Published by

Comments

# TrackBack said on 24 October, 2003 11:59 PM
# TrackBack said on 11 November, 2003 06:35 PM
# bernard said on 21 November, 2003 09:24 AM
BB,??,??????blog?,?? ???? ??
# bernard said on 21 November, 2003 09:26 AM
Hi BB,i found you blog :)
# bernard said on 23 November, 2003 10:43 PM
haha.. thanks ceocio... I got one here and one with Joy - MVP china.
# bernard said on 02 December, 2003 09:49 PM
:)
# bernard said on 02 December, 2003 09:50 PM
i found you on IISFAQ.com too.
# bernard said on 08 December, 2003 12:23 PM
Err what do you mean by found me in iisfaq.com ?

# bernard said on 09 December, 2003 11:18 AM
??
# bernard said on 11 December, 2003 12:07 PM
This one is fresh... 10/12/03 -
How To Configure PassivePortRange In IIS
http://support.microsoft.com/?id=555022
# bernard said on 24 December, 2003 05:31 PM
ok,??it
# bernard said on 30 December, 2003 12:08 PM
Update - this
IIS 6.0 Does Not Serve Dynamic Content
http://support.microsoft.com/?id=555019

has been removed due to duplication.
# TrackBack said on 30 December, 2003 12:35 PM
# bernard said on 30 December, 2003 12:59 PM
so nothing to worry ? I have urlscan in my Iis server.
# bernard said on 05 January, 2004 08:46 AM
it should be fine as I mentioned before.
# TrackBack said on 13 January, 2004 02:22 PM
# bernard said on 13 February, 2004 12:17 AM
Found your page while using Yahoo. I am currently working on a project related to this, and found it helpful. Thanks!
# bernard said on 13 February, 2004 12:18 AM
Found your page while using Yahoo. I am currently working on a project related to this, and found it helpful. Thanks!
# bernard said on 16 February, 2004 09:57 AM
Sure.. but pls stop advertising... your product :)
# TrackBack said on 21 February, 2004 08:06 AM
# TrackBack said on 29 February, 2004 08:55 PM
[MVP][KB] IIS KBs
# bernard said on 29 February, 2004 08:57 PM
Hi. Pls do not forget to mention about tools that can be downloaded. :D
http://www.microsoft.com/downloads/details.aspx?familyid=56FC92EE-A71A-4C73-B628-ADE629C89499&displaylang=en

--
Kenji Yamamoto [Security; Windows Server Systems]
http://msmvps.com/yamaken/
# bernard said on 01 March, 2004 06:54 AM
Cool ! Thanks for blog posting :)
# bernard said on 01 March, 2004 06:55 AM
Hhaha.. Of coz.. it's in the download section.
# bernard said on 02 March, 2004 02:39 PM
Hi. It seems the "XML" page on the left upper side is somewhat having trouble. A SQLMVP, Mitsugi Ogawa has reported this to me.
Pls look into it. He said when loaded w/ RSS bandit, bandit says an error occured during the XML parsing phase.
# TrackBack said on 02 March, 2004 05:53 PM
Microsoft's Fast facts and key events....
# TrackBack said on 02 March, 2004 05:54 PM
Book - IIS 6 Administration
# TrackBack said on 02 March, 2004 06:00 PM
Checklist: Securing Your Web Server
# TrackBack said on 02 March, 2004 06:04 PM
2004 ? 3 ?: IIS ?? WebCasts
# bernard said on 03 March, 2004 01:20 PM
Thanks Kenji :) .. my feedreader didn't pick up the error. It's fixed now.. thanks again.
# TrackBack said on 04 March, 2004 02:17 PM
SQL2k Book Online Update 2004
# TrackBack said on 04 March, 2004 02:17 PM
Microsoft IIS Links
# TrackBack said on 05 March, 2004 04:11 AM
SQL2k Book Online Update 2004
# bernard said on 12 March, 2004 10:02 PM
BB?????????KB??
# TrackBack said on 14 March, 2004 08:27 PM
[KB] IIS KBs - by MVPs
# TrackBack said on 22 March, 2004 09:56 PM
Windows XP SP2 RC1 is now available to everyone
# TrackBack said on 22 March, 2004 10:02 PM
Windows XP SP2 RC1 is now available to everyone
# bernard said on 31 March, 2004 06:06 AM
user
# bernard said on 01 April, 2004 10:49 AM
I just been told by MS that these documents will be updated soon and local help file will be updated with Windows Server 2003 SP1.
# TrackBack said on 01 April, 2004 11:56 AM
# bernard said on 01 April, 2004 09:01 PM
Hmm, I cannot get rfeed push the postings at my server... It seems I have to look at this stuff more...
# bernard said on 01 April, 2004 10:30 PM
Hi All

We've actually fixed the FTP User Isolation information in the IIS 6.0 Resource Guide (now called the Technical Reference) which is FREE online (see the enclosed link). With SP1, the online Help for FTP User Isolation points users directly to the Resouce Guide.


Thanks,
-Jim (IIS Technical Writer)
# bernard said on 01 April, 2004 10:32 PM
Really adding the link this time:

http://www.microsoft.com/resources/documentation/IIS/6/all/techref/en-us/iisRG_CFG_21.mspx

# bernard said on 02 April, 2004 10:37 AM
'IIS 6 Comprehensive Resource Guide' is now changed to

IIS 6.0 Technical Reference:
http://www.microsoft.com/resources/documentation/IIS/6/all/techref/en-us/default.mspx

Thanks to Jim [MS]
# bernard said on 02 April, 2004 10:38 AM
Hi Jim,
Thanks for the update.

# bernard said on 02 April, 2004 10:45 AM
Hi YamaKen,

This is a test I do with GTEC's engineer -
D:\WINDOWS\system32\inetsrv>cscript rfeed.vbs -t a -r sha-colin-1000 -f peer -i 2 -oa push -on * -ox 5 -oz true -op 128

Microsoft (R) Windows Script Host Version 5.6
Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.

Successfully added the following feed:
Remote server: sha-colin-1000
Feed type: Peer
Outbound feed properties:
Feed ID: 44
Action: Push
Enabled: True
Path header (Uucp name):
Process control messages: True
Authinfo account:
Maximum connection attempts: 10
Interval (minutes): 5
Outgoing port: 128
Temp Directory:
Newsgroups: *

-----
If you successfully configured the feed, you see the Feed ID and its detail, if you got blank response after you run your rfeed script, it mean the newsfeed setting is not accepted by server.

# bernard said on 30 April, 2004 08:40 AM
There are some known issues with MS04-011, please refer
http://support.microsoft.com/?kbid=835732
# bernard said on 05 May, 2004 12:09 PM
UPDATE (05/04/2004):
- This alert is being updated to advise you of an update to Microsoft Security Bulletin MS04-011. This update details additional workaround steps which customers can take to protect against the LSASS vulnerability (CAN-2003-0533). This is the vulnerability which is exploited by the Sasser worm and its variants. Customers who have not yet deployed the security update for MS04-011 can evaluate implementing this new workaround to protect against the Sasser worm and its variants.

- In addition, Microsoft has updated the cleanup tool for W32.Sasser.worm to remove the C and D variants of the Sasser worm. The Sasser removal tool now removes Sasser A, B, C and D. The updated removal tool is located at http://www.microsoft.com/downloads/details.aspx?FamilyId=76C6DE7E-1B6B-4
FC3-90D4-9FA42D14CC17&displaylang=en and is documented in Knowledge
Base article KB841720
http://support.microsoft.com/default.aspx?scid=kb;EN-US;841720.

What is this alert?
- Microsoft has been made aware of a worm identified as "W32.Sasser.worm" and it is currently circulating on the Internet. The worm exploits the Local Security Authority Subsystem Service (LSASS) vulnerability fixed in Microsoft Security Update MS04-011 on April 13, 2004.

- Microsoft encourages customers to protect themselves against this worm by installing Microsoft Security Bulletin MS04-011 <www.microsoft.com/technet/security/bulletin/ms04-011.mspx> immediately.

- Customers who have enabled the Windows XP Firewall are protected from the vector this worm attacks, which is TCP Port 139. Most third party firewalls also block this attack vector by default.

If you have any questions regarding the security updates or its implementation after reading the above listed bulletin you should contact Product Support Services in the United States at 1-866-PCSafety (1-866-727-2338). International customers should contact their local subsidiary.

--------
And the removal tool is now on WindowsUpdate

# TrackBack said on 06 May, 2004 07:50 AM
# TrackBack said on 06 May, 2004 07:50 AM
# TrackBack said on 06 May, 2004 07:50 AM
# TrackBack said on 06 May, 2004 08:01 AM
# TrackBack said on 06 May, 2004 08:01 AM
# TrackBack said on 06 May, 2004 08:01 AM
# TrackBack said on 06 May, 2004 08:01 AM
# TrackBack said on 09 May, 2004 04:04 PM
??: IIS 6.0 NNTP ???????????????
# TrackBack said on 09 May, 2004 04:05 PM
??: IIS 6.0 NNTP ???????????????
# bernard said on 09 May, 2004 04:10 PM
Cool. I think I am gonna get this book!
# TrackBack said on 09 May, 2004 04:12 PM
Book - CYA Securing IIS 6.0
# TrackBack said on 09 May, 2004 04:12 PM
Book - CYA Securing IIS 6.0
# bernard said on 11 May, 2004 12:59 PM
Thanks, It's coming out to local store in few weeks time.
# bernard said on 11 May, 2004 08:13 PM
Is it doable for IIS6?
# bernard said on 12 May, 2004 08:22 AM
I love U baby!!!!I need this very soon!
# bernard said on 12 May, 2004 10:26 AM
Yes, all the above I believe work with IIS 5 and IIS 6.

IIS 4.0 ? what ? you still have NT 4 :) ... I believe the ftp fix apply to IIS 5.0 and above. though you still able to hide HTTP with urlscan and etc.
# bernard said on 18 May, 2004 11:13 PM
I can't help myself. You have a double negative, "...you can’t never login...". Since two negatives make a positive, you are saying that you CAN log into a FTP server with a windows FTP account.

Despite this, I still enjoy reading your weblog.
# bernard said on 19 May, 2004 01:09 PM
Thank you. You sound like my authoring editor :) My bad, I will correct it. Cheers.
# bernard said on 20 May, 2004 04:26 PM
http://securityadmin.info/faq.asp#banner has some links to some other items that people wishing to hide their banners or OS information should consider.

You can see from the link above that I am lukewarm on the benefits of hiding banners. But while it is true that security through obscurity is not by itself effective, it can still be a worthwhile pursuit in combination with other countermeasures. After all, some hackers do still attempt system enumeration before attacking.
# bernard said on 22 May, 2004 02:19 PM
Cool to know that FTP banner issue is fixed.
So as you know there will be NNTP that is remaining...

By the way, from RC2 on, as for POP3 service you can modify the strings via registry.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Pop3 Service\Greeting

# I have been informed of this by Alex Feinman. He has been a geek of Whistler for quite a long time, too. ;-)
# bernard said on 22 May, 2004 02:27 PM
Ah, forgot to mention.

As you know, there are other two header fields of W3SVC, which are well-known.

We need to modify realm and content-location. ;-)

1. the Content-location header field
See the KB 218180...

2. realm (esp. for the basic auth.)
Likewise edit the following entry in the metabase.

cscript C:\inetpub\adminscripts\adsutil.vbs set w3svc/(the num. of the virtual site)/realm (strings to show)

# TrackBack said on 22 May, 2004 02:50 PM
KB: IIS Banner removal ????????
# TrackBack said on 22 May, 2004 02:52 PM
KB: IIS Banner removal ????????
# bernard said on 25 May, 2004 08:48 AM
Thanks Karl and Kenji ! Great stuff indeed. I will start part two right away :)
# TrackBack said on 25 May, 2004 09:21 AM
# bernard said on 25 May, 2004 11:16 PM
Hey Bernard,

Check this out :

http://www.theregister.co.uk/2004/05/25/comcast_ms_deal/

Regards,

Paul Lynch
# TrackBack said on 26 May, 2004 09:07 AM
# TrackBack said on 26 May, 2004 09:14 AM
# bernard said on 26 May, 2004 09:20 AM
Congratuations!
# bernard said on 26 May, 2004 11:52 AM
Bravo !! Will get one asap.
# bernard said on 26 May, 2004 11:54 AM
Happy to see you are published in some serious context, maybe MS should read the book and learn a thing or two... Congratulations man

B
# bernard said on 26 May, 2004 12:33 PM
Congratulations Bernard! You make us all proud Malaysians. Hazman
# bernard said on 26 May, 2004 12:39 PM
Congrats !!
# bernard said on 26 May, 2004 01:43 PM
congratulations!!
# bernard said on 26 May, 2004 02:13 PM

Thanks everyone :)
Also thanks to community members in .cn newsgroups, CSDN - http://expert.csdn.net/Expert/topic/3106/3106218.xml?temp=.5059931, MIND - http://www.mind.com.my/mind/forum/AspNetForums/ShowPost.aspx?PostID=29463, Joycode - http://blog.joycode.com/ff/posts/22650.aspx
# bernard said on 26 May, 2004 03:50 PM
Thanks Hazam.
# bernard said on 26 May, 2004 08:59 PM
Congratuations!
# TrackBack said on 27 May, 2004 03:48 AM
# bernard said on 27 May, 2004 04:30 AM
Congratulations,teacher BB~~
HaHa~~
# bernard said on 27 May, 2004 07:29 AM
Congratuations!
# bernard said on 27 May, 2004 07:48 AM
Thanks for the link, Paul. I'm just very interested to see how IISLockdown work on the TV Platform, and from my guess it is still using IIS 5.0.
# TrackBack said on 27 May, 2004 08:22 AM
# bernard said on 28 May, 2004 05:45 AM
Congratulations!
# bernard said on 03 June, 2004 08:57 AM
Congratulations!
# bernard said on 04 June, 2004 03:20 PM
best thing about it is spymac provides pop3 based service so your outlook express or the ximian evolution can get all the mails from the spymac servers.
# TrackBack said on 07 June, 2004 01:22 PM
# bernard said on 09 June, 2004 12:14 PM
Bernard, Congratulations^10! You are the champion! :)
# bernard said on 10 June, 2004 12:02 PM
And then there is the obvious component that the number of vulnerabilities can be further reduced by the fact that some of the 21 W2K3 vulnerabilities just do not apply to an IIS 6.0 Server maintained by anyone with sound mind and judgement.

As far as the 22 IE vulnerabilities, how long has it been SOP not to perform casual web browsing from a production server?
# TrackBack said on 10 June, 2004 01:01 PM
# bernard said on 10 June, 2004 09:26 PM
Kudos on a well written post :)

Security is the sum of all the parts and it's only as strong as it's weakest link.

IIS 6.0 (which is yet to have it's first security release) is [b]VERY SECURE[/b]. It represents the fruitition of MS's efforts in strengthening it's security products.

Russ is somewhat correct, in that to build a secure MS Internet or Intranet server, you need to consider all the parts (Windows, IE, etc), and thus you can arrive at dozens of required patches. Still, IIS is just a part and saying that [b]it[/b] has the number of vulnerabilities Russ identified is misleading.

Respectfully, Harry
# TrackBack said on 11 June, 2004 04:49 PM
# bernard said on 11 June, 2004 11:24 PM
Just a quick note in passing on the item "PCT Vulnerability - CAN-2003-0719" - PCT is not enabled by default on Windows Server 2003, and it's difficult to imagine too many situations where an admin would enable it. For the vulnerability to work, PCT would have to be enabled - enabling SSL is not enough.
# bernard said on 12 June, 2004 07:53 PM
Cool. I didn't know that. Thanks Alun.
# TrackBack said on 14 June, 2004 11:07 AM
re: [Secur] KB:834141 FIX: IP address is revealed in the content-location field in the TCP header in IIS 6.0
# bernard said on 19 June, 2004 12:58 AM
Grat article with lots of good info. I would like to script (adsutil.vbs) the change so IIS won't "Send detailed ASP error messages to client" (Default Web Site|Home Directory|Configuration|Debugging Tab). What value do I set in the metabase (AspScriptErrorSentToBrowser)?
Thanks,
# bernard said on 21 June, 2004 10:47 AM
Hi Ray,
Just set it to false, and set AspScriptErrorMessage for the error msgs.
# bernard said on 27 June, 2004 03:03 AM
Latest KB article about the exploit -
Internet Information Services (IIS) 5.0 – Download.Ject Detection and Recovery Advisory
http://support.microsoft.com/?id=871277
# bernard said on 28 June, 2004 02:49 PM
More detail -
http://www.microsoft.com/presspass/press/2004/jun04/0625download-jectstatement.asp
# bernard said on 01 July, 2004 05:56 AM
Further information
# bernard said on 01 July, 2004 10:59 AM
Thanks.
# bernard said on 02 July, 2004 11:36 PM
Latest Microsoft's response:
Microsoft has released a configuration change that addresses the recent malicious attack against Internet Explorer known as Download.Ject.

In addition, Microsoft has released a Knowledge Base article, 870669, that provides information that administrators can use to implement this change manually in their environment and to deploy the change across
their networks. This Knowledge Base article is available here:

http://support.microsoft.com/?id=870669

Customers are advised to review the information in the Knowledge Base article, test and deploy the change immediately in their environments, if applicable.
# bernard said on 10 July, 2004 11:35 AM
3ks
# bernard said on 14 July, 2004 11:41 AM
Hi everyone,

You can't download IIS 6.0. IIS 6.0 only comes with Windows Server 2003, it's not a standalone downloadable package. Read - http://msmvps.com/bernard/archive/2004/07/14/10083.aspx

Regards,
Bernard
# bernard said on 15 July, 2004 02:44 AM
Funny you should post this blog entry --- just added a similar thing to my FAQ section as I get at least 10-20 emails a week asking where they can download IIS...
# bernard said on 15 July, 2004 06:20 PM
IIS 6.0 Download
# bernard said on 16 July, 2004 11:44 AM
LOL :) Even after this post, I'm still getting 10+ requests per day... Google 'IIS 6 Download', that post was on the right spot :)
# bernard said on 16 July, 2004 02:28 PM
Yeah - I noticed that you are way up there for the IIS 6 Download search in Google... Nice job man!

# bernard said on 19 July, 2004 01:22 AM
Well, we (including you and me) do not need to know what we do not really need, but must know what we need, what we are using, and what we are going to use.

IN my opinion network admins and server admins should know at least how to use the 75 tools, if really in need.

At least we have ours in each of our toolboxes. I am going to show off mine, so pls keep on checking my blog. ;-)
# bernard said on 21 July, 2004 10:55 AM
:) can I start selling banner now ?
# bernard said on 21 July, 2004 10:58 AM
Agreed. Well, your list up yet ?
# bernard said on 21 July, 2004 12:25 PM
Take a look at: http://blogs.sqlpassj.org/yamaken/archive/2004/07/21/3456.aspx

Enjoy!
# bernard said on 25 July, 2004 01:59 AM
http://www.microsoft.com/downloads/details.aspx?FamilyID=56fc92ee-a71a-4c73-b628-ade629c89499&displaylang=en
# bernard said on 25 July, 2004 01:29 PM
Hi, The url link is for IIS6.0 Resource kit, not IIS 6.0 server, as I mentioned before, you can only get IIS6.0 with Windows Server 2003, it's part of OS, no separate downloads.
Cheers.
# TrackBack said on 28 July, 2004 10:50 PM
# TrackBack said on 28 July, 2004 10:52 PM
# bernard said on 29 July, 2004 12:48 AM
on the link you provide, it still says IISState v.3.3.1 everywhere on the page...
# TrackBack said on 29 July, 2004 06:56 AM
# bernard said on 29 July, 2004 10:30 AM
Hi Julie,
Yes, 3.3.1 is the latest. When it's released, I were told 3.4. but the fact is 3.3.1 :) Sorry about the confusion.

