All Tagsauthenticationauthorization (RSS)
  • Authentication breaks

    My framework 4 asp.net app using forms authentication runs fine in Cassini and in IIS7.5 on the local box but on a public facing box with IIS7.5 in the DMZ (running cookieless session state) the authentication breaks without returning any error - the forms authentication simply does not work. I have...
    Posted to Forum by jakb on 11-16-2009, 5:09 AM
  • Directory Enumeration possible on Web Server

    Hi, My web application runs on Windows Server 2008 and IIS 7. During penetration testing, we found that it was possible to determine the existence of directories within the web root on the system through messages returned by the access control code. This could enable an attacker to target particluar...
    Posted to Forum by sunitha4ever on 11-10-2009, 1:22 AM
  • Forms authentication with roles page wont display error

    My web site has been modeled after the asp.net personel starter kit since it came out. I'm now running asp.net 3.0 and IIIS 7. I am trying to protect the web pages in a folder named Memberpages using roles.The role name Friends. Logging into my web site has allways gave me access to the Admin folder...
    Posted to Forum by jayirvin on 09-16-2009, 12:07 PM
  • Virtual Directory Issue

    Hi everyone, I'm new to this forum and look forward to learning more about IIS and it's members. I have a IIS 7 security problem ( at least I think it is a security issue) that have been trying to solve and create a virtual directory, yet unsuccessful!! I'm hoping to find the solution with...
    Posted to Forum by bosepehr@hotmail.com on 07-13-2009, 10:29 PM
  • What to do for a rootkit...

    I have recently found a rootkit on my computer through AVG and am wondering how to get this thing off. I tried to get AVG to delete it but it said it cannot. I heard you can re-install windows vista and also restore default settings but I am not sure if that deletes everything and I'll have to get...
    Posted to Forum by rgsnowman on 06-14-2009, 9:01 AM
  • Problem with IIS 7.0 and asp net session var

    Hello, I have a big trouble 'cause I have an asp net application and this application needs session vars, when I'm using windows xp and IIS 6 the application works preffectly, but in production with windows server 2008 and IIS 7 the session expires each 10 minutes, please help me, thanks and...
    Posted to Forum by raptor07 on 04-18-2009, 3:34 PM
  • Setup Integrated Windows Authentication like in IIS6

    I would like to password protect a website, where people have to enter a username/password (a windows account for example) to view the website. The website would then use its own authentication method (forms) to handle user accounts and decide whether or not to show member specific pages, etc. When the...
    Posted to Forum by jgeurts on 01-12-2009, 3:11 PM
  • Mixed Authentication: Windows OR Anonymous based on origin

    Is there a way to have IIS7 do different authentication on virtual applications based on rules like: * This request comes from this range of IP, so we do Windows Authentication here * This request comes from another range of IP so we use Anonymous Authentication here Filtering above could be based on...
    Posted to Forum by geschwint on 10-22-2008, 5:38 AM
  • Role Manager - IIS web.config vs .net 2.0 web.config

    G'day, I'm just trying to get my head around the syntax difference in my .net 2.0 web.config files when deploying to customers. I've had an issue with Forms authentication on IIS7, so I tried to revert to Windows Authentication and let the customers internal staff test the application. In...
    Posted to Forum by Jamie Clayton on 06-03-2008, 1:59 AM
Page 1 of 1 (9 items)
Microsoft Communities