Welcome to HostingForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Login security issue.

 
   Web Hosting Problem Solving Community! (Home) -> IIS RSS
Next:  Unable to launch pages from UNC configured drive  
Author Message
Michael

External


Since: Mar 21, 2005
Posts: 2



(Msg. 1) Posted: Mon Mar 21, 2005 10:43 am
Post subject: Login security issue.
Archived from groups: microsoft>public>inetserver>iis, others (more info?)

I've setup an ASP page to allow users to change their password from a
website in ADS. The script I have is working, I can change the password,
then login with a workstation with the new password and the old password
won't work.

However, if I connect to a website requiring basic authentication, both
passwords work. I've tried closing all browsers to make sure its not
locally cached, plus I've even logged in from a workstation that had no
browsers open and had not previously been authenticated.

It seems to take about 20 minutes for till the old password stops working,
20 minutes is the same as the session timeout.

Could I be reconnecting to the same session even though I've closed all
browsers?

Any ideas on how not to have this happened?

TIA

 >> Stay informed about: Login security issue. 
Back to top
Login to vote
user641

External


Since: Aug 22, 2003
Posts: 1637



(Msg. 2) Posted: Mon Mar 21, 2005 2:23 pm
Post subject: Re: Login security issue. [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Michael" <michaelteff.RemoveThis@hotmail.com> wrote in message
news:ujpUjUjLFHA.1948@TK2MSFTNGP14.phx.gbl...
 > I've setup an ASP page to allow users to change their password from a
 > website in ADS. The script I have is working, I can change the password,
 > then login with a workstation with the new password and the old password
 > won't work.
 >
 > However, if I connect to a website requiring basic authentication, both
 > passwords work. I've tried closing all browsers to make sure its not
 > locally cached, plus I've even logged in from a workstation that had no
 > browsers open and had not previously been authenticated.
 >
 > It seems to take about 20 minutes for till the old password stops working,
 > 20 minutes is the same as the session timeout.
 >
 > Could I be reconnecting to the same session even though I've closed all
 > browsers?
 >
 > Any ideas on how not to have this happened?

This explains it:
<a style='text-decoration: underline;' href="http://support.microsoft.com/default.aspx?scid=kb;en-us;152526" target="_blank">http://support.microsoft.com/default.aspx?scid=kb;en-us;152526</a>

--
Tom Kaminski IIS MVP
<a style='text-decoration: underline;' href="http://www.microsoft.com/windowsserver2003/community/centers/iis/" target="_blank">http://www.microsoft.com/windowsserver2003/community/centers/iis/</a>
<a style='text-decoration: underline;' href="http://mvp.support.microsoft.com/" target="_blank">http://mvp.support.microsoft.com/</a>
<a style='text-decoration: underline;' href="http://www.iistoolshed.com/" target="_blank">http://www.iistoolshed.com/</a> - tools, scripts, and utilities for running IIS<!-- ~MESSAGE_AFTER~ -->

 >> Stay informed about: Login security issue. 
Back to top
Login to vote
Michael

External


Since: Mar 21, 2005
Posts: 2



(Msg. 3) Posted: Mon Mar 21, 2005 2:23 pm
Post subject: Re: Login security issue. [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Thanks for the info. I couldn't find that KB when I was looking, wasn't sure
what was being cached.


"Tom Kaminski [MVP]" <tomk (A@T) mvps (D.O.T) org> wrote in message
news:ezzm2tkLFHA.3788@tk2msftngp13.phx.gbl...
 > "Michael" <michaelteff.TakeThisOut@hotmail.com> wrote in message
 > news:ujpUjUjLFHA.1948@TK2MSFTNGP14.phx.gbl...
  >> I've setup an ASP page to allow users to change their password from a
  >> website in ADS. The script I have is working, I can change the password,
  >> then login with a workstation with the new password and the old password
  >> won't work.
  >>
  >> However, if I connect to a website requiring basic authentication, both
  >> passwords work. I've tried closing all browsers to make sure its not
  >> locally cached, plus I've even logged in from a workstation that had no
  >> browsers open and had not previously been authenticated.
  >>
  >> It seems to take about 20 minutes for till the old password stops
  >> working,
  >> 20 minutes is the same as the session timeout.
  >>
  >> Could I be reconnecting to the same session even though I've closed all
  >> browsers?
  >>
  >> Any ideas on how not to have this happened?
 >
 > This explains it:
<font color=purple> > <a style='text-decoration: underline;' href="http://support.microsoft.com/default.aspx?scid=kb;en-us;152526</font" target="_blank">http://support.microsoft.com/default.aspx?scid=kb;en-us;152526</font</a>>
 >
 > --
 > Tom Kaminski IIS MVP
<font color=purple> > <a style='text-decoration: underline;' href="http://www.microsoft.com/windowsserver2003/community/centers/iis/</font" target="_blank">http://www.microsoft.com/windowsserver2003/community/centers/iis/</font</a>>
<font color=purple> > <a style='text-decoration: underline;' href="http://mvp.support.microsoft.com/</font" target="_blank">http://mvp.support.microsoft.com/</font</a>>
 > <a style='text-decoration: underline;' href="http://www.iistoolshed.com/" target="_blank">http://www.iistoolshed.com/</a> - tools, scripts, and utilities for running
 > IIS
 >
 ><!-- ~MESSAGE_AFTER~ -->
 >> Stay informed about: Login security issue. 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
IIS Integrated security login issue. - 2003 and share point services 2.0 We also have our dns zone listed as a trusted intranet site inside internet explorer. The root website is set for anonymous access. There are multiple sub web sites that are also open except for some document..

Newbie security issue? - Hi, I just got a new ISP that gave me a fixed IP, so I thought I'd give a try to IIS 5.1, running on XP pro. I put together some stuff and threw it into the default web server. Now I can see the pages if I enter the private address of my computer..

401.3 Anonymous only security ACL issue - Hi all, I have been searching for an answer on this but can't quite seem to pin it down. I have a Windows 2003 64-bit server running IIS 6.0. I have set the Directory Security at the root level (Web Sites down) with the following: Enable anonymous..

IIS Security Issue w/ website users - I'm experiencing a very strange problem which I believe is assocaited w/ Frontpage Server Extensions. Some users of our internal intranet site, get windows user and password prompts when they try to access office files. If the user clicks cancel, the...

Multiple web users security issue - I have a Win2k Server, 2 users who have web sites. I am trying to isolate each one so they can not read files or folders from directories that do not belong to them. I have setup impersonate="true" with blank user name and password in the..
   Web Hosting Problem Solving Community! (Home) -> IIS All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]