Cheers.
# bernard said on 02 August, 2004 12:55 PM
Bulletins Update -

********************************************************************
Title: Microsoft Security Bulletin Re-release, August 2004
Issued: August 1, 2004
********************************************************************

The following bulletin has undergone a major revision increment.
Please see the appropriate bulletin for more details.

* MS04-025

http://www.microsoft.com/technet/security/bulletin/MS04-025.mspx
Reason for re-release: Bulletin updated to reflect availability of a new version of the update for Windows XP customers running Windows Update Version 5.

Originally posted: July 30, 2004
Updated: August 1, 2004
Version: 2.0
# bernard said on 19 August, 2004 05:31 PM
Why hate Microsoft?
# bernard said on 19 August, 2004 05:32 PM
Where Download this book?
# bernard said on 19 August, 2004 05:34 PM
You have to buy it :)
# bernard said on 19 August, 2004 05:35 PM
Why?
# bernard said on 30 August, 2004 03:23 PM
Give me
# bernard said on 03 September, 2004 04:06 PM
i want to download iss server 3.0
# bernard said on 11 September, 2004 01:34 AM
Thanks for the help, the CName info is what i've been missing. I don't have a CName for my default website and it works fine. Why do i need one for each additional website i host with IIS 6.0/Win2003
# bernard said on 11 September, 2004 09:32 PM
CNAME is just an type of DNS record, if you using A (host) record, it will works too. As long as the name resolution is pointing to the configured IP address specified in the website settings, it should be fine.
# bernard said on 20 September, 2004 09:29 AM
All loopback address except 127.0.0.1?
I thought it was done on purpose. Is one address not enough?
# bernard said on 20 September, 2004 11:52 AM
Yes, but some programs might depend on other addresses. This is what had happen and MS is providing this fix, if you 'like' to remove this restriction.
# bernard said on 23 September, 2004 08:11 PM
Want to know about ISS
# bernard said on 25 September, 2004 05:29 AM
We need other addresses on the loopback adapter when we deploy some common configurations concerning load-balancing using load-balancers like BigIP (F5), ServerIron(Foundry), or Alteon.
(I am thinking about the patterns of DSR:Direct Server Response...)
# bernard said on 25 September, 2004 11:42 AM
Arigato tomo yo :)
# bernard said on 27 September, 2004 10:26 PM
I tend to install the Loopback Adapter and bind to that. It also means that,on my laptop, I can bind Virtual PC images to it too and have them all communicating without touching the network at all.
# TrackBack said on 28 September, 2004 11:26 PM
# TrackBack said on 29 September, 2004 07:01 AM
# bernard said on 29 September, 2004 02:40 PM
renzhe
# bernard said on 02 October, 2004 12:27 AM
Do you have the info from KB832985, as I am trying to get IIS to suppress HTTP continue and cannot find this KB anywhere.

Thanks in advance


Gareth
# bernard said on 06 October, 2004 07:18 AM
http://dotnetjunkies.com/WebLog/stefandemetz/archive/2004/10/05/27720.aspx
# bernard said on 06 October, 2004 10:44 AM
Woohoo ! thanks Stefan
# bernard said on 06 October, 2004 11:04 AM
Hi Gareth,
I understand you had also contacted Chris, I believed he is working on it and shall update us when he get the answer.
# TrackBack said on 06 October, 2004 08:38 PM
# TrackBack said on 06 October, 2004 08:44 PM
# bernard said on 07 October, 2004 10:18 PM
Tested with IE 6, IE 5.5 and FireFox 1.0 on IIS 5.0/Win2K + URLScan. Results and updates are here:
http://dotnetjunkies.com/WebLog/richard.dudley/archive/2004/10/06/27788.aspx
# bernard said on 07 October, 2004 10:26 PM
I have posted my questions there :)
# TrackBack said on 19 October, 2004 01:47 AM
# bernard said on 24 October, 2004 07:54 AM
IIS vs Apache security http://dotnetjunkies.com/WebLog/stefandemetz/archive/2004/10/05/27720.aspx
http://dotnetjunkies.com/WebLog/stefandemetz/archive/2004/03/30/10388.aspx

# bernard said on 29 October, 2004 11:16 PM
Hi Bernard,

Great survey :) I had filled up mine.

Regards,
Chua Wen Ching
# bernard said on 14 November, 2004 04:55 PM
Hi,

I wouldn't count much on such "studies". There are multiple reasons, e.g which some you also pointed out (more detail part).

In addition one could argue about locking down the server _properly_ in which case majority of the bugs are not exploitable - I can do such IIS, as well as Apache.

And even more; study is based on public information. Not all bugs are public, from either side (Open- or closedsource).

And last; I am slightly disappointed that such a great person as Michael starts "pissing" contest where objective information would do much better. In objective I mean that telling what you're doing regards security etc.
# bernard said on 14 November, 2004 07:34 PM
Hi Ted,
Thanks for the comment, those details as you mentioned are more towards 'FYI', I wouldn't count it as well, security is complex and messy, it's not about product at all, there are needs to 'integrate' with people and processes. I believed everyone would agreed with this.

and lastly :) I can't comment on behalf of Micheal, but I'm sure he is not 'pissing' around.

cheers.
# TrackBack said on 17 November, 2004 08:52 PM
IIS Team Blog ??
# bernard said on 18 November, 2004 01:23 PM
Thank you for this info, Bernard. ;-)
# bernard said on 19 November, 2004 11:40 AM
No problem :)
# bernard said on 22 November, 2004 01:23 AM
good
# bernard said on 24 November, 2004 05:39 PM
Under a third of web servers running IIS [netcraft], which comprise a consistently higher proportion of compromised systems.
How can you swallow the creamy disinformation spread by microsoft, smile and say it tastes good.
# bernard said on 24 November, 2004 05:56 PM
Few points to take note.
a) This report is not about usage or market share. it's a study on security bugs filed between IIS 6 and Apache 1.x / 2.x

b) Again, we are not talking about exploited hosts counts here. Do you have the figures ?

c) IIS4/5 was not a quality webserver with many vulnerability and bugs. IIS 6.0 on the other hand has been improved. I have yet to receive any report for compromised IIS 6 boxes that due to IIS flaws. However, there are incidents which related to OS level exploits.
but that's not IIS if it's based on component level.

d)All products are subjected to bugs! and this post is FYI. not asking you MUST use IIS 6. I have talk about choosing the right prouduct for the right requirement and solution in the first paragraph.

e)I'm not 'pissing' around as well.
# bernard said on 27 November, 2004 08:59 PM
good
# TrackBack said on 29 November, 2004 06:03 PM
# bernard said on 30 November, 2004 01:56 AM
1.1 was released on 9/6/2004. Not sure why they do this as it seems that every couple of months they "re-release" tools like this when they actually are doing nothing but updating the release date
# bernard said on 30 November, 2004 10:02 AM
Hmm... I didn't actually get any detail of the Sept release, but 1.1 is out as earlier as in July - http://msmvps.com/bernard/archive/2004/07/29/10858.aspx

It seems like it is more related to bug fixings and minor enhancements for each release.
# TrackBack said on 06 December, 2004 10:08 PM
# bernard said on 07 December, 2004 05:35 AM
Does it work? Can I replicate a server to a new machine (we need more disk space). Our new machine will have a new name and IP Address. Will that matter?
# bernard said on 07 December, 2004 02:08 PM
Yes, it will work. However, the tool only migrate one site at a time. here's the update version -
http://msmvps.com/bernard/archive/2004/11/23/20304.aspx
# bernard said on 09 December, 2004 05:49 PM
My style -

Let other people try first. If it works fine with them all without any issues.. then only i will.

So Bernard, are there any sad stories you heard after ppl installing it to their live server?

I like to know.
# bernard said on 09 December, 2004 06:19 PM
Sad story ? I have one. coz my laptop is using W2k3. during beta it wasn't so bad, i spend few hours just to make livemeeting work with my IE.... the so called 'IE enhanced' feature really lockdown everything. Anyway, it's good call too as you should not surf from your production box.

Anyway, it is so far so good. though I have complaint to MS that documentation is totally outdated and incomplete. Hope they will release the beta document soon.
# bernard said on 27 December, 2004 07:25 PM
how to call a alert in asp.net
# bernard said on 30 December, 2004 09:51 AM
Is there a workaround here? I bought my own server thinking i would be able to host all parts of my website on it. But if I am understanding the host header/ssl problem correctly, my shopping cart has to be on this maching by itself, and i will have to get a another machine (or keep paying for hosting) for everything else. The problem is I wanted to make the main site dynamic, with web apps like forums and on the fly web page creation so it could be a lot snazzier and more competitive. any suggestions welcome. thanx.

natcolley@earthlink.net
# bernard said on 30 December, 2004 11:59 AM
Hi Nat,

SSL doesn't click with host header, hence for each SSL site you need separate IP address.

Cheers.
# bernard said on 08 January, 2005 03:23 AM
ermm.. I was wondering level 200 means novice, casual, advanced or...?
# TrackBack said on 08 January, 2005 12:31 PM
??: IIS FTP ? AD ???????? User Isolation ???????????????????????????
# bernard said on 08 January, 2005 12:58 PM
Level 200 will be an overview of the technology or product.

Full detail of different level -
http://support.microsoft.com/?scid=http://support.microsoft.com%2Fservicedesks%2Fwebcasts%2Flevels.asp
# TrackBack said on 09 January, 2005 03:13 AM
??: IIS FTP ? AD ???????? User Isolation ???????????????????????????
# bernard said on 12 January, 2005 10:00 PM
Well, I still able to download it at the url posted -
http://www.microsoft.com/downloads/details.aspx?FamilyId=E90FE777-4A21-4066-BD22-B931F7572E9A&displaylang=en

# TrackBack said on 19 January, 2005 09:11 PM
# TrackBack said on 01 February, 2005 08:39 AM
# bernard said on 02 February, 2005 04:07 PM
Update! I got 8 out of 10. No 4 is correct, so is X and 10. what is no X ?
# bernard said on 03 February, 2005 09:00 AM
Hey, I just received the stuff from Amazon and read through.
Yes, Yes, Yes!!!!!!!!!

Good job! Very clear and not-so-difficult guides and checklists! I like the way. I wish someone translates the book into Japanese. Then I would definitely use it for training my fellow people. ;-)
# bernard said on 03 February, 2005 10:05 AM
:) thanks man ! not sure if there's plan for translations. Normally, the publisher will work out with the resellers. Thanks for the support again.
# bernard said on 08 February, 2005 01:45 AM
Dear Bernard Cheah

Thanks for your response to samuel lee in MIND FORUM on how to import *.DBX files into outlook express.

My Colleague was in great distress after loosing important files during transfer in outlook express.

Now things are fine after i imported *dbx files

Sorry to post this message through this forum meant for something else.

But i wanted to get to you and say "Thanks a lot"

Regards

Kumaran


# bernard said on 08 February, 2005 01:47 AM
Wish you a Happy Chinese New Year

Rgds

Kumaran
# bernard said on 09 February, 2005 07:51 PM
No problem. Happy holiday to you too :)
# TrackBack said on 13 February, 2005 10:40 PM
# bernard said on 09 March, 2005 04:52 AM
good
# bernard said on 10 March, 2005 04:34 AM
Guys do you have or know any link that provide set of commands for migration tool
# bernard said on 14 March, 2005 08:08 AM
I think the readme and help doc that come with the migration kits have some information about the command line interface.
# bernard said on 14 March, 2005 09:06 PM
re: WebCasts - November 2004
# bernard said on 14 March, 2005 09:09 PM
re: WebCasts - November 2004
# bernard said on 16 March, 2005 12:19 PM
Congrats!
# bernard said on 22 March, 2005 10:23 AM
Hey, I tried exactly that with the SMTPDiag tool but You know where it says TCP test succeeded.
UDP test failed.

I got just the opposite:
TCP test failed.
UDP test succeeded.

Can you help me ??? I need to know how to fix this. Please...

-Satish
# bernard said on 22 March, 2005 10:44 AM
Just confirm, what OS you running now ? W2k3 ?
As for the tcp port issue, you need to verfiy that tcp port 53 is not blocked by firewall or router access list
# bernard said on 22 March, 2005 11:54 AM
I am running Windows 2003 standard edition and the built in firewall is not enabled. Is there something else i can check
# bernard said on 22 March, 2005 12:14 PM
It is fine then. Since this is W2k3, it will try UDP first. Anyway, this is just one part of the diag process, and whether UDP or TCP will do, as long as not both are failed. what's the problem you facing ? what about other diagnostic output ?
# bernard said on 22 March, 2005 12:40 PM
My problem is that I am unable to send email outside my dedicated server. I have a dedicated server which is running my site www.zalavadia.com it is running IIS 6 and i can receive email and I am able to POP the email to my outlook client, however in the outlook client I can't use the smpt for my dedicated server because it just wont' send out emails. This is my out put from the smtpDiag

Searching for Exchange external DNS settings.
Computer name is D00110991E211.
Failed to connect to the domain controller. Error: 8007054b

Checking SOA for gmail.com.
Checking external DNS servers.
Checking internal DNS servers.
Failed to connect to the domain controller. Error: 8007054b

Checking SOA for gmail.com.
Checking external DNS servers.
Checking internal DNS servers.
DNS server [66.235.217.202] did not return a valid SOA record.
SOA serial number match: Failed with one or more failures.

Checking local domain records.
Checking MX records using TCP: zalavadia.com.
Warning: The TCP DNS query returned no results.
Checking MX records using UDP: zalavadia.com.

Checking remote domain records.
Checking MX records using TCP: gmail.com.
Warning: The TCP DNS query returned no results.
Checking MX records using UDP: gmail.com.

Checking MX servers listed for satish.zalavadia@gmail.com.
Connecting to gsmtp185.google.com [64.233.185.27] on port 25.
Successfully connected to gsmtp185.google.com.
Connecting to gsmtp171.google.com [64.233.171.27] on port 25.
Successfully connected to gsmtp171.google.com.
Connecting to gsmtp57.google.com [216.239.57.27] on port 25.
Successfully connected to gsmtp57.google.com.

What do you think this could be?
# bernard said on 22 March, 2005 01:19 PM
Post the other part of the log, the log is not complete. Not sure why.

Have you try other domain other than gmail ?
# bernard said on 22 March, 2005 01:39 PM
I have tried yahoo too. Here is the output from yahoo.

Searching for Exchange external DNS settings.
Computer name is D00110991E211.
Failed to connect to the domain controller. Error: 8007054b

Checking SOA for yahoo.com.
Checking external DNS servers.
Checking internal DNS servers.

Checking TCP/UDP SOA serial number using DNS server [66.235.216.48].
TCP test failed.
UDP test succeeded.
Serial number: 2005032118

Checking TCP/UDP SOA serial number using DNS server [64.70.61.131].

Checking TCP/UDP SOA serial number using DNS server [66.235.217.202].
Failed: DNS server [66.235.217.202] may be down.
DNS server [66.235.217.202] did not return a valid SOA record.
SOA serial number match: Failed with one or more failures.

Checking local domain records.
Starting TCP and UDP DNS queries for the local domain. This test will try to
validate that DNS is set up correctly for inbound mail. This test can fail for
3 reasons.
1) Local domain is not set up in DNS. Inbound mail cannot be routed to
local mailboxes.
2) Firewall blocks TCP/UDP DNS queries. This will not affect inbound mail,
but will affect outbound mail.
3) Internal DNS is unaware of external DNS settings. This is a valid
configuration for certain topologies.
Checking MX records using TCP: zalavadia.com.
Warning: The TCP DNS query returned no results.
Checking MX records using UDP: zalavadia.com.
MX: MAIL.zalavadia.com (10)
A: MAIL.zalavadia.com [66.235.214.81]
A: NS21.WORLDNIC.com [216.168.228.13]
A: NS22.WORLDNIC.com [216.168.225.152]

Checking remote domain records.
Starting TCP and UDP DNS queries for the remote domain. This test will try to
validate that DNS is set up correctly for outbound mail. This test can fail for
3 reasons.
1) Firewall blocks TCP/UDP queries which will block outbound mail. Windows
2000/NT Server requires TCP DNS queries. Windows Server 2003 will use UDP
queries first, then fall back to TCP queries.
2) Internal DNS does not know how to query external domains. You must
either use an external DNS server or configure DNS server to query external
domains.
3) Remote domain does not exist. Failure is expected.
Checking MX records using TCP: yahoo.com.

Successfully connected to mx4.mail.yahoo.com.
Connecting to mx4.mail.yahoo.com [68.142.202.112] on port 25.
Received:
220 YSmtp mta120.mail.mud.yahoo.com ESMTP service ready

Sent:
ehlo zalavadia.com

Received:
250-mta120.mail.mud.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <satish@zalavadia.com>

Received:
250 sender <satish@zalavadia.com> ok

Sent:
rcpt to: <satish_zalavadia@yahoo.com>

Received:
250 recipient <satish_zalavadia@yahoo.com> ok

Sent:
quit

Received:
221 mta120.mail.mud.yahoo.com

Successfully connected to mx4.mail.yahoo.com.

# bernard said on 22 March, 2005 02:01 PM
I don't see any error with the above log. do you get any mail in your yahoo mailbox ?

try send it using this method
http://support.microsoft.com/?id=297700

if not working, anything in smtp log file ?
# bernard said on 23 March, 2005 10:16 AM
Hey listen, thank you for taking the time to look at my problem. I saw no errors in the log and i didn't see any emails in yahoo , hotmail or gmail. I did a port scan and all necessary ports r ok. Anyhow, thanks for ur help, i just used no-ip and forwarded email to there and it went through fine. Weird.
# bernard said on 23 March, 2005 11:41 AM
This could happen when the remote server blacklist you or etc. I have a smtp test server that can only send to yahoo mailbox, but not gmail or hotmail, because both gmail and hotmail doesn't recognize the smtp box, etc. hence though it got deliever, but it doesn't reach the mail box.
# bernard said on 25 March, 2005 12:21 AM
Does this mean iisanswers.com is dead?
I have not been able to access it for a month!
# bernard said on 25 March, 2005 08:15 AM
Hi Dantel,

No, the list is back up last week, due to some server relocation issue. As for iisfaq.com, there's plan to fix the slow connectivity to the site.
# TrackBack said on 30 March, 2005 09:11 PM
# TrackBack said on 31 March, 2005 11:03 PM
# TrackBack said on 31 March, 2005 11:07 PM
# TrackBack said on 31 March, 2005 11:07 PM
# bernard said on 04 April, 2005 07:11 PM
Fantastic, ran through the above and it worked a treat. Many thanks
# bernard said on 11 April, 2005 06:29 PM
New URL :)
http://mvp.support.microsoft.com/mvpins200503
# bernard said on 14 April, 2005 06:42 PM
thanks!
# bernard said on 15 April, 2005 12:21 PM
Update - Info released from sponsor - Windows IT Pro -
http://www.windowsitpro.com/Article/ArticleID/46058/46058.html
# bernard said on 15 April, 2005 07:32 PM
NICE ;-)
# bernard said on 18 April, 2005 03:00 PM
Here's a sample chapter @ IIS-resources.com
http://www.iis-resources.com/modules/AMS/article.php?storyid=358
# bernard said on 23 April, 2005 06:48 AM
hard to Google my way until here, mas worked like a charm ;) To fix the MSDTC just type in the comand line "msdtc -resetlog", and then do the above.. regards
# bernard said on 29 April, 2005 09:32 AM
IIS 6 doesn't allow you to configure a website with no host headers.
Is there anything else I can do?

