&amp;nbsp;6 SP1&lt;/U&gt; and alternating &lt;U&gt;401.1&lt;/U&gt; / &lt;U&gt;401.2 &lt;/U&gt;when trying to get any /Lists/List/view.aspx followed by code 200 if the user has enough persistence or impatience to either repeatedly enter their password or hit Cancel in despair. Filemon shows that all file requests at the time of 401's return with success, so probably NTFS permissions are not to blame.&lt;/P&gt;
&lt;P&gt;The server local&amp;nbsp;restricted users granted the right to &lt;U&gt;manage site&lt;/U&gt; separately or by inclusion in the &lt;STRONG&gt;Administrator&lt;/STRONG&gt; &lt;U&gt;site group&lt;/U&gt; do not experience this problem - they authenticate once and continue working normally as expected.&lt;/P&gt;
&lt;P&gt;This post is not about automatically authenticating users without asking for credentials even once (save the local machine logon), but rather helping them to use SharePoint without this annoyance.&lt;/P&gt;
&lt;P&gt;Any help finding the solution without employing AD would be appreciated. Authentication methods other than Windows Authentication are disabled.&lt;/P&gt;
&lt;P&gt;Thanks in advance, &lt;/P&gt;
&lt;P&gt;&lt;EM&gt;ACrush&lt;/EM&gt;&lt;/P&gt;</description></item></channel></rss>