Thanks
# bernard said on 01 May, 2005 06:05 AM
hola
# bernard said on 03 May, 2005 01:32 AM
This also assumes that you have 1 IP per website. You still can't do *.domain.com in IIS, unless you give each site it's own IP. I have roughly 400 sites shared on 1 IP, and would love to do this, however I don't want to have to apply for 400 more IP addresses, nor do the DNS changes ;)
# bernard said on 03 May, 2005 10:13 AM
Hi Rehan,

IIS 6 supports host header, refer
HOW TO: Use Host Header Names to Configure Multiple Web Sites in Internet Information Services 6.0
http://support.microsoft.com/?id=324287
# bernard said on 03 May, 2005 10:14 AM
Hi Matt,

For each wildcard host header *.domain.com you need one IP, and you will have ONE site. Since you have 400 sites with different domain URL, you will need 400 IPs if you want to utilized this feature.

You can use host header to host 400 sites with 1 IP. But for *.domain.com to work for that, we need to skip the host header and listen on the IP only. Hence, you are referring 400 *.domain.com sites and you need 400 IPs in a way. One way to skip the IP is, configure *.domain.com for that 400 domains, then when request hit the default page of the ONE site, using scripting to dynamic parse the URI then redirect to a proper site or virtual directory.
# bernard said on 06 May, 2005 01:49 AM
We run MS Exchange 5.5 on an NT 4.0 box.
Our mx record points to our public IP address.
Our firewall then forwards SMTP email to our Exchange 5.5
We have been successfully sending/receiving internet email for years and do not have an open relay.

Let's call my internet email domain address abcdnet.com. This as well as mail.abcdnet.com point to our public IP address.

Last week I setup a Windows 2000 IIS server to act as a SMTP relay for inbound mail only. I got it to work and it worked fairly well until yesterday. I started to receive event log messages stating:
"Message delivery to remote domain 'abcdnet.com' failed ...: The connection was dropped by the remote host'.

I'm not sure why after 5 days of working this started to happen. How would I trouble shoot this? Here is what I did when I installed the SMTP relay.

1) Edited Exchange Server's file c:\winnt\system32\driver\etc\services to default SMTP to port 26 (previously 25).

2) On the IIS box Default SMTP Server Properties->General->Connection I changed the Outgoing TCP port to 26

3) On the IIS box UNDER the Default SMTP Server I created a remote domain named called "abcdnet.com". Under properties I have checked 'Allow incoming mail to be relayed through this domain' checked. I also 'Forward all mail to smart host': internal IP address of Exchange Server.

4) I then pointed the smtp port in the firewall to point to the IIS box.


This setup was partially due to Symantec's suggestions for setting up a relay to be used with their anti-spam server, which is currently not setup.

So I am wondering if perhaps I did something wrong. It worked for 4 days then stopped. We did get hit by a lot of virus emails yesterday (sobe?) so we did have a higher than normal load, yet nothing seems to have become infected. It as if the SMTP relay got bogged down somehow. Everythign was working fine then just not.
# TrackBack said on 07 May, 2005 10:10 PM
# TrackBack said on 07 May, 2005 10:10 PM
# bernard said on 09 May, 2005 10:15 AM
Thank You so much! I had tried (over & over) to install IIS from the Add & Remove Windows Components with no luck! So I didn't have to delete anything cause it simply wasn't there! But it's there now! Yippie!
# bernard said on 09 May, 2005 10:46 AM
Hi Joe,

What kind of mail volume we are looking here? 10K per day? did you actually found any 'mails' stuck in badmail/drop under the mailroot/ folder? Lastly, any errors in smtp log?

I have seen this behavior before in one of my previous setup. Roughly 40K mails a day, hence the log is huge and you never know whether the mail really get delivered or not, it just too many. This could be due to heavy traffic and at that particular time. Under default setup, smtp will try to resend the mail. What you need to do one is to check if user complaint about mail not being delivered, then check the mail folder and smtp log to see if there's more clues to troubleshoot.

Cheers.
# bernard said on 11 May, 2005 07:26 AM
I just found this from Googel searches and it was exactly what I needed to do.

1. comand line "msdtc -resetlog"
2. rundll32 wamreg.dll, CreateIISPackage
3. rundll32 regsvr32 asptxn.dll
4. IISRESET

I can run ASP finally!

Thanks a lot.
# TrackBack said on 11 May, 2005 10:59 AM
IIS-Resources.com
# bernard said on 13 May, 2005 12:24 PM
Update: I just confirmed that the JetBug fix 838306 is included in SP1, detailed @ Ken's blog - http://www.adopenstatic.com/cs/blogs/ken/archive/2005/05/11/18.aspx
# bernard said on 18 May, 2005 11:06 AM
Here's the press release video.
http://www.xbox.com/media/games/e32005/vid-e32005livewebcast-001-Hi.asx
# bernard said on 19 May, 2005 09:42 AM
I love it!
# TrackBack said on 23 May, 2005 10:35 PM
Configuring 'website operator' in IIS 6.0ooeess
# bernard said on 24 May, 2005 05:28 PM
New Xbox 360 game trailers (high def) @ Microsoft download -
http://www.microsoft.com/downloads/details.aspx?familyid=abde1e02-b529-469e-ae6a-7417fcde9e12&displaylang=en
# TrackBack said on 24 May, 2005 11:41 PM
# TrackBack said on 25 May, 2005 12:56 AM
# bernard said on 26 May, 2005 11:49 PM
I just saw an Overview of IIS 7 yesterday and blogged about it at http://www.windowsadvice.com/blogs/jason_n_gaylord/archive/2005/05/25/Overview_Of_IIS_7_Alpha.aspx.
# bernard said on 27 May, 2005 09:31 AM
Thanks for sharing :)
# bernard said on 27 May, 2005 03:24 PM
Hi Bernard:

Actually, that's not quite correct. You can indeed determine which site corresponds to which entry. Even with enabling centralized logging, you can turn on the extended W3C properties, particularly s-sitename which will give you the W3SVC[INDEX] for each site. This makes it quite easy to figure out which entry corresponds to which site. Additionally, you can enable cs(Referer) and cs-version as well as any of the other extended attributes. You do it at the global level, note my log entries below from a log of mine I pulled from my dev environment:

#Fields: date time s-sitename s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs-version cs(User-Agent) cs(Referer) cs-host sc-status sc-substatus sc-win32-status sc-bytes cs-bytes time-taken
2005-05-03 08:59:59 W3SVC123499 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123499.com 200 0 0 255 140 15
2005-05-03 08:59:59 W3SVC123466 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123466.com 200 0 0 255 140 15
2005-05-03 08:59:59 W3SVC123476 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123476.com 200 0 0 255 140 0
2005-05-03 08:59:59 W3SVC123560 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123560.com 200 0 0 255 140 15
2005-05-03 08:59:59 W3SVC123635 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123635.com 200 0 0 255 140 15
2005-05-03 08:59:59 W3SVC123600 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123600.com 200 0 0 255 140 0
2005-05-03 08:59:59 W3SVC123514 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123514.com 200 0 0 255 140 0
2005-05-03 08:59:59 W3SVC123481 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123481.com 200 0 0 255 140 0
2005-05-03 08:59:59 W3SVC123579 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123579.com 200 0 0 255 140 15
2005-05-03 08:59:59 W3SVC123613 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123613.com 200 0 0 255 140 0
2005-05-03 08:59:59 W3SVC123605 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123605.com 200 0 0 255 140 0
2005-05-03 08:59:59 W3SVC123624 172.29.16.83 GET /index.htm - 80 - 172.29.16.83 HTTP/1.1 Mozilla/4.61+[en]+(WinNT;+I) - domain123624.com 200 0 0 255 140 0

I agree it's quite cool and long overdue. I've rewritten my log processing engine to take advantage of this. Now, instead of n number of handles open to n number of log files I only have 1 handle open to 1 log file, improving the load on my servers. Hope this information helps.

Thanks.

-matt
# bernard said on 27 May, 2005 04:09 PM
Thanks Matt! I missed that global settings part. Thanks for pointing out.

Cheers.
# bernard said on 30 May, 2005 10:17 AM
Cool posting.

I've been successful with WildCard SSL + wildcard DNS on an IIS virtual server hosting SharePoint in host header mode otherwise known as scalable hosting. It's worked well and now is supporting around 1000 unique subdomains.

Example:

DNS & SSL Cert:
https://*.team.domain.com

SiteName:
https://site.team.domain.com

The IIS WebSite/Virtual Server is not IP bound in this case as SharePoint does not support IP binding. It's the only IIS Virtual server on the box in a 2 node cluster.
# bernard said on 30 May, 2005 05:29 PM
Thanks for sharing Joel. That's the trick with *.subdomain.com wildcard cert :)
# TrackBack said on 30 May, 2005 11:16 PM
re: Log Parser 2.2 ?????????????????????????? (eXConn)
# TrackBack said on 31 May, 2005 09:01 PM
ANN: This is NOT ME!ooeess
# bernard said on 31 May, 2005 09:43 PM
Problema no IIs4.0
# bernard said on 31 May, 2005 11:39 PM
Hi,
I have tried the above, but when I come to:
regsvr32 asptxn.dll
I got this message: DllRegisterServer in asptxn.dll fail.
Returncode: 0x8004e00f

I have googled for a day now, and read 10 Microsoft KB's... but still cant get the answer.

Help me please,

Sam Boman
Sweden
# bernard said on 01 June, 2005 08:25 AM
Hi Sam,

Have you try http://support.microsoft.com/?id=301919 ? and rundll32 wamreg.dll, CreateIISPackage before you try regsvr32 asptxn.dll ?
# bernard said on 03 June, 2005 05:24 AM
Cant get this to work

Local groups cannot be added to the iis_wpg group so i create a global group in AD.

When adding permissions to lower level nodes you get the message that permission are inherited. Copy of Clear? If they realy are inherited allowing the group full controll at the top level node should do the trick, right?
# bernard said on 08 June, 2005 02:07 PM
Looks like the download link is broken
# bernard said on 08 June, 2005 06:23 PM
I got no problem downloading the file, here's some other useful resources about Log parser 2.2
Chap2 - Monitoring IIS
http://www.iis-resources.com/downloads/LPChap2.zip
Chap5 - Managing Snort Alerts
http://www.logparser.com/311_LogParser_05.pdf

And of coz Amazon
http://www.amazon.com/exec/obidos/ASIN/1932266526/larkware-20/104-0831330-3461537 (I contributed on the IIS portion)

and the forum where Gabriele(MS) always hang out.
http://www.logparser.com/instantforum33/default.aspx
# TrackBack said on 09 June, 2005 08:08 AM
# bernard said on 09 June, 2005 06:46 PM
Hi Mike,
If you are in a domain, then of coz you need to use global group. As for the permissions, you can assign user/group at higher node and let the permissions get inherited for those child nodes.
# bernard said on 11 June, 2005 05:33 AM
Download
# bernard said on 12 June, 2005 09:17 AM
Technically not at guy, but he will be when he grows up:

http://snmpboy.msft.net/
# bernard said on 12 June, 2005 01:06 PM
With only 512mb ram. snmpboy rocks!!
# TrackBack said on 17 June, 2005 03:34 AM
# bernard said on 17 June, 2005 08:16 PM
Hi,
I am looking for an IIS solution and just pass by your site.
I am doing something in here:
http://support.microsoft.com/kb/247389/EN-US/

multi line HTTP header works in IIS5, but not IIS6. The script in Q247389 will give me "The parameter is incorrect".

Do you know any way to solve this?
thanks.
# bernard said on 20 June, 2005 11:21 AM
Hi Francis,

If you got the error msgs, then I believe the script doesn't apply to IIS6, since it's meant for IIS5 only. I also read your post in public IIS newsgroup, I do not know any workaround for this, however I believe experts in newsgroup will be able to help you.

Cheers.
# bernard said on 20 June, 2005 12:54 PM
Like Sam, I am having no joy here attempting to apply the fix from the KB and also from this page. Any other thoughts?
# bernard said on 20 June, 2005 01:53 PM
thank you.
fyi, this is the <a href="http://www.google.com/url?sa=D&q=http://blogs.msdn.com/david.wang/archive/2005/06/19/ISAPI_Filter_to_set_CacheControl_based_on_ContentType.aspx'>link</a> for the solution that I described.

sorry to bother you.
# bernard said on 22 June, 2005 01:19 PM
Great! David is good in ISAPI stuff.
# bernard said on 22 June, 2005 01:21 PM
Hi Travis,

What do you have in event log now ?
# TrackBack said on 26 June, 2005 03:08 AM
# bernard said on 28 June, 2005 08:10 AM
You can download it from that link
# bernard said on 30 June, 2005 07:33 PM
Q: I am using Windows XP FTP server. Every file that is downloaded from my FTP server is logged in my c:\ drive also. So after some days I find a lot of files named s1f4.3, s1f4.4, s1f4.5, s1f4.a, ... with the same content and size of the corresponding downloaded files. How can I disable this?
# bernard said on 30 June, 2005 09:18 PM
Hi Thomas,

Are you using IIS FTP server that come with XP Pro? Are you saying you have mystery file in your c:\ ? are you uploading or downloading ? You might want to post this question with more information in public IIS newsgroups.
# bernard said on 01 July, 2005 04:45 AM
Yes, I am using standard IIS FTP that come with XP Pro. Every file that is downloaded from my FTP server is appearing in this strange file format on c:\.
# bernard said on 01 July, 2005 10:15 AM
Are you saying when you download from your IIS FTP server, those downloaded files appear in strange format? How do you download? have you try download it via ftp.exe ?

C:\> ftp localhost

login, do a dir listing, set the transer mode (ascii / binary), mget the file.

what file you are downloading anyway?
# bernard said on 01 July, 2005 06:46 PM
thanks
# TrackBack said on 01 July, 2005 07:29 PM
# bernard said on 09 July, 2005 08:30 PM
Thanks, worked for me.
MSDN was pretty useless in this case.
# bernard said on 09 July, 2005 11:35 PM
Thank you very much for sharing this info. This fixed me right up. (got here through Google).

I had trouble running "regsvr32 asptxn.dll", so I dropped back and first followed the steps in the Knowledge Base link you mentioned:
http://support.microsoft.com/?id=301919

rebooted, re-followed your steps, and it works great! Best Regards.
# bernard said on 10 July, 2005 01:05 AM
You're welcomed, Bill. Glad it fixed your problem.
# bernard said on 11 July, 2005 07:55 AM
OK, whatever program I use to download files from my IIS FTP server I can successfully download them to the client. But all files that have been downloaded appears in that strange naming format also on drive c:\ of the server. Looks like there is something logging every FTP access of my server.
# bernard said on 11 July, 2005 10:55 AM
In this case, do you have special software installed in the machine? antivirus, IDS, or ? Does this happen to your machine only? what about other client workstation? same issue. If it's your machine alone, then you need to know what's in the box that manipulating the incoming ftp packets.
# bernard said on 12 July, 2005 07:38 AM
IDS?
# bernard said on 14 July, 2005 07:16 AM
I have IIS 6 on a server joint to a domain - I am trying to add a user to operate a web site but doesn't do anything - Any special steps that I have to do to make it work or just remove it from the domain.

Thanks
# bernard said on 14 July, 2005 01:30 PM
Hi Joshua,

Nothing special, you can either use local or domain user. Assuming IIS is a a member server, you can add in those domain user to the WebOperator group.
# bernard said on 19 July, 2005 02:19 PM
re-registering vbscript didn't work for me but this did:
regsrv32 jscript.dll

Probably because I use server side Jscript in my asp scripts.
# bernard said on 19 July, 2005 03:32 PM
Yes, you need JSCRIPT.DLL - thanks for the update.
# bernard said on 29 July, 2005 08:28 PM
Having 'internal dns error' for the past 6 months. After running fine for few hours, my dedicated server will fail.

Upon failure. I get the following results:
- ping an external IP fails
- ping an external domain (ip show up) fails
- ping internal domain OK
- nslookup for internal and external domains OK
- Browser fails on both internal and external website.
- Email client can access mails
- Email client can send mails but mails will get stuck in queue for resend.
- Web cdo mail fails, goes to queue for resend.

After rebooting the server, all mail queue will goes out. All the abovemention problems do not exist until several hours later.

Any suggestions would be greatly appreciated.

Larry
http://www.geromail.com
# bernard said on 30 July, 2005 10:55 AM
Can you run smtpdiag when the problem occurs? use verbose mode and post the output here.
# bernard said on 02 August, 2005 10:21 AM
Thank you! This article solved a problem that was driving me nuts.

You may find that you don't have to reinstall Component Services to fix the problem where the MMC won't open your computer. This fixed that problem for me:

http://www.jsifaq.com/SUBJ/tip4500/rh4593.htm
# bernard said on 03 August, 2005 06:47 PM
Additional troubleshotting steps for XP - refer
http://www.iis-resources.com/modules/newbb/viewtopic.php?viewmode=flat&topic_id=3838&forum=9
# bernard said on 09 August, 2005 03:31 AM
I've taken all the steps you've listed and I still can't get wildcards to work. I've already got a blank A record (same as parent folder) pointing to one IP and a 'www' A record pointing to another IP. I need anything else to point to a different IP. Will the wildcard record only work if it's the only A record?

ie - mydomain.com => IP1
www.mydomain.com => IP2
*.mydomain.com => IP3
# bernard said on 09 August, 2005 07:35 PM
Interesting setup you have there. Not sure if ie / www will get resolved to IP3. So now, when you ping ie or www, does it resolve to IP1/IP2 or IP3.

What is not working? if you ping super.mydomain.com - it should returns IP3 and the IP3 website should bind to IP address without any host header value.
# bernard said on 10 August, 2005 02:18 AM
This is what's listed in the mydomain.com.dns file on our DNS server:

--------------------------------
;
; Zone records
;

@ A [IP1]
@ MX 10 maildomain.mydomain.com.
www A [IP2]
* IN [IP3]
----------------------------------

On our IIS server there's an entry for IP1 with no host header, an entry for IP2 with a www.mydomain.com host header and an entry for IP3 with no host header.

When I ping mydomain.com, it returns IP1. When I ping www.mydomain.com it returns IP2. When I ping [anything].mydomain.com it returns 'Unknown host [anything].mydomain.com'
# bernard said on 10 August, 2005 10:49 AM
Hi Donovan,

Thanks for the clarification, You are correct, it's a 'A' record not IN, I have updated the post, my apologize on the typo :( it should be:
* A IP.IP.IP.IP

Thank you.
# bernard said on 12 August, 2005 02:28 AM
Thanks Bernard.

It's working for me now. I had actually already tried changing 'IN' to 'A' previously and it still didn't work. I'm not sure what I did differently this time, but I think it had to do with modifying the entry on BOTH DNS servers. I thought it would automatically import from DNS1 to DNS2 but I had to change the physical .dns file on both servers.

Thanks for your help.
# bernard said on 12 August, 2005 05:27 AM
I am having trouble with my email. I am able to send email to some accounts and others it fails. I ran the SMPTdiagtool and get the following.

error expected 250 smtp.pp.htv.fi

I'm not sure what is happening. I also notice that emails to AOL fail.

Thanks

HW
# bernard said on 12 August, 2005 02:43 PM
No problem. When I tested it I didn't try on zone transfer to secondary DNS servers. Have you try transfer from master, any event log? I think it should transfer without any problem.
# bernard said on 12 August, 2005 02:51 PM
Can you post the complete smtpdiag log? I'm guessing the remote mail server rejected the mail. pls look at the smtp log files. It could be your mail host is not a valid host (e.g. complete with reverse lookup dns record), not in whitelist or it's blacklisted, etc.

And it's not really smtp issue as you can send to certain domains, but rather the smtp host itself been able to send mail like the rest of those valid mail server.
# bernard said on 15 August, 2005 11:36 AM
I can't do the following thind.
c:\winnt\system32\inetsrv\>rundll32 wamreg.dll, CreateIISPackage
# bernard said on 15 August, 2005 05:21 PM
Is your %windir% - c:\winnt\ or c:\windows or ???
Navigate to the path first, then excute the command. if you do, then any error msgs while you excute the command?
# bernard said on 16 August, 2005 05:34 AM
I'm also having touble sending email form a windows 2003 server. I downloaded SMTPDiag and below afre the results, Unfortunatly I'm much more of a developer than a network guy, do you have any ideas what the problem might be? Thanks for you help.


Searching for Exchange external DNS settings.
Computer name is NS1.
Failed to connect to the domain controller. Error: 8007054b

Checking SOA for yahoo.com.
Checking external DNS servers.
Checking internal DNS servers.

Checking TCP/UDP SOA serial number using DNS server [70.84.160.11].
TCP test failed.
UDP test succeeded.
Serial number: 2005081508

Checking TCP/UDP SOA serial number using DNS server [70.84.161.11].
TCP test failed.
UDP test succeeded.
Serial number: 2005081508
SOA serial number match: Passed.

Checking local domain records.
Starting TCP and UDP DNS queries for the local domain. This test will try to
validate that DNS is set up correctly for inbound mail. This test can fail for
3 reasons.
1) Local domain is not set up in DNS. Inbound mail cannot be routed to
local mailboxes.
2) Firewall blocks TCP/UDP DNS queries. This will not affect inbound mail,
but will affect outbound mail.
3) Internal DNS is unaware of external DNS settings. This is a valid
configuration for certain topologies.
Checking MX records using TCP: hubshift.com.
Warning: The TCP DNS query returned no results.
Checking MX records using UDP: hubshift.com.
MX: mailstore1.secureserver.net (10)
MX: smtp.secureserver.net (0)
A: smtp.secureserver.net [64.202.166.12]
A: mailstore1.secureserver.net [64.202.166.11]
A: PARK5.secureserver.net [64.202.165.110]
A: PARK6.secureserver.net [64.202.167.149]

Checking remote domain records.
Starting TCP and UDP DNS queries for the remote domain. This test will try to
validate that DNS is set up correctly for outbound mail. This test can fail for
3 reasons.
1) Firewall blocks TCP/UDP queries which will block outbound mail. Windows
2000/NT Server requires TCP DNS queries. Windows Server 2003 will use UDP
queries first, then fall back to TCP queries.
2) Internal DNS does not know how to query external domains. You must
either use an external DNS server or configure DNS server to query external
domains.
3) Remote domain does not exist. Failure is expected.
Checking MX records using TCP: yahoo.com.
Warning: The TCP DNS query returned no results.
Checking MX records using UDP: yahoo.com.
MX: mx3.mail.yahoo.com (1)
MX: mx4.mail.yahoo.com (5)
MX: mx1.mail.yahoo.com (1)
MX: mx2.mail.yahoo.com (1)
A: mx1.mail.yahoo.com [67.28.113.10]
A: mx1.mail.yahoo.com [67.28.113.11]
A: mx1.mail.yahoo.com [4.79.181.14]
A: mx1.mail.yahoo.com [4.79.181.15]
A: mx2.mail.yahoo.com [67.28.114.35]
A: mx2.mail.yahoo.com [67.28.114.36]
A: mx2.mail.yahoo.com [4.79.181.13]
A: mx2.mail.yahoo.com [64.156.215.8]
A: mx3.mail.yahoo.com [4.79.181.12]
A: mx3.mail.yahoo.com [64.156.215.5]
A: mx3.mail.yahoo.com [64.156.215.6]
A: mx3.mail.yahoo.com [64.156.215.18]
A: mx4.mail.yahoo.com [67.28.113.19]
A: mx4.mail.yahoo.com [68.142.202.11]
A: mx4.mail.yahoo.com [68.142.202.12]
A: mx4.mail.yahoo.com [66.218.86.156]

Checking MX servers listed for kywillis@yahoo.com.
Connecting to mx3.mail.yahoo.com [64.156.215.18] on port 25.
Received:
220 mta340.mail.scd.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta340.mail.scd.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta340.mail.scd.yahoo.com

Successfully connected to mx3.mail.yahoo.com.
Connecting to mx3.mail.yahoo.com [64.156.215.6] on port 25.
Received:
220 mta189.mail.scd.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta189.mail.scd.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta189.mail.scd.yahoo.com

Successfully connected to mx3.mail.yahoo.com.
Connecting to mx3.mail.yahoo.com [64.156.215.5] on port 25.
Received:
220 mta151.mail.scd.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta151.mail.scd.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta151.mail.scd.yahoo.com

Successfully connected to mx3.mail.yahoo.com.
Connecting to mx2.mail.yahoo.com [64.156.215.8] on port 25.
Received:
220 mta311.mail.scd.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta311.mail.scd.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta311.mail.scd.yahoo.com

Successfully connected to mx2.mail.yahoo.com.
Connecting to mx2.mail.yahoo.com [4.79.181.13] on port 25.
Received:
220 mta153.mail.mud.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta153.mail.mud.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta153.mail.mud.yahoo.com

Successfully connected to mx2.mail.yahoo.com.
Connecting to mx2.mail.yahoo.com [67.28.114.36] on port 25.
Received:
220 mta202.mail.dcn.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta202.mail.dcn.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta202.mail.dcn.yahoo.com

Successfully connected to mx2.mail.yahoo.com.
Connecting to mx1.mail.yahoo.com [4.79.181.15] on port 25.
Received:
220 mta242.mail.mud.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta242.mail.mud.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta242.mail.mud.yahoo.com

Successfully connected to mx1.mail.yahoo.com.
Connecting to mx1.mail.yahoo.com [4.79.181.14] on port 25.
Received:
220 mta219.mail.mud.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta219.mail.mud.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta219.mail.mud.yahoo.com

Successfully connected to mx1.mail.yahoo.com.
Connecting to mx1.mail.yahoo.com [67.28.113.11] on port 25.
Received:
220 mta183.mail.re2.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta183.mail.re2.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta183.mail.re2.yahoo.com

Successfully connected to mx1.mail.yahoo.com.
Connecting to mx2.mail.yahoo.com [67.28.114.35] on port 25.
Received:
220 mta140.mail.dcn.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta140.mail.dcn.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta140.mail.dcn.yahoo.com

Successfully connected to mx2.mail.yahoo.com.
Connecting to mx1.mail.yahoo.com [67.28.113.10] on port 25.
Received:
220 mta135.mail.re2.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta135.mail.re2.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta135.mail.re2.yahoo.com

Successfully connected to mx1.mail.yahoo.com.
Connecting to mx3.mail.yahoo.com [4.79.181.12] on port 25.
Received:
220 mta113.mail.mud.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta113.mail.mud.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta113.mail.mud.yahoo.com

Successfully connected to mx3.mail.yahoo.com.
Connecting to mx4.mail.yahoo.com [66.218.86.156] on port 25.
Received:
220 mta263.mail.scd.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta263.mail.scd.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta263.mail.scd.yahoo.com

Successfully connected to mx4.mail.yahoo.com.
Connecting to mx4.mail.yahoo.com [68.142.202.12] on port 25.
Received:
220 mta230.mail.mud.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta230.mail.mud.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta230.mail.mud.yahoo.com

Successfully connected to mx4.mail.yahoo.com.
Connecting to mx4.mail.yahoo.com [68.142.202.11] on port 25.
Received:
220 mta217.mail.mud.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta217.mail.mud.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta217.mail.mud.yahoo.com

Successfully connected to mx4.mail.yahoo.com.
Connecting to mx4.mail.yahoo.com [67.28.113.19] on port 25.
Received:
220 mta213.mail.re2.yahoo.com ESMTP YSmtp service ready

Sent:
ehlo hubshift.com

Received:
250-mta213.mail.re2.yahoo.com
250-8BITMIME
250-SIZE 31981568
250 PIPELINING


Sent:
mail from: <kywillis@hubshift.com>

Received:
250 sender <kywillis@hubshift.com> ok

Sent:
rcpt to: <kywillis@yahoo.com>

Received:
250 recipient <kywillis@yahoo.com> ok

Sent:
quit

Received:
221 mta213.mail.re2.yahoo.com

Successfully connected to mx4.mail.yahoo.com.
# bernard said on 17 August, 2005 09:55 AM
From the log, it shows that your smtp is working correctly. Are you experiencing the mail get sent but not received at the other end? e.g. emails not delivered to hotmail/yahoo mailbox. The possible reason that your mail hosts is blacklisted, or doesn't pass their filter rules (e.g. has a valid reverse lookup name), etc.
# bernard said on 21 August, 2005 12:06 AM
Hey, I would like to meet you man.... Hopefully, i can find time to come down... :)
# bernard said on 21 August, 2005 11:42 AM
Cool :) See ya there.
# bernard said on 23 August, 2005 04:44 PM
c:\winnt\
# bernard said on 23 August, 2005 04:55 PM
What's the error msgs when you run the command? Can you find the rundll32 file ?
# TrackBack said on 24 August, 2005 02:08 AM
# TrackBack said on 24 August, 2005 07:15 PM
# bernard said on 24 August, 2005 09:13 PM
What a relief! There are some many useless links on MS and other ASP/IIS sites that just couldn't cut it. Thanks so much for your tip.
# TrackBack said on 25 August, 2005 07:33 PM
# bernard said on 29 August, 2005 12:17 PM
Hi Bernard,
Iam having some problem with implementing webservices using IIS 6.0 the webservice implemented is cosumed by Java.

Would be good to discuss with You. how to contact You. My email is "gokulraja.dhamodaran"

I just gave without domain name to prevent spam. Its my gmail id.

Regards,
Gokul
# bernard said on 29 August, 2005 07:48 PM
Hi, You should post it to the public IIS newsgroups or IIS-resources.com. I will try to follow up from there. I don't reply technical posting via blog or email.

Cheers,
Bernard
# bernard said on 01 September, 2005 05:53 AM
It might be wort mentioning that the patterns and practices book is available as a free PDF from MSDN. There is also a threat modelling one, and a ton of other good material at http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnanchor/html/anch_netsecurity.asp
# bernard said on 03 September, 2005 01:25 AM
come on now, IIS = Internet Information Services
# bernard said on 10 September, 2005 01:23 AM
I have the same 'Class not registered' problem, but when I run c:\winnt\system32\inetsrv\>regsvr32 asptxn.dll I get this error:
"DllRegisterServer in asptxn.dll failed
Return code was: 0x800800005"

I realized that in the event viewer(Application) I have this error:

Source: MSDTC
Event ID: 4437
Description:
The account that the MS DTC service is running under is invalid. This can happen if the service account information has been changed using the Services snap-in in Microsoft Management Console (MMC). MS DTC service will continue to start. Please make sure that the MS DTC service account information is updated using the Component Services Explorer.

and also

Source: COM+
Event ID: 4863
Description:
TransactionManager->GetWhereabouts failed. If Distributed Transaction Coordinator is configured to use remote host to coordinate transactions, it is likely that remote host cannot be contacted. You can configure MSDTC to use local coordinator by clicking MSDTC toolbar button in Component Services MMC snap-in. Since further execution is impossible at this time, server process has been terminated.
Server Application ID: {02D4B3F1-FD88-11D1-960D-00805FC79235}
Server Application Instance ID:
{5A2E8651-3C35-4B7D-8AE2-4864339345F7}
Server Application Name: System Application
Error Code = 0x8004d01b : The Transaction Manager is not available.
COM+ Services Internals Information:
File: d:\qxp_slp\com\com1x\src\comsvcs\txprop\dtcinfo.cpp, Line: 164
Comsvcs.dll file version: ENU 2001.12.4414.258 shp


Any ideas??
# bernard said on 10 September, 2005 12:27 PM
First is to fix the MSDTC, then com+, then IIS. So, try
How to reinstall Microsoft Distributed Transaction Coordinator on a computer that is running Windows XP
http://support.microsoft.com/?id=891801
# bernard said on 20 September, 2005 04:15 PM
Microsoft is working diligently on a new tool designed to make the life easier for IIS administrators and developers who are tasked with solving complex problems such as crashes, hangs, or memory leaks. The tool, called Debug Diagnostics 1.0, is the next generation debugging utility that extends on the functionality of previous tools such as IIS Debug Toolkit 1.1, Debug Matrix, and IIS State. This tool will be the only fully supported tool for debugging applications that run on IIS upon release and is supported on the IIS 4.0, 5.0, 5.1, and 6.0 platforms.
# bernard said on 28 September, 2005 11:34 PM
Might be because of a exploit I found.

http://ingehenriksen.blogspot.com/2005/09/iis-51-allows-for-remote-viewing-of.html
# bernard said on 03 October, 2005 04:23 PM
Thx dude,worked fine to me.
# TrackBack said on 07 October, 2005 01:48 PM
# TrackBack said on 07 October, 2005 01:59 PM
# TrackBack said on 07 October, 2005 02:15 PM
# bernard said on 08 October, 2005 05:51 AM
Possible :) but I know PSS has been telling users for a long time, but this is the first official article from MS addressing the supportability issue with FAT/FAT32.
# bernard said on 13 October, 2005 04:59 AM
Yeah, IIS 7 promises to be pretty cool. I love the ability to add/remove modules, reducing the IIS surface. With the documentation, it would be nice if MS could post an RSS link for it, so we can be informed when an update occurs on the pages.
# bernard said on 13 October, 2005 10:23 AM
Hi Matt,
There's no RSS feed at the moment, nevertheless - many of the us are watching all the detail release by Microsoft very closely. Will post here when it is available.
Cheers.
# bernard said on 14 October, 2005 01:28 PM
I followed your steps 100% and ASP pages are now functional on my windows xp prof sp2 dev box.

one note - I stepped along up to this instruction:

a) Delete IIS related package in Component Services MMC...

but there were no component services entries to be found for iis. after thinking about it a bit, i skipped the step assuming a mistake like skipping any step could realistically mean reinstalling the o.s. i mean hey - anything could happen as a result of skipping a step with something that goes slightly over your head. but i did, and continued on picking up with this step:

b) Open command prompt, navigate to %windir%\system32...

I had no other problems. opened ie, went to http://localhost/index.htm to verify that a know loading page would come up, which it did, then jumped to http://localhost/default.asp and bam - hello world.

many thanks
# TrackBack said on 14 October, 2005 09:48 PM
# bernard said on 17 October, 2005 10:17 PM
looking for performance tuning
# bernard said on 18 October, 2005 06:09 PM
Thank you very mucg for the suggestion! It worked just great!!! I't interesting though how did you find out that vbscript.dll is unregistered?

Thanks a lot again!
Traian
# bernard said on 19 October, 2005 11:45 AM
Well, I have seen this issue many times :)
# bernard said on 24 October, 2005 02:35 PM
You can probably bug me with questions and things may leak here and there... ;-)

I am actually advocating for less "product documentation" and more guidance and community involvement. Stay tuned...

//David
# bernard said on 24 October, 2005 03:33 PM
Of coz, David, I know where to look for you :)
# bernard said on 27 October, 2005 05:47 PM
very good!
# bernard said on 28 October, 2005 04:53 PM
I ahve a 2k box that I configured for WSUS, didn't test IIS before installation but the WSUSAdmin page created the above error. This fix worked first time, thanks!
# bernard said on 30 October, 2005 06:50 AM
THXXXXXXXXXXX!
# bernard said on 01 November, 2005 08:16 AM
worked perfectly for me. Thanks for the quick fix!
# bernard said on 01 November, 2005 10:01 AM
I've done this and it doesn't work -- it's still trying to use ports outside of this range!!
# bernard said on 01 November, 2005 04:30 PM
Many Many Many Thanks dude.

I found that many times when installing a new security update or service pack, the installer fails to copy files.
I have been installed service pack 1 for windows server 2003, but it was deleted the old VBSCRIPT.DLL and didnt copy the new VBSCRIPT.DLL . I manually copied the file and registered it.
now it is working.

Reza Toghraee

# bernard said on 10 November, 2005 10:52 AM
thanks
# TrackBack said on 10 November, 2005 09:27 PM
# TrackBack said on 10 November, 2005 09:31 PM
# bernard said on 11 November, 2005 05:38 AM
Thank you very much!!! I have all day trying to figure this issue and finally was able to fix it with your tip. I really appreciated. Thanks.

Victor
# TrackBack said on 11 November, 2005 08:17 AM
# TrackBack said on 11 November, 2005 08:21 AM
# bernard said on 16 November, 2005 06:40 AM
Thanks alot, saved my day!!!

This happened on Windows 2000 Advanced Server.

Great Work!!
# TrackBack said on 16 November, 2005 11:44 PM
# TrackBack said on 16 November, 2005 11:59 PM
# bernard said on 22 November, 2005 11:13 PM
Actually, you can add local groups to the IIS_WPG group. For some reason it will not let you add local groups to local groups in the GUI. If you go to the command prompt and type
'net localgroup "IIS_WPG" "TheLocalgrouptoAdd" /add'
It will add the localgroup to the IIS_WPG group.

Any questions just email me.
# bob said on 15 December, 2005 03:51 PM
I ran the integrate to get combine the xp and xp sp2 files. That went fine. Now when I try to install IIS, it now says it cannot copy the file STAXMEM.DL_ after I tell it to pull from my newly combined file location.

Now what?
# Michael Freidgeim said on 16 December, 2005 12:16 AM
# Michael Freidgeim said on 19 December, 2005 12:47 AM
# Matt Baldwin said on 19 December, 2005 01:16 PM
As one who works in webhosting, I would have to say YES.

-matt
# bernard said on 19 December, 2005 11:06 PM
Hi Bob,
Since you encounter problem with method 2, have you try method 1. I have actually tested method 2 before and it works fine. did the integration of sp2 and original xp cd went well?
# Peter Schmidt said on 20 December, 2005 07:34 AM

I sure hope FTPS will be included in IIS 7, we really miss that feature.

/Peter
# IIS7 said on 22 December, 2005 01:24 AM
Yes ! Yes ! Yes!
# Alun Jones said on 27 December, 2005 11:10 PM
You know it's all under NDA, and I can't tell you any information that Microsoft hasn't publicly released. I may not work there any more, but I did promise that I would leave private information private.

However, in the meantime, I can suggest an FTP server that currently does have FTPS - my own WFTPD Pro, at http://www.wftpd.com - okay, so that's a little free advertising, but there's several more clients, tunnels and servers at http://www.ford-hutchinson.com/~fh-1-pfh/ftps-ext.html
# Alun Jones said on 28 December, 2005 10:24 AM
And, of course, if you're masking the banner trying to fool hackers, viruses and worms, forget it - they'll use whatever exploit they have, regardless of what your server claims to be. If your server is vulnerable, it's vulnerable and will fall, no matter what the banner claims to be.
# Rob said on 28 December, 2005 11:25 AM
Attempting to implement your workaround to allow a non local box admin to administer IIS 6.

All appears to work except step 3. When a user who is a member of the appropriate group logs in the the server, and runs the custom IIS admin, they can see the app pools, and web service extensions, but nothing is visible in web sites.

I have verified via Metabase Explorer that the group they are in has Full Control to the individual sites under W3SVC and that the permission is present at all sub keys.

On your suggestion I tried again with Regmon and Filemon running in the background. Absolutely nothing in Filemon, and no "Access Denied" in Regmon, though several "Not Found."

I welcome any additional insight.
# bernard said on 28 December, 2005 07:51 PM
Agreed! Masking doesn't protect you from attacks. You still need to configure proper network, server, application, etc security...
# bernard said on 28 December, 2005 07:53 PM
Lovely :) You have my support here.... I'm pushing MS to put this in, but till now this is still a question mark.
# bernard said on 28 December, 2005 07:59 PM
Hi Rob,

Did the user has READ permission on the W3SVC node? step 2e ??
Since you are able to sort out app pool and web service extensions node, this looks like just a permission issue on w3svc node.
# David Wang said on 02 January, 2006 01:26 PM
Hmm... I wonder if the same branding agency did the work... with Intel leaping ahead and XBox jumping in...

I rather liked "Intel Inside", but I guess we will soon see what the new logo looks like.

//David
# Rob said on 03 January, 2006 02:32 PM
Bernard,

In my case, I had to grant Full on the LM node in order for the user to see the Web Sites. Once that was done, all other permissions could be set as Read, or as otherwise desired.

Thanks!
# bernard said on 03 January, 2006 10:43 PM
It's out :)
http://news.com.com/2300-1006_3-6016382-1.html

I can't comment too much, else legal depart will be chasing me. Set aside the branding, Intel is moving away from making cpu chip to a platform based company. You'll soon see a new range of latest innovative technologies in the market soon... from PC to home entertainment, to digital health and more.
# bernard said on 03 January, 2006 10:47 PM
Great! but i'm still curious on why can't you grant READ at the first place ? I mean at the w3svc node and granting full control at LM node could introduce hidden risks, and if you forgot to further lock down the sub nodes, the user will be able to manipulate all the metabase keys under the node.
# Server: Microsoft-IIS/6.0\r\n said on 07 January, 2006 02:59 AM
Came across this great article from the TechNet Magazine which talked about different tips to boots up...
# Server: Microsoft-IIS/6.0\r\n said on 07 January, 2006 03:00 AM
Came across this great article from the TechNet Magazine which talked about different tips to boots up...
# Server: Microsoft-IIS/6.0\r\n said on 07 January, 2006 03:01 AM
Came across this great article from the TechNet Magazine which talked about different tips to boots up...
# Dave said on 09 January, 2006 01:40 PM
I believe that I have the permssions correct in Metabase Explorer. However once in the MMC Snap-in the Web Sites fail to come up unless I am an administrator. Any thoughts?
# qbernard said on 11 January, 2006 03:35 AM
Hi Dave,
It sounds like permissions issue. if you can managed IIS as and administrator but you can't with the custom user - meaning he/she doesn't has required priviliges to manage IIS. So I would suggest you verify you configuration again.
# Prady said on 12 January, 2006 02:40 AM
Hi,

I am unable to send emails to yahoo/gmail or hotmail a/c . I am using win2003 server with iis 6. I am able to send mails within the organization but not able to send it to other accounts.I get a delivery failure . The event log log returns this message

=========================================

Message delivery to the host '66.249.83.114' failed while delivering to the remote domain 'gmail.com' for the following reason: The remote server did not respond to a connection attempt.

==========================================

Any pointers on what could be the reason.


The reports after running the smtpdiag are these..


Searching for Exchange external DNS settings.
Computer name is E2ESCV2.
Failed to bind to search. Error: 8007054b

Checking SOA for gmail.com.
Checking external DNS servers.
Checking internal DNS servers.

Checking TCP/UDP SOA serial number using DNS server [16.138.16.52].
TCP test succeeded.
UDP test succeeded.
Serial number: 2005122000

Checking TCP/UDP SOA serial number using DNS server [16.138.16.104].
TCP test succeeded.
UDP test succeeded.
Serial number: 2005122000
SOA serial number match: Passed.

Checking local domain records.
Starting TCP and UDP DNS queries for the local domain. This test will try to
validate that DNS is set up correctly for inbound mail. This test can fail for
3 reasons.
1) Local domain is not set up in DNS. Inbound mail cannot be routed to
local mailboxes.
2) Firewall blocks TCP/UDP DNS queries. This will not affect inbound mail,
but will affect outbound mail.
3) Internal DNS is unaware of external DNS settings. This is a valid
configuration for certain topologies.
Checking MX records using TCP: xx.com.
MX: smtp.xx.com (10)
MX: smtpx.xx.com (30)
A: smtp.xx.com [192.151.81.254]
A: smtpx.xx.com [15.81.168.21]
A: smtpx.xx.com [15.81.176.20]
A: smtpx.xx.com [15.81.176.21]
A: smtpx.xx.com [15.45.89.154]
A: smtpx.xx.com [15.45.89.155]
A: smtpx.xx.com [15.45.89.156]
A: smtpx.xx.com [15.45.89.157]
A: smtpx.xx.com [15.81.168.20]
Checking MX records using UDP: xx.com.
MX: smtp.xx.com (10)
MX: smtpx.xx.com (30)
A: smtp.xx.com [192.151.81.254]
A: smtpx.xx.com [15.81.176.20]
A: smtpx.xx.com [15.81.176.21]
A: smtpx.xx.com [15.45.89.154]
A: smtpx.xx.com [15.45.89.155]
A: smtpx.xx.com [15.45.89.156]
A: smtpx.xx.com [15.45.89.157]
A: smtpx.xx.com [15.81.168.20]
A: smtpx.xx.com [15.81.168.21]
Both TCP and UDP queries succeeded. Local DNS test passed.

Checking remote domain records.
Starting TCP and UDP DNS queries for the remote domain. This test will try to
validate that DNS is set up correctly for outbound mail. This test can fail for
3 reasons.
1) Firewall blocks TCP/UDP queries which will block outbound mail. Windows
2000/NT Server requires TCP DNS queries. Windows Server 2003 will use UDP
queries first, then fall back to TCP queries.
2) Internal DNS does not know how to query external domains. You must
either use an external DNS server or configure DNS server to query external
domains.
3) Remote domain does not exist. Failure is expected.
Checking MX records using TCP: gmail.com.
MX: gmail-smtp-in.l.google.com (5)
MX: gsmtp83.google.com (10)
MX: gsmtp163.google.com (10)
MX: gsmtp185.google.com (10)
MX: gsmtp83-2.google.com (10)
MX: gsmtp185-2.google.com (10)
A: gsmtp83.google.com [66.249.83.27]
A: gsmtp163.google.com [64.233.163.27]
A: gsmtp185.google.com [64.233.185.27]
A: gsmtp83-2.google.com [66.249.83.114]
Checking MX records using UDP: gmail.com.
MX: gmail-smtp-in.l.google.com (5)
MX: gsmtp83.google.com (10)
MX: gsmtp163.google.com (10)
MX: gsmtp185.google.com (10)
MX: gsmtp83-2.google.com (10)
MX: gsmtp185-2.google.com (10)
Both TCP and UDP queries succeeded. Remote DNS test passed.
A: gmail-smtp-in.l.google.com [64.233.163.27]
A: gmail-smtp-in.l.google.com [64.233.163.114]
A: gsmtp185-2.google.com [64.233.185.114]

Checking MX servers listed for pradykris@gmail.com.
Connecting to gmail-smtp-in.l.google.com [64.233.163.114] on port 25.
Connecting to the server failed. Error: 10061
Failed to submit mail to gmail-smtp-in.l.google.com.
Connecting to gmail-smtp-in.l.google.com [64.233.163.27] on port 25.
Connecting to the server failed. Error: 10061
Failed to submit mail to gmail-smtp-in.l.google.com.
Connecting to gsmtp185-2.google.com [64.233.185.114] on port 25.
Connecting to the server failed. Error: 10061
Failed to submit mail to gsmtp185-2.google.com.
Connecting to gsmtp83-2.google.com [66.249.83.114] on port 25.
Connecting to the server failed. Error: 10061
Failed to submit mail to gsmtp83-2.google.com.
Connecting to gsmtp185.google.com [64.233.185.27] on port 25.
Connecting to the server failed. Error: 10061
Failed to submit mail to gsmtp185.google.com.
Connecting to gsmtp163.google.com [64.233.163.27] on port 25.
Connecting to the server failed. Error: 10061
Failed to submit mail to gsmtp163.google.com.
Connecting to gsmtp83.google.com [66.249.83.27] on port 25.
Connecting to the server failed. Error: 10061
Failed to submit mail to gsmtp83.google.com.
# Chris said on 12 January, 2006 09:28 AM
Ive been trying frantically for 2 days to apply these solutions,neither method seems to work,not even Microsoft has any vaiable solutions.
I'm running a 2.8ghz Pentium 4,XP Pro, 1gig of memory.
Only course open is a re-format, not forgetting to install IIS first off !!
Thanks Bill Gates for bug riddled security on IIS(As a developer using ASP .NET that failed miserably too and had to abandon an application I was writing for a client!).
Any saviours out there can force this useless OS to work according to the solutions ?
# qbernard said on 14 January, 2006 06:38 AM
Hi Prady,
Obviously from the event log and smtpdiag log. it is indicating that your host is unable to connect to the remote smtp server on port 25. Make sure this port is not blocked by your firewall, etc.
# qbernard said on 14 January, 2006 06:41 AM
Hi Chris,
I'm sorry to hear that you encounter many problems with IIS. Are you able to run IIS now? are there any error msgs when you integrated the sp2 with the original installation cd? are you seeing the same 'file not found' during installation?
# Server: Microsoft-IIS/6.0\r\n said on 16 January, 2006 04:13 AM
Last year, Microsoft released the first version of IIS diagnostics toolkits&amp;nbsp;withLog Parser 2.2SMTPDiag...
# Andreas Kraus said on 17 January, 2006 11:26 AM
Cool, thanks for the news!
# Server: Microsoft-IIS/6.0\r\n said on 17 January, 2006 09:02 PM
Last year, Microsoft released the first version of IIS diagnostics toolkits&amp;nbsp;withLog Parser 2.2SMTPDiag...
# Server: Microsoft-IIS/6.0\r\n said on 17 January, 2006 11:33 PM
Last year, Microsoft released the first version of IIS diagnostics toolkits&amp;nbsp;withLog Parser 2.2SMTPDiag...
# Server: Microsoft-IIS/6.0\r\n said on 17 January, 2006 11:46 PM
Mm.... this is kinda late, but heck there wasn't one scheduled for this month [:)].&amp;nbsp;I posted this...
# Server: Microsoft-IIS/6.0\r\n said on 18 January, 2006 01:01 AM
Mm.... this is kinda late, but heck there wasn't one scheduled for this month [:)].&amp;nbsp;I posted this...
# Server: Microsoft-IIS/6.0\r\n said on 18 January, 2006 01:02 AM
Last year, Microsoft released the first version of IIS diagnostics toolkits&amp;nbsp;withLog Parser 2.2SMTPDiag...
# Norm said on 19 January, 2006 03:30 PM
HI,
I have a few questions.
I have Windows 2K with IIS with Frontpage Extentions running. I want to be able to setup Forms in Frontpage so that when the form is filled out, it will be sent to an email address. Right now when I try this, I get an Event Log saying "unknown email address".
I guess my question is in IIS, is the Virtual SMTP Server the only thing that has to be setup to get this to work?

I found some information on how to setup the Virtual SMTP Server but it is still confusing. For example, in IIS under the SMTO Virtual Server under Domain, select NEW - DOMAIN then I have a choose between Remote or Alias, I think this should be Remote so I choose Remote. Then it asks "What is the address space of mail that is to be delivered by this domain? Do I just make up a name and put it in the box??? I did try that but I get the error mentioned above.

Thanks for any help.
# qbernard said on 20 January, 2006 02:25 AM
Err. I think you are having another problem. It looks like you are confuse with SMTP and not SMTP is not sending mail.
a) first of all, your Frontpage question. To be frank - I'm not sure, coz I never use frontpage before :( anyway - try post it to frontpage newsgroup.

b) IIS SMTP is design to help you relay emails. I don't configure any remote or alias for new virtual server as the default one is enough to fulfill my needs.

So, first, you need to understand what you want to do? to relay email? forward to smart host? or ?

Here's some generic SMTP KB that should give you a better picture.
HOW TO: Configure the SMTP Virtual Server for Message Delivery
http://support.microsoft.com/?id=303734

HOW TO: Configure a Remote Domain for an Internet Information Services SMTP Mail Relay Server in Windows Server 2003
http://support.microsoft.com/?id324272

HOW TO: Set SMTP Security Options in Windows Server 2003
http://support.microsoft.com/?id=324285
# Norm said on 20 January, 2006 08:26 AM
Hey thanks again. I'll try and find some Frontpage Newsgroups and see what they say.

All I'm really trying to do is to get my website to email messages that come from a FrontPage Extentions Form on a webpage.

# John Baker said on 25 January, 2006 07:15 AM
Here has more details:

http://www.determina.com/advisories/securityadvisory_dec202005.html

"The reference counter responsible for the vulnerability is also present in IIS 5.0 on Windows 2000, but the code that deallocates the object is not there. Windows 2000 and Windows 2003 are most likely not affected by this vulnerability, but the Determina Security Research team is still investigating alternative exploitation vectors."

As there reason why IIS 5.0 is not effected.
# BasCN said on 27 January, 2006 01:30 PM
Hi,

I've the exact same problem as written above. Only I don't have the CD with WindowsXP SP2 Professional. I bought a brand new laptop and Windows was pre-installed.

What can I do? Please help me out

Thanks
# qbernard said on 30 January, 2006 03:14 AM
Sounds like your original installation media has been integrated with SP2. What's the status of the esentutl checking? error ?
# David said on 30 January, 2006 03:29 AM
Yeah, Chris has been and will continue to be very busy.

Getting IIS Diagnostic Toolkit out has been chewing up a bunch of time recently, but we are nearly complete with it all.

//David
# David said on 30 January, 2006 03:34 AM
Minor details:

You probably do not want to use the older versions of WFetch. There were some pretty bad bugs in there that were fixed in WFetch 1.4.

TraceDiag will only be available on WS03SP1 and later because ETW Tracing was introduced in IIS6 for SP1. I know because I had to make this versioning happen in the MSI. :-)

http://blogs.msdn.com/david.wang/archive/2006/01/18/IIS_Diagnostics_Toolkit_January_2006_Released.aspx

//David
# qbernard said on 31 January, 2006 03:09 AM
Great :) thanks for update.
# gavish said on 05 February, 2006 02:09 AM
Hi I have the same problem with a new computer i have. It is a fresh installation of win xp sp2, and I can't install the iis. i already asked for a new win xp cd, and tried the 2 methods.

please if some one can help.
# Paul Williams said on 07 February, 2006 01:05 AM
Thanks so much. Saved my day and night. Could have spent ages trying to find that out.
# Michel's IIS, ASP and General Windows platform corner said on 07 February, 2006 03:06 AM
Good tools are an indispensable part of any troubleshooting effort. This section identifies tools that...
# Tim said on 10 February, 2006 04:43 PM
man I have been screwing with this for 1 1/2 years. (it wasn't vital that I run an ASP app on my box but convenient) Finally I don't have to log on somewhere else to debug one of our legacy apps! Weeeeee!
# Server: Microsoft-IIS/6.0\r\n said on 26 February, 2006 12:33 AM
Mm.... this is kinda late, but heck there wasn't one scheduled for this month [:)].&amp;nbsp;I posted this...
# Server: Microsoft-IIS/6.0\r\n said on 26 February, 2006 12:33 AM
Last year, Microsoft released the first version of IIS diagnostics toolkits&amp;nbsp;withLog Parser 2.2SMTPDiag...
# Server: Microsoft-IIS/6.0\r\n said on 26 February, 2006 12:34 AM
Came across this great article from the TechNet Magazine which talked about different tips to boots up...
# Server: Microsoft-IIS/6.0\r\n said on 16 March, 2006 11:19 PM
LOL! After been missing for two months + all the complaints, Chris finally come out from the closet and...
# Server: Microsoft-IIS/6.0\r\n said on 27 March, 2006 08:30 PM
I talked about this last year asking if you guys like to see if&amp;nbsp;FTPS is&amp;nbsp;to be included in IIS...
# gertjan said on 28 March, 2006 08:57 AM
same for me, new computer XP with integrated SP2 installed.
don't get IIS to work properly
# qbernard said on 29 March, 2006 01:33 AM
You have tried both the workarounds and none work?
Do you have the installation media CD? which file you get prompted?
# Server: Microsoft-IIS/6.0\r\n said on 29 March, 2006 03:48 AM
Wow! wonder how the folks managing microsoft.com uses log parser? They have been so kind, after first...
# Rachel said on 04 April, 2006 04:25 PM
I am also getting the same problem. I ran through method 2 and everything went fine until the last command. At xpsp2 ... It does not seem to recognise that command and tells me that command does not exist???
What am I doing wrong?
# qbernard said on 04 April, 2006 11:28 PM
You need to type it at the XP SP2 CD drive path, where do you get your SP2 ? is it a full copy ? you should get the package here, then extract it... http://www.microsoft.com/downloads/details.aspx?FamilyId=049C9DBE-3B8E-4F30-8245-9E368D3CDB5A&displaylang=en
# Suryanto said on 07 April, 2006 10:01 PM
The main problem was MSDTC was not running when we install IIS. During IIS installation it will try to create IIS Package and it failed. If you fix MSDTC problem before installing IIS, IIS installation will sucessfully create the COM+ package, and everything will be fine without manually created IIS pacakge.
# rashmi said on 11 April, 2006 05:21 PM
I have installed IIS but It is not running and If I try to start it manually It's giving error
# qbernard said on 11 April, 2006 10:43 PM
What error ? file not found? Have you look at the KB?
# Jeffrey Tindillier said on 14 April, 2006 11:30 AM
Congrats on the good job
# Peter Schmidt said on 25 April, 2006 03:27 AM
Congrats on the re-award, well deserved. You are doing a great job.
# Matias Haldmeyer said on 26 April, 2006 03:39 PM
An international bug, im from Argentina, I've the legal WinXp sp2, but it doesn't work. I tried several times, I even try to get the files from another PC that had IIS alredy working but it didn't work too. now im dowloading the SP2 as qbernard say. If it work you'll have news. thanks
# qbernard said on 26 April, 2006 10:12 PM
Thanks for the update Matias
# Alun Jones said on 27 April, 2006 11:38 AM
Deploying SSL in IIS is a whole lot easier than deploying SSL in anything other than IIS. It would be nice to see Microsoft come out with a general certificate wizard.
# Casey Lengacher said on 28 April, 2006 06:44 PM
In general, I'm finding deployment of SSL in IIS to be fairly straight-forward; however, I am having one difficulty that I have yet to resolve.

I've setup a website so that at the lowest level possible, all content is to be delivered using SSL and 128 bit encryption via the checkboxes accessed under Directory Security.

I'm doing this because this site is for a DotNetNuke installation, and while there are some URL manglers supplied by third party vendors, I'd just rather make sure I knip the weird exceptions and their faulty code in the bud by blocking everything with a mechanism that sits below their code.

So I tried this out, secured the whole site, then went to the default file for the site and unchecked the SSL protect just for that file.

Now, if I type in the usual URL of http://soandso.org, I still get blocked. But, if I type in http://soandso.org/default.aspx, I do not.

Apparently there is something else going on that overrides the override if the override is on a file being accessed by the default content mechanism?
# qbernard said on 30 April, 2006 12:10 AM
Interesting Casey... while I'm not sure how DNN work all together, but could you look at the IIS log entries, and see what's the different between visiting the domain url itself and url + default doc. when you said you got blocked, you are referring that you hit the 'required ssl page' right?
# Andre said on 01 May, 2006 01:50 AM
I have a ssl web site that works fine 99% of the time but one particular user is intermittently able to stop https for all traffic. The website is still available not using ssl, so it is not iis or the website that caused the problem. Is this weird or what, that a user is able to stop the website for everyone. There is obviously still some problems with microsofts https server. I hope microsoft is aware that their https implementation still need some work. I am kicking myself now I did not use Apache.
# qbernard said on 03 May, 2006 10:03 AM
Interesting, Andre. 'that a user is able to stop the website for everyone' ? You mean when he/she browse the site via SSL, the IIS just stop responding ? I personally have not seen this before. have you try different browser on the client machine? when it's not responding... can you browse simple html page via http ? I suggest you post this + more detail to public IIS newsgroup, we can discussed over there.
# wouter ramon said on 04 May, 2006 09:30 AM
For me, problems disappeared after reading/applying all this comments. I recapitulate for the ones who want to see everything in 1 comment:

A) APPLY http://support.microsoft.com/?id=301919

1. Open registry editor, locate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3, and then delete this key.
2. From the Start menu, point to Settings, click Control Panel, and then click Add/Remove Programs.
3. Click Add/Remove Windows Components.
4. Proceed through the wizard, and accept all of the defaults.
5. Restart the computer.

B) Start the service Distributed Transaction coordinator

C) Apply the fixes of this webpage

CD %windows%\system32\inetsrv
msdtc -resetlog
rundll32 wamreg.dll, CreateIISPackage
regsvr32 asptxn.dll
IISRESET

Good luck!
# Robin Irwin said on 09 May, 2006 07:15 AM
I tried method 2 in the KB article and have had no luck. When I integrate the installation I get a message that this hasn't been successful. I think this is because I have installed updates (automatic updates to on). In our organisation this is not recommended - now I see why!
# Tomek said on 10 May, 2006 04:16 AM
If you still experience this problem (like I did) you may try to restart and/or unistnall/intall Distributed Transaction Coordinator.
The commands to install/unistall dtc are:
msdtc.exe -install
msdtc.exe -uninstall

You may also check http://support.microsoft.com/?id=891801

Actually I don't know what I did to fix the problem but now I am able to see asp pages and COM+ Applications in Component Services.

HTH
# Chris said on 11 May, 2006 03:14 PM
Thank you, you're a star.
# xinrong said on 14 May, 2006 05:32 PM
thank you so much!

at first i can't do step b.
than i found additional instructions from
http://www.brooksyounce.com/XpAspFix.htm

and i typed
"msdtc -install",
before step B

and then everything works fine!

# Nadxelle Velasco said on 16 May, 2006 11:35 AM
I have a brand new computer with XP Professional SP2 and I have this instalation disk but I don't have the Windows XP Professional 'Only' disk so I can't try the method 2.
I've already try with the method 1 but was unsucessful.
What can I do know?
Do I have to buy a Windows XP Professional without the SP2??
Is there a method to install the IIS in another way??

I REALLY need Help!!!
# john said on 17 May, 2006 02:41 PM
your answer did it A+
# qbernard said on 18 May, 2006 12:42 AM
Nadxelle,

If your machine is already build with SP2, I don't think this apply to you as your source should be already integrated with SP2.

I have not seen a pre SP2 build having this problem before. you got the same prompt during installation?

if yes, you might want to talk to the pc vendor and see if they can help you as your source should be already integrated with sp2.
# koora said on 24 May, 2006 04:11 AM
ok its good and enjoyyyyyyyy
# felix marrero said on 24 May, 2006 07:36 PM
I need to get IIS install in my computer
# qbernard said on 24 May, 2006 11:05 PM
What's the problem you facing when you try to install IIS ?
# qbernard said on 30 May, 2006 07:39 PM
Thanks.
# Shibaram said on 09 June, 2006 08:46 AM
Worked great!!! thanks a lot
# Jan said on 11 June, 2006 09:11 PM
I am having problems when I run the following steps too:

msdtc -resetlog
rundll32 wamreg.dll, CreateIISPackage
regsvr32 asptxn.dll

The error that I faced is warmreg.dll module cannot be found.

May I know if there is anything that has gone wrong?

TIA!
# qbernard said on 11 June, 2006 09:28 PM
Are typing the command at this path ?
%windir%\system32\inetsrv
# Adrian said on 13 June, 2006 04:50 PM
This problem drove me crazy for about 5 hours. I had problems with everything, strarting from the "class not registered", then going through the "regsvr32 asptxn.dll" thing.

Thanks a lot for sharing.

Best regards from Argentina!
# Andreas Kraus said on 14 June, 2006 03:24 AM
It's really nice and it will be a big step, can't wait to use it :)
# absco said on 15 June, 2006 11:32 AM
Genius!! Thanks
# Andrew said on 15 June, 2006 06:16 PM
I was also getting this error:

Event Type: Warning
Event Source: W3SVC
Event Category: None
Event ID: 36
Description:
The server failed to load application '/LM/W3SVC/1/ROOT. The error was 'Class not registered'.

Using the information in one of the earlier posts by Bernard fixed everything for me (pasted in below). Without step 1, the rest of the steps would not succeed.

Although there is a typo in step 3. It should be just:

3. regsvr32 asptxn.dll

># re: The famous 'Class not registered'
>I just found this from Googel searches and it >was exactly what I needed to do.
>
>1. comand line "msdtc -resetlog"
>2. rundll32 wamreg.dll, CreateIISPackage
>3. rundll32 regsvr32 asptxn.dll
>4. IISRESET
>
>I can run ASP finally!
>
>Thanks a lot.
>Wednesday, May 11, 2005 7:26 AM by bernard
# zo said on 15 June, 2006 07:37 PM
thanks for posting this! It worked!
# Rob said on 16 June, 2006 11:19 AM
Fantastic fix to a really irritating (and time consuming) problem!

Thanks
# MAXIMEP said on 16 June, 2006 03:02 PM
Hello
I have the same problem.
Hall was correctly configured, AND WORKS, until I install SP1 on the server.
Now I have Acces Denied when I connect remotely, But works fine localy.

Any Ideas ???

Thanks
# qbernard said on 16 June, 2006 11:49 PM
Mm.. sp1. interesting. I have not tested it with SP1 yet. You might want to get filemon / regmon from sysinternals.com to trace the access denied.
# David Wang said on 17 June, 2006 03:21 AM
Casey - You only set the exception on metadata for http://soandso.org/default.aspx">http://soandso.org/default.aspx

When you make a request to http://soandso.org , IIS has to read metadata for http://soandso.org to decide how to handle it. The request ends up being treated as 30x courtesy redirect to http://soandso.org/ (note added trailing backslash on the courtesy redirect). The client then makes a second request to http://soandnso.org/, which IIS processes with the default document handler and in turn executes http://soandso.org/default.aspx">http://soandso.org/default.aspx and triggers its metadata.

http://blogs.msdn.com/david.wang/archive/2005/10/14/HOWTO_IIS_6_Request_Processing_Basics_Part_1.aspx

The metadata for http://soandso.org and http://soandso.org/ do not contain the exception and thus requires SSL protect.

//David
# DamPee said on 19 June, 2006 09:14 AM
Thanks!

The error occurred on a machine of a client of mine after uninstalling windows media streaming server on a windows 2003 server.
# Channa said on 19 June, 2006 08:18 PM
Just follow these steps

Check in the windows services if Dstributed Transaction Cordinator is insatllled and in "Started" state if not run
1. comand line msdtc -install

Then

2. rundll32 wamreg.dll, CreateIISPackage
3. rundll32 regsvr32 asptxn.dll
4. IISRESET


It should start working
# Saddam said on 05 July, 2006 02:36 AM
I have DLLRegisterServer 0x80040154
error while
rundll32 regsvr32 asptxn.dll
What should I do?
# qbernard said on 06 July, 2006 10:47 PM
Saddam, have you try the first two commands?
1. comand line "msdtc -resetlog"
2. rundll32 wamreg.dll, CreateIISPackage

and during 'regsvr32 asptxn.dll' do you see any addtional event log error?
# jewel said on 10 July, 2006 05:37 AM
Thanks for u, this article really help me for understanding iis log.
I am intresting about 530 event. Can be this event alone... without 331 event i.e. somebody can pass user identyfication and try to login entering password only?
# yan said on 10 July, 2006 09:11 PM
Hello,

for see your log go to :

C:\WINDOWS\system32\Logfiles\MSFTPSVC1

# qbernard said on 11 July, 2006 10:46 PM
Hi Jewel,

Interesting, I have not any 530 for 'pass' event withouth 331 username input. can you post your log file here?
# IIS Digest » IIS patches said on 12 July, 2006 04:54 AM
PingBack from http://www.iis-digest.com/?p=183
# Livin life... said on 15 July, 2006 12:42 AM
Introduction
Log Parser 2.x is, in my skewed perspective, the coolest tool Microsoft has ever released.&amp;nbsp;...
# Manoj said on 15 July, 2006 01:27 PM
I had faced all the problems listed in this thread.

I finally got it working. Thanks Bernard.
I had to do what you said above:

"First fix the MSDTC, then com+, then IIS."

When I first started with my ASP pages not working, I started searching for help on IIS, and trying to fix that.  Re-installed many times.  No luck.  
More searches lead me to Com+ issues under Component Services. I Couldn't open any folder under My Computer in Component Services.

Then I found this thread, and got stuck at
>rundll32 regsvr32 asptxn.dll
like many people here. I too got that DLLRegisterServer error

But after re-installing MSDTC, everything worked.

So like Bernad, I suggest:
A) APPLY http://support.microsoft.com/?id=301919

B) You may also check http://support.microsoft.com/?id=891801

C)
CD %windows%\system32\inetsrv
msdtc -resetlog
rundll32 wamreg.dll, CreateIISPackage
regsvr32 asptxn.dll
IISRESET

Good Luck
# Graphfixz said on 20 July, 2006 06:06 PM
THe link to LPChap2.zip is broken!!
# qbernard said on 21 July, 2006 11:57 PM
Try this new link -
http://download.it-hq.org/zip/LPChap2.zip
# Ravi said on 23 July, 2006 01:38 PM
Hi,
I am having "class not registered" issue after trying all the steps mentioned above. I will explain my situation in detail below:
1. I installed IIS 5.1 and the front page extensions.
2. I installed VS.NET 2003 and tried to open a  new project. I got the error "can not open the application because no web server was detected at http://localhost/webapplication1"
3. I tried to perform the steps mentioned in your blog exactly as mentioned in the following order.

3.1) I was able to acess the My computer in Component Services MMC Snap-In. Hence i did NOT perform the step to fix the COM+ services first by using the microsoft kb http://support.microsoft.com/?id=301919

3.2)  I directly went to "Delete IIS related package in Component Services MMC" step. Strangely, i found that there was only
IIS Utilities listed in the MMC under MyComputer-->COM+ applications.
I went ahead and deleted each invidual components inside the IIS utilities package i had. I was not able to able to figure out how to delete the IISUtilities directory itself; which wasw empty at this point as i had deleted all of its contents.

3.3)Then i followed the steps b and c as mentioned.
c:\winnt\system32\inetsrv\>rundll32 wamreg.dll, CreateIISPackage -- This step completed sucessfully without any error

c:\winnt\system32\inetsrv\>regsvr32 asptxn.dll - This step completed sucessfully without any error and also recived windows dialog box indicating sucess.

Enter IISRESET at command prompt -- This is where i get the error message again "class not registered".

Please help me ..i had been trying to solve this problem from a long time..Thanks

# qbernard said on 23 July, 2006 11:16 PM
Ravi,

First, do you have any other event log ? like MSDTC? if your com+ catalog is fine, then you can skip it. but i would still prefer you follow the steps, especially on the add/remove program wizard, just click 'next' all the way, it will clean up com+ catalog... the reapply all other steps.
# Puja said on 24 July, 2006 03:14 AM
Hi,
i have an problem in installing IIS.After installing IIS, the default web site(control panel->Admin tools->IIS)under computer name is showing stopped.When i try to run it manually, it is displaying internal error. How can i solve this problem.Please suggest.
Thanks.
# qbernard said on 24 July, 2006 03:33 AM
Can you post the error message here? do you see log entries in event viewer as well?
# Ravi said on 24 July, 2006 11:53 AM
Hi Bernard,
Thank you very much for the help. Actually the issue was resolved using a different approach. Seems like McAfee was the main culprit. I will explain the problem in detail so that someone else will not waste time like i did:
1. I installed IIS when McAfee was turned ON.
2. I encountered the class not registered error.
3. I uninstalled/turned OFF my McAfee security center.
4. I uninstalled my IIS using the windows components add/remove option in control panel.
5. I installed IIS again and Voila! everything is perfect. I did not have to go through any of these steps listed above.

Please note that i tried installing IIS several times after i encountered error. But the most important thing i realised is that "IIS did not install itself properly with McAfee turned ON. So everytime i tried to reinstall windows perhaps realised that IIS was already installed and did nothing."
ONLY AFTER I TURNED OFF McAFEE, UNINSTALLED IIS AND THEN REINSTALLED IIS, It was sucessful!
# qbernard said on 24 July, 2006 08:02 PM
Cool. This is the first time I see McAfee name with this error msgs. I know McAfee does break or prevent IIS to function probably. but causing this error? mm... what McAfee product did you install?
# Ajay Malhotra said on 25 July, 2006 05:57 AM
Sir,
I have installed IIS
The problem is i get "Default Web Site(Stopped)"

When i start the Default web site it gives a message saying service cannot be started

when i restart iis it again gives the message as the service cannot start

my operating system is win xp proffessional service pack 2

Please give me the solution
# qbernard said on 25 July, 2006 09:33 PM
Ajay, what's the error msgs in event log? don't think this is related to sp2. to speed up the troubleshooting, pls post it to public IIS newsgroup or www.iis.net.
# David Laub said on 27 July, 2006 04:02 PM
I just purchased an HP Pavillion dv8000 laptop & ran into this exact problem - AFTER I installed Visual Studio 2005 Express products.  I'll never know if Component Services was screwed up fresh from the factory or occured after downloading the Microsoft software.
# yilaylay said on 29 July, 2006 11:53 AM
Yeah,it works.
It spent me one week to solve the problem.
If I didn't happen to see your post , my
nightmare would reside always. Thank you!!!!
# Dimitri said on 01 August, 2006 11:52 AM
Please test this with SP1, it doesn't work properly.
You have to give Full Control to the LM level to see websites, then you see the websites. Still, if you have Full Control on a certain website, you can for example create a virtual directory, but you can never delete it. Also when you request the properties you get an "Access Denied" popup, but you can still see and change properties after that. Anyone know how to get this working properly ?
# Mahdigras said on 03 August, 2006 01:10 AM
I still ahve the problem after doing all u guys suggested. I have Installed Microsoft Script, deleted my programs n ts still there. PLease help.
# Misfit said on 03 August, 2006 05:02 PM
Fantastico!  This saved me.  Thanks a ton.
# afsar ali shah said on 06 August, 2006 02:54 AM
i have bought p4 dell pre installed win xp with sp2 ...
when i tried to install ISS i was astonished to see there is no option of ISS (Add/Remove windows components)...

plz tell me how to do it
my email is ask4ali@hotmail.com
# qbernard said on 07 August, 2006 01:20 AM
Shah,
Are you using XP Home, if it is - then IIS is not available on XP Home.
# IIS Digest » IIS 7.0 sneak peek said on 10 August, 2006 02:28 AM
PingBack from http://www.iis-digest.com/?p=209
# Renato said on 13 August, 2006 08:11 AM
Hi there, I am utterly confused.I have sp2 installed by virtue of Windows Update.  I therefore don't have a CD with sp2, which is what it is asking when I go into Add Components in order to install IIS.  Thanks to Google, I have read other people's attempts to rectify this problem.  I have just now tried
esentutl/d:\windows\system32\security\database\secedit.sdb.
I get error message
Error:Access to source database':\windows\system32\security\database\secedit.sdb'   failed with jet error -1022.  operation terminated.

Would appreciate very much if someone out there could help me.  Thank you.

Regards,   Renato.
# bswain said on 13 August, 2006 06:18 PM
My HP Pavilion dv8000 also has this problem.  I reset it to factory defaults with their recovery tool, tested Com+ and it failed.  This means that  COM+ was broken as it came from the factory.

HP support didn't help and stopped receiving my requests for help.

Anyone else having problems with their Pavilion dv8000?  Maybe there's a problem with this computer?
# qbernard said on 16 August, 2006 12:53 AM
Are you logon as local administrator?
# qbernard said on 16 August, 2006 12:55 AM
Wow! HP stop helping you? Mmm... anyway have you try to fix the com+ error base on the suggestion? what do you got in event log ?
# Renato said on 19 August, 2006 07:28 AM
Can someone please help me? Am desperate.
Regards, Renato
# qbernard said on 20 August, 2006 01:29 AM
Renato, as mentioned in previous reply. are you login as local administrator. you error is saying the attempt to fix the installation database failed - access denied.

if you need fast response. post it to public IIS newsgroup, there'll more experts helping you round the clock.
# Renato said on 22 August, 2006 11:25 AM
qbernard. thank you for your responses. I am now showing my lack of sophistication, but I am confused. I am logon as administrator.
Settings/UserAccounts reveal that I am the administrator, says "Renato Computer Administrator".  What do I do??? Regards, Renato.
# williambeyond said on 22 August, 2006 09:22 PM
I have the same problem too! My server WinServer2003 R2 have SP1 on,
I have gave Full control to every node, but when I try to connect to the server remotely via IIS Manager, it just fail with "You have been denied access to this machine"

I have it working before without SP1 on a window2003 NT server.

any help?
# qbernard said on 22 August, 2006 09:27 PM
Ok. I think this could be path issue. where is your windows directory resides? drive c or d?
ensure you are typing:
C:\WINDOWS\security\Database>esentutl /g secedit.sdb
# qbernard said on 22 August, 2006 09:29 PM
SP1 or even R2 has new security restriction. I have no time to test it yet. So it could due to the new restriction that this workaround is not working.
# williambeyond said on 25 August, 2006 12:32 AM
hm... then I will have to create a utility similar to IIS Manager but allows non-server-admin users to be able to administrate IIS,

is there any reference/example/.NET API I can follow?
# qbernard said on 25 August, 2006 02:49 AM
Hi William,
Glad to know you are developing the utility. While I don't know the exact API, but generally you can use the WMI, ADSI interfaces to manage IIS. Some example here
http://www.microsoft.com/technet/scriptcenter/scripts/iis/iis6/default.mspx

for .net you can use system.directoryservices
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/iissdk/html/cd63ff7d-f84b-4a1a-8c87-2a72fcf33402.asp

bare in mind that no matter what interface you use, the account need to have permissions on the metabase.
# Renato said on 27 August, 2006 11:33 AM
qbernard, thank you for your response; yes my Windows is on "c" drive.As you advised,I typed
C:\Windows\security\Database>esentutl/g secedit.sdb .   I get reply "The system cannot find path specified".  What is  'g' for ??
I then tried:
esentutl/C:\Windows\security\database\secedit.sdb    and I get:
Usage error Invalid mode
Modes of operation
Defragmentation
Recovery
Integrity
Repair
Checksum
Filedump
Press a key for more help
d= defragmentation k=Checksum  G=Integrity    etc......
When I press any of these letters, I get message "..... is not recognised as internal or external command.

Also have been reading the article (id=894351
revision 6) explaining Method 1 and 2 as possible solutions.  Point 4 of method 2 requests sp2 CD which I don't have as stated in my original contact.
Any help you can give me would make me happy.I need IIS because I am learning Dreamweaver 8 ASP Coldfusion and PHP.
I do like to figure things out for myself but this problem is beyong my comprehension.
Even if that statement worked, what would I needed to have done afterwards ?? Would method 1 have been applicable?
I trust you can continue with your replies.

Regards Renato.  
# qbernard said on 27 August, 2006 09:26 PM
The /g is for integrity check. I think again you have type the command wrongly. make sure it is esentutl /g ...... space between esentutl and /g follow by the database name.

you need to install IIS before you can play with dreamweaver, coldfusion and php. so after you fix the database, you then install IIS.
# Renato said on 28 August, 2006 05:40 AM
qbernard, Thank you.   I retyped:
C:\Windows\security\Database>esentutl /g secedit.sdb
making sure of space between esentutl and /g.
I get reply:
"C:\Windows\security\Database'  is not recognised as an internal or external command, operable program or batch file
Regards Renato
# qbernard said on 28 August, 2006 11:29 PM
Arrghh... sigh! You don't have the esentutl.exe ? That's funny, it should be located at \windows\system32\ do you have the file? this should be build in for XP machine. you don't have it? but previous I thought you have and you got the 'usage error invalid mode' error?

You need to go to command prompt first, then navigate to the directory.
a) start menu - all programs - access0ries - command prompt.
b) inside the command prompt, navigate to the database folder "cd\windows\security\database"
c) only then you run the command -
esentutl /g secedit.sdb

got it?
# Renato said on 29 August, 2006 08:21 AM
dbernard, do I now have to apologize for my low level knowledge of Windows technology ??
I' m doing my best. Fom my point of view, I was only doing what I understood you were telling me to do.
Ok, I now did as per your last message. I got message:
Integrity check successful
Operation completed successfully in 0.516 seconds.
Gee, dbernard, now what?? According to aricle id 894351 vers. 6, having got that message means I'm to perform method 2. But then point4
says to load sp2 CD ???? What do I do ??
Gee this is all starting to get like a book.   Regards Renato.          
# qbernard said on 30 August, 2006 01:58 AM
Ok. if you don't have CD, you get the full package.
http://www.microsoft.com/downloads/details.aspx?FamilyId=049C9DBE-3B8E-4F30-8245-9E368D3CDB5A&displaylang=en

then extract the file to a folder. and follow the steps. except using the cd drive, you use the new folder name.

before you do that. can you try reinstall IIS again. does it prompt for cd2 again?
# Renato said on 31 August, 2006 11:43 AM
Hi qbernard, thank you for your response.I felt confident of an imminent resolution. I did, as you said, first try to re-install, and yes it did prompt for CD2 again. Then I did:
1 (a) Start, Run, typed CMD, OK
 (b) typed cd \
 (c) md winxp
 (d) cd winxp
 (e) md i386
2. Loaded original vers. of XP pro. into my CD (drive="D")
3. typed: xcopy /E /I /V D:\i386\*.* /s Drive:\winxp\i386

I got message 'invalid path 0 files copied'
I tried the process again, from 1 (b).
After 1 (c) I got : a subdirectory or file winxp already exists.
After 1 (e) I got : a subdirectory or file i386   already exists.
When I  redid (3), I receved same "invalid path" message
again.
If you can help me, qbernard, thank you. I downloaded that file at school and extracted it using winzip,it created
folder called "i386', I put it on my usb memory stick, at home I access it on my "G' drive. For point 5 of article (id = 894351)
does that mean I type in "G:\i386" , given what you said in your previous reply ??
Regards Renato.
# qbernard said on 31 August, 2006 07:03 PM
In your case:
where do you create the winxp folder in step 1?  drive c: if yes, then it should be:
"xcopy /E /I /V D:\i386\*.* /s c:\winxp\i386"

after that since you don't have the sp2 cd at drive D. you will go to g:\i386 at step 5.
then
"xpsp2 /integrate:c:\winxp"

good luck.

# Renato said on 01 September, 2006 11:43 AM
Thank you, qbernard, for your response. The "xcopy" statement worked, copied 6511 files, then for step 5, I typed      "g:\i386"
I got answer that "g:i386 not recognised as internal or external command". I tried:   "g:"   and it went to  "G:\", and then I typed "i386" and got same reply that i386 was not internal or external command.
I understand that I need to navigate to "G:\i386" and then type in the statement "xpsp2 /integrate:c:\winxp" ,

but, how do I get to "g:\i386" ?
I remember the similar problem I had before, refer-your reply August 28, where I needed to navigate to c:\windows\security\Database before typing the "esentutl" command.Given that "cd\Windows\security\Database" was the answer, I tried: "gd\i386",that sounded OK to me, but I got "system could not find path specified".  
Regards, Renato.

# qbernard said on 03 September, 2006 06:43 AM
You need to catch up on some basic windows navigation knowledge. when I said "g:\i386", you need to navigate to that folder at command prompt.
so again
a) g:
b) cd i386
c) then xpsp2 /integrate:c:\winxp

# frankienapoli said on 03 September, 2006 08:27 PM
Yep, same problem with an hpdz8000. What a pain. I purposely got XP Pro for ASP.NET development. My desktop with Media Edition works fine.
# Renato said on 04 September, 2006 11:50 AM
qbernard, thank you for your responses, you must be losing patience with me, I am losing patience with me. After the "xcopy" statement, screen read: " 6511 files copied C:\winxp> " I type in "g:" the screen read: "G:\>" then I type in "cd i386" the screen read: "G:\i386" then, I type in "xpsp2 /integrate:c:\winxp" and the screen now says "xpsp2 is not recognised as an internal or external command, operable program or batch file G:\i386> " I will email you the screen dump. Regards Renato
# Nick Kuvyrkin said on 05 September, 2006 06:34 AM
Thanks a lot for your tip. This is the only thing that helps.
# qbernard said on 05 September, 2006 08:25 AM
Arrghh.. you would have to try this... since you are using the network version not sp2 cd. http://support.microsoft.com/?id=889719 do it at the g: drive the c:\bin should be c:\winxp. it should be "update.exe /integrated:c:\bin"
# Renato said on 05 September, 2006 02:14 PM
qbernard, I am thankful that you have responded to my queries, but this is all getting me down, I'm losing my hair and its going grey, and I' m too young for that to be happening to me. Will this ever come to a conclusion? I'm sorry, I don't understand your latest reply. Please I don't wish to appear to be disrespectful. The last 2 words of the heading of Article 889719 refers to "windows 2000", point 2 says ".......on a computer that is running on windows 2000". I saw this and I'm going nuts, as my computer is running not on windows 2000 but on XP. And what is it, that I do on "g drive" ?? Is it the "update,exe" statement ?? Also if "c:\bin" should be "c:\winzip", why is "c:\bin" at the end of the statement, and not "c:\winzip" . Also how will the instructions hitherto, affect what needs to be done now? I am not a fellow microsoft specialist, please keep in mind that. Regards Renato
# Sceece said on 06 September, 2006 07:34 AM
I’m running XP Pro SP2. Loaded IIS a couple of weeks ago to check my ASP pages before uploading to server. Has been working fine. It’s gone – I check under control panel>admin tools and IIS has disappeared and I am unable to check ASP pages. Then thought I would go through add programs>window components, tick the boxes and reinstall. It goes though the motions but there is still nothing under admin tools. I then deleted inetpub and all files contained, went through above step and still no joy. I have restarted after each time but nothing seems to work. Can you give me any idea?? Thanks Scott
# Tom said on 06 September, 2006 08:10 AM
Thanks dude, worked a treat.
# aimperial said on 06 September, 2006 06:31 PM
Need to know if someone make it work over 2003 with SP1 ,cause all i got is acces denied i have review a lot of time the permission and simple doesnt work tanx
# frankienapoli said on 06 September, 2006 06:35 PM
Sorry for the confusing previous post. I have an HP Pavillion dv8000z, the AMD model. I popped for XP Pro to do contract work at a variety of places and wanted the connectivity features. I have Media Edition on a desktop at home. Both OS's can run IIS. The dv8000z has the exact problem. Don't know if it's XP Pro, the box, or what. I haven't tried to fix with this method yet but will when I can risk the machine blowing up. Thanks all. Frank
# qbernard said on 06 September, 2006 09:45 PM

I don't know what is loaded with dv8000z. is it XP Pro, are you having the 'class not registered' error msgs or ?  have you install IIS ?

# qbernard said on 06 September, 2006 09:47 PM

That could be it with new changes in SP1, like component services security enhancement,etc. I have seen many users claimed that this workaround can't be applied to w2k3 sp1.

# qbernard said on 06 September, 2006 09:48 PM

IIS gone? installation any error ? check the iis6.log at %windir% and look for failed entries.

# qbernard said on 06 September, 2006 09:54 PM

Renato,

I will try my best, been busy. Now it's typo error. it should be "update.exe /integrated:c:\winxp"  according to where you copy the source file. what you are trying to do is integrate the sp2 to the original installation file. and hope this will solve your issue and allow you to install IIS. That article shows how to do it in w2k, but I believe it applies to xp as well. coz you got the downloaded sp2 not SP2 CD. I think you should have update.exe there. it's been a while I applied sp2. I don't have the file now.

Anyway, i know this has taken lot of times. if you need quick and fast response, try post this to public newsgroup - google this online. or contact Microsoft support at your local area. Experts there will help you realtime.

# Mike K said on 08 September, 2006 07:33 AM
Thansk for the great tip. I ran the cited KB and dll commands in the top post and it FINALLY works after 2 days of searching for the answer.
# Renato said on 11 September, 2006 10:00 AM
Hi qbernard, again thank you for being kind in answering me.I tried and tried and tried. Regarding article 889719, I already had on "c:\winzip" copy of XP, and on "G:\i386" I had SP2, so I proceeded to point 3. I performed point 4 ("G:" then "cd i386") After performing point 5, I got "WindowsXP-KB835935-SP2_ENU.exe /x" with that all too familiar message "is not recognised as an internal or external command...............or batch file". Also, given that I have SP2 on "G:\i 386" what do I put for points 6 and 7 ? I don't understand points 6 and 7. What am I doing wrong ? Regards Renato Regards Renato
# wannabekenobi said on 12 September, 2006 06:09 AM
Hi guys, i had the same problem, and i can see qbernard is slightly frustrated with whats going on, so maybe i can lend a hand, im not sure if its relevant but i found out that the integrate switch doesnt always work, microsoft has an article on methods How to integrate Windows XP Service Pack 2 files into the Windows XP installation folder here: http://support.microsoft.com/kb/900871/ hope its useful
# Ray said on 12 September, 2006 04:04 PM
My problem is that my ASP pages just will not execute on XP Pro...no error messages or anything, they just freeze up and do nothing. It's the most frustrating thing I have ever encountered!!! I disabled McAfee, uninstalled and reinstalled, ran all the tips above (no errors), set security permissions, did the works. Pure HTML works fine, but when I load an ASP page the browser loads forever...a permanent FREEZE with no error messages. Is there somebody who can shed some light on this behaviour? Please... Ray
# Ray said on 13 September, 2006 06:19 AM
I had a slightly different problem. My ASP just would not execute...no error messages to lead me on, the page just loaded forever. I tried all the fixes noted above, but it still did not work. I even reinstalled with McAfee disabled and did all the fixes again. By chance I picked up a tip through another forum that my GLOBAL.ASA file could be the problem, so I renamed it and WHAM, the ASP ran like a dream! However, that was not the end of my misery because no database access was possible without GLOBAL.ASA, so I continued my research and discovered that the Function FrontPage_FileExists(fspath) was the guilty party. I modified it as follows: Function FrontPage_FileExists(fspath) On Error Resume Next FrontPage_FileExists = False set fs = CreateObject("Scripting.FileSystemObject") 'begin of replacement part if (fs.FileExists(fspath)) then FrontPage_FileExists = True end if 'end of replacement part 'begin of deleted part ' Err.Clear ' set istream = fs.OpenTextFile(fspath) ' if Err.Number = 0 then ' FrontPage_FileExists = True ' istream.Close ' end if ' set istream = Nothing 'end of deleted part set fs = Nothing End Function Again, that was not the complete solution as I got an ODBC error as follows: Microsoft OLE DB Provider for ODBC Drivers error '80004005' [Microsoft][ODBC Driver Manager]Data source name not found and no default driver specified. The solution to that is too long to describe here, but you can find it at: http://support.microsoft.com/kb/306345/EN-US/ After doing what they told me I restarted the IIS using IISRESET and I was SOLVED!! I hope this helps somebody as it is invaluable information that can take days to find...
# Rafael said on 14 September, 2006 06:45 PM
Hello, qbernard. Well, I have similar problems. I followed the steps in Method 2 up to #5, but there is no xpsp2.exe anywhere on the CD, nor for that matter anywhere on my windows xp drive, just xpsp2res.dll. The CD does say "Includes SP2". Here is a screen dump: D:\I386>DIR XPSP2* Volume in drive D is VRMPFPP_EN Volume Serial Number is 60B7-C3F9 Directory of D:\I386 08/04/2004 05:00 AM 468,411 XPSP2RES.DL_ 1 File(s) 468,411 bytes 0 Dir(s) 0 bytes free D:\I386>XPSP2 'XPSP2' is not recognized as an internal or external command, operable program or batch file. D:\I386>dir update.exe Volume in drive D is VRMPFPP_EN Volume Serial Number is 60B7-C3F9 Directory of D:\I386 File Not Found Thank you in advance for any help.
# Rafael H said on 14 September, 2006 07:05 PM
Hello, qbernard. Thank you for dealing with this problem. I am having similar one, except i don't even get to running xpsp2.exe because there is no such file anywhere on the SP2 CD, it does say "Includes Service Pack 2" on the CD itself. Thank you in advance for any insight! screen dump searching for the file D:\I386>DIR XPSP2* Volume in drive D is VRMPFPP_EN Volume Serial Number is 60B7-C3F9 Directory of D:\I386 08/04/2004 05:00 AM 468,411 XPSP2RES.DL_ 1 File(s) 468,411 bytes 0 Dir(s) 0 bytes free D:\I386>XPSP2 'XPSP2' is not recognized as an internal or external command, operable program or batch file. D:\I386>dir update.exe Volume in drive D is VRMPFPP_EN Volume Serial Number is 60B7-C3F9 Directory of D:\I386 File Not Found
# qbernard said on 15 September, 2006 01:09 AM

LOL. Thanks WannabeKenobi.

Renato, can you refer to the new KB?

http://support.microsoft.com/kb/900871/

since you already extract all the files, just follow method 2 at step4 and make sure you enter the correct path...

I've been busy for past few days, going to travel again...

good luck.

# qbernard said on 15 September, 2006 01:10 AM

Rafael, can you follow my previous comment to get the xp-sp2 and integrated with orginal installation source first, then retry your installation.

# qbernard said on 15 September, 2006 01:12 AM

Thanks Ray for sharing your solution.

# Easa said on 15 September, 2006 02:21 AM
Hi After adding the UseHostName and setting it to 1 on IIS Metabase for /LM/W3SVC level, i'm still able to see IP address in the content-location header. I accessed the web server using the IP address. Can you please clarify why IP address is revealed. Thanks Easa
# Soren Werk said on 15 September, 2006 04:09 AM
It is now possible to use host header names with SSL on IIS 6.0 on Windows Server 2003 SP1. http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/596b9108-b1a7-494d-885d-f8941b07554c.mspx?mfr=true
# qbernard said on 16 September, 2006 12:33 AM

Did you get the hotfix from MS ? It's been awhile, not sure if MS include this fix in w2k3 sp1. anywhere. assuming you got the fix and after followed the steps, did you restart the computer?

# qbernard said on 16 September, 2006 12:35 AM

Yes, Soren, you are correct. Back then in 2004 when I replied, this is not possible :)

# Frank M. Allen (aka frankienapoli) said on 17 September, 2006 12:34 PM
Success!!! Here is what I found on my HP dv8000z. It looks like the MSDTC service was never installed. All I did was: uninstall IIS. run msdtc.exe -install run msdtc.exe -resetlog start msdtc service install iis run aspnet_regiis -i In IE I type /localhost and get the welcome page. I start VS, create a C# Web App that defaults to /localhost/WebApplication1 and I go back to IE /localhost/WebApplication1/WebForm1.aspx and it works. Thanks all for all the info. Because this is showing up on the HP boxes, I suspect they just neglected to install MSDTC service when they set the boxes up. Anyway, I hope that helps someone else. I was anticipating a long afternoon but didn't have to edit the registry at all and it took about 15 mins. Good luck all. Frank
# qbernard said on 17 September, 2006 08:33 PM

Yeah, glad you fixed it.

# Renato said on 26 September, 2006 10:27 PM
Success, success, success. Thank you qbernard for your help and patience, I hope I didn't annoy you too much. Thank you WannabeKenobi for taking the time and submitting your reply. Thanks guys. Regards, Renato.
# qbernard said on 27 September, 2006 09:39 PM

Woohooooooooo.... Glad you have nailed it down.

# David Lorg said on 04 October, 2006 10:47 AM
Creating a FTP site
# IIS Digest » Sep. - IIS KBs said on 05 October, 2006 02:27 AM

PingBack from http://www.iis-digest.com/?p=249

# Geoff Hughes said on 05 October, 2006 01:26 PM
Ok, I have to admit I am disappointed. With all the cool logos out there, and many of them animated, can't we get something a little more snazy?
# qbernard said on 05 October, 2006 07:11 PM

Mm.. :) I will pass on the point to the product team.

# Tuan Pham said on 07 October, 2006 02:16 PM
Thanks
# Krish said on 08 October, 2006 11:22 PM
Well, it is nice of you to help. Yet, it would be more hlepful if you can add info on how to do it all from step 5 - for people like me. thanks anyway. i was able to do untill step 4/ when i reach step 5 i don't know how to proceed further. I still have that damn error. krs kristtee@mail.com
# qbernard said on 09 October, 2006 09:31 AM

Oh for step5 is actually related to step6 :) it is about NTFS permissions. so for example to manipulate in XP you can refer to this kb.

How to set, view, change, or remove file and folder permissions in Windows XP

http://support.microsoft.com/?id=308418

# Server: Microsoft-IIS/7.0\r\n said on 12 October, 2006 11:04 PM

Starting Windows 2003 SP1, you will be able to configure SSL with your host header websites . I&#39;m

# Steve Schofield Weblog said on 16 October, 2006 10:35 PM

I just posted a blog about IIS6 compression. I was wondering if IIS7 compression was much different.

# Mark said on 18 October, 2006 10:40 AM
I was getting all of the above. However my event log also showed that MSDTC was not starting up. My fix script was as follows: :: repair MSDTC cd c:\windows\system32\ msdtc -uninstall msdtc -install msdtc -resetlog :: repair IIS Package cd c:\windows\system32\inetsrv rundll32 wamreg.dll, CreateIISPackage regsvr32 asptxn.dll IISRESET Ran in under a minute and worked like a charm. This was my first time using ASP on this XPSP2 box, so it may never have been working. The MSDTC errors go way back in my log. I cannot provide any insight as to the all important when did it started. Root cause(s) remain unknown...
# qbernard said on 18 October, 2006 07:46 PM

So you got the same error again?

# Steve said on 20 October, 2006 07:21 PM
I thought I should add to Ravi's problem with McAfee Virus scan.. This problems also occurs when Norton AntiVirus Auto Protect is enabled. So, when installing IIS remember to switch your virus scanner OFF!
# Chris said on 23 October, 2006 09:11 PM
Awesome! I don't normally leave comments, but this just saved me too much time not to voice my appreciation. Well Done.
# Nicholas said on 24 October, 2006 07:55 PM
Shame, I have a customer insisting on shared IIS hosting, who also wants wildcard subdomains for his site, it's simply not possible without giving their site a static ip, in apache this is easy to do an a shared ip, you simply tell apache the ServerAlias *.domain.tld and it will recognise it regarless of the fact that the ip address is being used by other host headers for different sites.
# qbernard said on 25 October, 2006 12:00 AM

Well, feedback already given to product team.

# kerim said on 31 October, 2006 12:55 AM
wooohoooo, it works!!!!!!
# Jesse Hauserman said on 08 November, 2006 08:59 AM
I get it only when browsing ASP pages on one specific server. I am the only one getting this error and it does not occur when browsing ASP pages on other servers. I tried regsvr32 on my PC to no avail. Does it need to be done on the server?
# PCPPC said on 09 November, 2006 03:22 AM

晕。。。还是不行

# Adaptive-Techniques.net » IIS KB’z said on 10 November, 2006 03:02 AM

PingBack from http://adaptive-techniques.net/2006/11/10/iis-kbz

# qbernard said on 12 November, 2006 09:06 PM

什么不行? 所有步骤都试了吗?什么错误信息?

# Marc Wilson said on 13 November, 2006 04:35 AM

I tried all of the above, including adding the IUSER account to Administrators, and I *still* get the 0201 error.  Any more ideas?

# qbernard said on 14 November, 2006 09:07 PM

Mmm.. this is weird. when you register those dll, any error msgs?

# Alun Jones said on 15 November, 2006 02:45 PM

This sounds like typical FTP: URL behaviour.

Remember that ftp://user:password@site.example.com/ means to log on to the FTP server at site.example.com, using user "user", and password "password", then CWD to the root, before producing a listing.

Not perhaps what you expect, but not without precedent.

Perhaps you need to configure your FTP server such that it restricts the user's directory structure in such a way that the home directory appears to be the root directory, then you don't have this problem.

# qbernard said on 16 November, 2006 12:30 AM

Well, this works on IE 6. Next on the restrict part, it needs a mininum read at the root before can redirect. And in user isolation mode, it get stuck in root as well. So something differently changed in IE7 as compare with the previous version.

# Terry Schwarz said on 20 November, 2006 08:46 PM

You mean ... this part of the spec ... RFC 1738 Uniform Resource Locators (URL) December 1994 ... blah ... blah ... blah page 7 ...

  For example, the URL <URL:ftp://myname@host.dom/%2Fetc/motd> is

  interpreted by FTP-ing to "host.dom", logging in as "myname"

  (prompting for a password if it is asked for), and then executing

  "CWD /etc" and then "RETR motd". This has a different meaning from

  <URL:ftp://myname@host.dom/etc/motd> which would "CWD etc" and then

  "RETR motd"; the initial "CWD" might be executed relative to the

  default directory for "myname". On the other hand,

  <URL:ftp://myname@host.dom//etc/motd>, would "CWD " with a null

  argument, then "CWD etc", and then "RETR motd".

I read this as double slash (//) means start from root and single slash is mention as relative. It does say anything about single means root.

Every other browser in the universe I've used works relative path. MS should either justify there position by speaking up or fix there crappy software!

# Yaseen said on 21 November, 2006 02:08 AM

i have a backup certificate with private key and i was tryout import my certificate in IIS but msg appear

Error

CANNOT IMPORT KEY RING BACKUP FILE

Thanks

Yaseen

# Mike said on 21 November, 2006 11:30 AM

I agree...something has changed and this is an absolute mess

# qbernard said on 21 November, 2006 08:08 PM

Interesting. just to check does it work with you import it on another machine of IIS4/5 ? same issue?

# qbernard said on 21 November, 2006 08:57 PM

Thanks for sharing, Terry. I'm not really a hard and fast RFC fans. I'm just a normal user that expect things to work as it is in IE6.0 :)

# Jake said on 22 November, 2006 09:11 PM

It's a bug.

# Mike Hteit said on 25 November, 2006 01:15 PM

i have one webserver (one IP used) setup on IIS 6.0 and it is working fine. however, if i try to add another (and i do it successfully), i can't open web and i get "The system cannot find the path specified". i tried checking the permissions for IIS_WPG and NETWORK SERVICE. still, no luck. i can't get any site running besides the one i already have.

PLEASE HELP

# qbernard said on 25 November, 2006 11:29 PM

Hi Mike, what do you mean by 'try to add another' ? another IIS machine or ? have you try reinstall? and any error msgs or event log?

# marioooo said on 29 November, 2006 08:12 PM

funny

# Server: Microsoft-IIS/7.0\r\n said on 01 December, 2006 11:45 PM

Hehe :) Not just me! You have got the power as well.... to manage IIS via PowerShell. Honestly, I'm not

# Kimberly said on 18 December, 2006 09:51 PM

It's Microsoft "breaking things that used to work" and calling it "more secure". (Yet STILL leaving holes in other areas... and NOT fixing them at all.)

Smart move (again) guys.

# www.consultmelive.com » To fix http 500 error on HP Pavillion 5000 after Dot Net and IIS Install. said on 10 January, 2007 05:05 PM

PingBack from http://consultmelive.com/2007/01/10/to-fix-http-500-error-on-hp-pavillion-5000-after-dot-net-and-iis-install/

# Laila said on 26 January, 2007 05:45 PM

I have a website, when I try to upload aspx pages that made using master page, this error msg displayed:(

# qbernard said on 27 January, 2007 07:51 AM

And have you try the suggestion above? still experiencing same error?

# CenterWeblog said on 29 January, 2007 02:25 AM

PingBack from http://center.slimblogs.com/article/667269/IISNET-Download-

# Server: Microsoft-IIS/7.0\r\n said on 02 February, 2007 12:13 AM

3 months after IIS team debut the first preview with Zend , Preview 2 is out! Read the annoucement here

# Mike Volodarsky said on 02 February, 2007 08:34 PM

Thanks for posting!  A lot of people are very excited about this release, and the upcoming PHP 5.2.1 release that form our foundation for serious PHP support for Windows / IIS.  Be sure to check in again at http://mvolo.com through next week for more coverage of it.

Mike

# Tobin said on 02 February, 2007 11:55 PM

So, tell me what's complicated and I'll do my best to help you. Is it Powershell itself, or is it my explanation of how to use it?  Are you coming at this from a developer perspective or an administrator perspective?  

To keep it simple, what are your paint points with using Powershell and IIS 7?

# qbernard said on 03 February, 2007 01:14 AM

Thanks Tobin, actually is the powershell syntax itself, looks like perl language to me :) How does PS complement appcmd.exe?

# Tobin said on 04 February, 2007 02:42 PM

IMHO, PS could replace appcmd. Putting that notion aside, consider that you can pipe your output to anything else.  That output could be a visual gadget, more text output, a file, or a network connection of some sort. You can filter your output how you want.  The list goes on.  Just like unix shells, the power isn't in typing out long syntax every time you want to do something.  It is in your ability to write shell scripts that you can execute with your own syntax.

For instance, instead of typing:

(New-Object Microsoft.Web.Administration.ServerManager).Sites["Default Web Site"]

I can create a simple script function:

function findSite()

{

 return (New-Object Microsoft.Web.Administration.ServerManager).Sites[$args[0]]

}

and then from that point on, I simply need to type: findSite("Default Web Site")

I can still pipe that output to anything I want.  I can also still format the output however I want.

I suppose as a developer, I find this more appealing that a restrictive command line tool that has a strict syntax.

# qbernard said on 04 February, 2007 11:07 PM

Cool! so in a way PS provides you more flexibility to manipulate data on top of a query and sort of like 'extending' your management power :)

# Tobin said on 05 February, 2007 04:50 AM

Exactly!  And, as my second blog post on the subject demonstrates, you can extend existing managed code with PowerShell.

# qbernard said on 07 February, 2007 05:26 AM

Lovely, I know internally the folks here are using PS with WMI for some general management. For me, I think it's time to learn more about the syntax :)

# Adaptive-Techniques.net » IIS KB’z said on 09 February, 2007 06:15 AM

PingBack from http://adaptive-techniques.net/2007/02/09/iis-kbz-2

# Joe said on 30 March, 2007 01:49 PM

The WebDAV support discontinuation is -brutal-. Does it make any sense to feature security for Windows Vista and then tell users to use FTP to upload files to IIS, transmitting their credentials in the clear?? Arg.

# qbernard said on 30 March, 2007 11:27 PM

Joe,

Well, the deal is that Vista is not suppose to be the production web server, hence DAV doesn't include in the bill. For ftp, If i'm not mistaken there'll be out of band ftp component in near future (LH timeframe) which will support ftps, etc.

# vcsjones said on 02 April, 2007 06:39 AM

I just got my MVP award, and I was half expecting to get to the end of the registration process, and at the end it said "Gotcha!"

# God said on 02 April, 2007 06:42 AM

There is a typo. It should be iwaM, not iwaN.

# qbernard said on 02 April, 2007 09:35 AM

Oops. thanks man.

# qbernard said on 02 April, 2007 09:36 AM

LOL... my registration went well. congrats !

# Alun Jones said on 02 April, 2007 02:46 PM

Congratulations - me too!

# qbernard said on 02 April, 2007 07:24 PM

Yeah.. Alun Alun Alun :)

# Server: Microsoft-IIS/7.0\r\n said on 03 April, 2007 03:36 AM

I talked about Vista SKUs and IIS 7 before :) yet it wasn't that clear as of why you might want to pick

# Server: Microsoft-IIS/7.0\r\n said on 03 April, 2007 03:42 AM

I talked about Vista SKUs and IIS 7 before :) yet it wasn't that clear as of why you might want to pick

# Server: Microsoft-IIS/7.0\r\n said on 03 April, 2007 03:55 AM

I talked about Vista SKUs and IIS 7 before :) yet it wasn't that clear as of why you might want to pick

# Server: Microsoft-IIS/7.0\r\n said on 03 April, 2007 09:42 AM

I talked about Vista SKUs and IIS 7 before :) yet it wasn't that clear as of why you might want to pick

# Joe said on 09 April, 2007 04:26 PM

Well, I get the not-a-production-server idea, but webDAV isn't just for production servers. It's for testing, too. And it's also for file transfer to your computer when you're outside the intranet, something that is painfully missing in Vista now.

The fact is, when you're a small time operation, you want to use your local IIS to test sites you're working on. Removing webDAV basically means Microsoft is saying, "Don't want to work within the intranet? Get longhorn server." This will require both a software and hardware investment for me, just to be able to upload content from the coffee house. I mean, come on!

RE: SFTP, that would be alright, though I think I read somewhere that was only going to be for Longhorn server. If not, I guess I'll be mollified-- but still grumpy! :-)

# qbernard said on 10 April, 2007 12:47 AM

Hi Joe, I will try relay the msgs to the product team, but no promise :) and SFTP and FTPS are two different technologies, whereas formal is using secure shell stuff to wrap over the ftp communication, but ftps is pure SSL cert implementation over ftp protocal.

# Wiebe Tijsma said on 16 April, 2007 02:01 PM

I also miss the WebDAV support (yes for development purposes), any workarounds?

# qbernard said on 16 April, 2007 11:23 PM

Nope :) ftp maybe ?

# Liang-Chih Yu said on 06 May, 2007 03:59 AM

Yes

# Steve Schofield Weblog said on 13 May, 2007 03:03 PM

SMTPDiag is a handy tool for tracking down SMTP based issues. I recently used in a newsgroup posting

# Jayce Ooi said on 17 May, 2007 07:50 AM

It is funny. :P

# Rory Primrose said on 18 June, 2007 08:55 PM

So I now have my new laptop which came bundled with Vista Home Premium. After I had it set up, I then

# Mike Volodarsky said on 25 July, 2007 10:35 AM

Hi Bernard,

Thanks for posting about this issue!

You've exposed one of the many cases where runtime validation rules for configuration are different from the base configuration validation rules.  This is a necessary evil of the new configuration system - there is simply no way to encode and express the richness of runtime validation into a declarative configuration store.  The .NET configuration system is based on code and it can do a little more validation on the configuration system itself, but still not enough to completely describe the validation done by a runtime consumer of it.  In most of these cases, we try to do validation at runtime and give decent errors when we detect stuff that doesnt make sense, but then again, this doesnt describe every possible way you could configure the server.

In this case, we consider this behavior a bug in the UI because it does not allow you to correct the condition.  From the AppCmd perspective, the delete vdir/create application approach is the answer here.  In IIS7, we think a lot more strictly about the difference between vdirs and applications - an application is a completley different beast from vdir unlike IIS6, where it was simply a vdir marked for application isolation.  You can read one of my recent posts on the subject here: mvolo.com/.../Creating-IIS7-sites_2C00_-applications_2C00_-and-virtual-directories.aspx.

Thanks,

Mike

# qbernard said on 26 July, 2007 09:27 AM

Thanks Mike, and I do aware of the redefinition between site, vdir and app objects in IIS 7.0 and came out with these.

- A Web site must contain at least one application.

- A Web application must contain a root virtual directory.

- A virtual directory belongs to only one application

# Scott Hanselman's Computer Zen said on 07 August, 2007 05:55 PM
# Scott Hanselman's Computer Zen - 32bitness and 64bitness and migrating DasBlog on IIS7 and ASP.NET under Vista64 said on 07 August, 2007 05:55 PM

Pingback from  Scott Hanselman's Computer Zen - 32bitness and 64bitness and migrating DasBlog on IIS7 and ASP.NET under Vista64

# Server: Microsoft-IIS/7.0\r\n said on 12 August, 2007 01:21 AM

Ever wonder where to configure HTTP KEEP-ALIVE in IIS 7.0, or where to configure detail error message

# toettoe said on 08 September, 2007 03:27 AM

In Vista "home premium", some of these features are missing, like the "http headers"-section. Crippling without good reasons.

# Bernard said on 10 September, 2007 09:39 AM

Well, this is per windows 2008 server. For Vista, you will have to wait till SP1 or try to configure it via appcmd.exe first.

# David Dellinger said on 12 October, 2007 12:36 AM

It is not new design when it breaks things that used to work! Any workaround to get this works?

# qbernard said on 15 October, 2007 08:19 AM

Hi David,

Yes, I would agreed with you that it should not breaks thing that used to be working. Yet, IE team did it, and they have their reasons behind, etc. why? I have no idea, you can ping them via the team blog url I posted.

And for the workaround? none - afaik. so try windows explorer :) ??

# internet » Blog Archive » Security Alerts - Microsoft Internet Information Services Could … said on 24 October, 2007 03:08 AM

Pingback from  internet  &raquo; Blog Archive   &raquo; Security Alerts - Microsoft Internet Information Services Could &#8230;

# Windows Vista News said on 13 November, 2007 09:15 PM

Interesting: msmvps.com

# IIS KBs - October 2007 (More IIS 7 Status Code) said on 13 November, 2007 10:11 PM

Pingback from  IIS KBs - October 2007 (More IIS 7 Status Code)

# hoozingo » Blog Archiv » IIS KBs - October 2007 (More IIS 7 Status Code) said on 14 November, 2007 07:26 PM

Pingback from  hoozingo  &raquo; Blog Archiv   &raquo; IIS KBs - October 2007 (More IIS 7 Status Code)

# Windows Vista News said on 24 January, 2008 01:00 AM

Interesting point at msmvps.com

# Filezilla Probleme - Server Support Forum said on 03 February, 2008 08:44 AM

Pingback from  Filezilla Probleme - Server Support Forum

# Errore con IIS - MasterDrive.it - Information Technology Developers Community said on 22 February, 2008 06:29 PM

Pingback from  Errore con IIS - MasterDrive.it - Information Technology Developers Community

# Server: Microsoft-IIS/7.0\r\n said on 12 March, 2008 09:48 PM

It is hot! with the official release of W2k8 / IIS 7.0 , Microsoft has released more goodies for you

# error code 8004e00f said on 08 April, 2008 07:23 PM

Pingback from  error code 8004e00f

# IIS 7.0 Administration Pack! | Log Parser Tips said on 01 May, 2008 06:04 PM

Pingback from  IIS 7.0 Administration Pack! | Log Parser Tips

# Marco said on 05 May, 2008 09:22 PM

Hello

# Kingcean said on 05 May, 2008 10:41 PM

There are some ASP in my computer, but i find it cannot run as well as before when i update iis7 release. It always says there is a error of Microsoft JET Database Engine '80004005' Unspecal...

# qbernard said on 06 May, 2008 09:52 PM

Your comment is not complete, can you repost or post it to iis.net forum. thanks.

# amol said on 09 May, 2008 12:40 PM

iis requried so thanks

# class not registered said on 10 May, 2008 02:17 PM

Pingback from  class not registered

# bill Staples said on 14 May, 2008 10:52 PM

duh, about time someone documented this!  thanks ;)

# IIS - Internal Server Error, Class not registered « Caveman’s Blog said on 23 June, 2008 03:58 PM

Pingback from  IIS - Internal Server Error, Class not registered &laquo; Caveman&#8217;s Blog

# IIS - Internal Server Error, Class not registered « Caveman’s Blog said on 23 June, 2008 03:58 PM

Pingback from  IIS - Internal Server Error, Class not registered &laquo; Caveman&#8217;s Blog

# IIS - Internal Server Error, Class not registered « Caveman’s Blog said on 23 June, 2008 03:59 PM

Pingback from  IIS - Internal Server Error, Class not registered &laquo; Caveman&#8217;s Blog

# IIS - Internal Server Error, Class not registered « Caveman’s Blog said on 23 June, 2008 03:59 PM

Pingback from  IIS - Internal Server Error, Class not registered &laquo; Caveman&#8217;s Blog

# IIS - Internal Server Error, Class not registered « Caveman’s Blog said on 23 June, 2008 04:15 PM

Pingback from  IIS - Internal Server Error, Class not registered &laquo; Caveman&#8217;s Blog

# IIS - Internal Server Error, Class not registered « Caveman’s Blog said on 23 June, 2008 04:15 PM

Pingback from  IIS - Internal Server Error, Class not registered &laquo; Caveman&#8217;s Blog

# walter said on 29 June, 2008 10:21 PM

Unfortunately the URLSCan and Scrawlr only able to detect through SQL Injection that is through querystring.

correct?

# qbernard said on 01 July, 2008 09:00 PM

For the urlscan the the hp scrawlr, both are done via http request and no source code is needed. Again, scarwlr is use to detect, while urlscan is defend, both didn't fix the issue at root.

# Message stuck in Microsoft SMTP service Queue « Axelilly’s Ponderings said on 28 July, 2008 11:51 AM

Pingback from  Message stuck in Microsoft SMTP service Queue « Axelilly’s Ponderings

# Interessante Links - Tom Schimana said on 29 October, 2008 06:53 AM

Pingback from  Interessante Links - Tom Schimana

# Interessante Links - Tom Schimana said on 05 November, 2008 01:49 AM

Pingback from  Interessante Links - Tom Schimana

# Windows 2008 Security - Top 8 - Web 2.0 Security Threats said on 18 February, 2009 05:04 AM

Pingback from  Windows 2008 Security  - Top 8 - Web 2.0 Security Threats

# Walter said on 18 February, 2009 01:52 PM

technically the #2 and #6 are mainly developer issues. When developer fail to write quality code, you going going to suffer :)

# Alun Jones said on 02 April, 2009 02:34 PM

Congratulations - me too!

# qbernard said on 03 April, 2009 09:30 PM

Nice! congrats too!!!

# Walter said on 05 April, 2009 10:48 PM

after a year only i realize I'm same batch as u :)

# qbernard said on 06 April, 2009 07:58 PM

Zzz.. same batch! ok, I quit!!!

# Genevieve said on 07 April, 2009 08:49 AM

Hi Bernard,

Quick questions on IIS:

Can I downgrade IIS 6 to IIS 5.1 on Win2003 Server machine?

I am having problems with Response Buffer and the easiest way out for now is to downgrade to 5.1 as I haven't fully tested my app on version 6. If it is possible, can I just simply uninstall 6.0 and install 5.1? Is it even possible to use 5.1 on a Win2003 server?

Appreciate your help as I know you're an expert on the subject.

Thanks!

 

# qbernard said on 07 April, 2009 10:49 AM

Ohh. I have replied you in email as well.

>>

You can't. with W2k3, you get IIS 6. IIS 5.1 is only for XP Pro 32bit edition (except home edition).

What's the reponse buffer error msgs anyway?

# Walter said on 10 April, 2009 04:38 AM

hahahahahah, dont lah like that :P

when will you be in KL? let's go for coffee 1 day

# qbernard said on 10 April, 2009 11:38 PM

@@ sure.. 1 day.. say today?

# Server: Microsoft-IIS/7.0\r\n said on 14 April, 2009 11:20 PM

A year ago... Cesar Cerrudo presented a serious vulnerability via evalvation of privilege involving the

# Server: Microsoft-IIS/7.0\r\n said on 14 April, 2009 11:22 PM

A year ago... Cesar Cerrudo presented a serious vulnerability via evalvation of privilege involving the

# Troubleshooting SMTP Issues in Windows & IIS » Virtual Memory said on 24 August, 2009 10:20 AM

Pingback from  Troubleshooting SMTP Issues in Windows & IIS » Virtual Memory

News

Search

Go

This Blog

Tags

Archives

IIS Sites

MVPs - MVPs

IIS Related

Syndication