IIS
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me

The Shed is going Social! Join us on FaceBook and Twitter and chime in on the conversation.

Go Back   Dev Shed ForumsSystem AdministrationIIS

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old November 17th, 2010, 06:49 AM
cyberpine cyberpine is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Dec 2009
Posts: 5 cyberpine User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 1 h 43 m
Reputation Power: 0
Integrated Windows Security bypassed by simply adding domain to IE 8 Local Intranet ?

I have a .NET 2.0 IIS 6 solution at home I thought was secure. Annonymous is off and integrated is on on the web site. The web config has this:

<system.web> <authentication mode="Windows"></authentication>
<authorization>
<allow users="MYHOMWEBSERVER\MYUSER"/><deny users="*"/>
</authorization>

My IE 8 client at work is logged into another domain, the user name is the same, but the password is different.

If I add the domain url of my soltuion to local intranet sites in IE 8 on my client IE now just lets me right into the site with no challenge/response authentication even after clearing cache with passwords and rebooting the client ????

I have not tested when authenticated in as another user on my work domain. But how is this possible?

Either IE is trusting same users accross domains, or windows is storing authentication in a way that even clearing cache or rebooting.

If I turn off the local trust entry or attempt to access the site from a non IE client challenge response happens and there is no way into the site without authentication into MYHOMWEBSERVER\MYUSER. Also, If I browse the site via IIS console on the server a challenge is presented.

Very confused and concerned that is is a Microsoft IE feature.

Thanks in advance.

Update: I just changed the user name in the web.config and now prompts me. I now suspect that entry is trusting any domain with that user name. Why is that? My web server is not under Active directory and is a VM joined into a workgroup all my home stations are joined into. Might I be trusting my work domain somewhere on the server? Does the workgroup play any role in the web.config?

Update2: A display of my windows identity says MYSERVER\MYUSERNAME implying that somehow my client has this authentication stored somewhere? How do I clear that? I tried clearing cache and rebooting. In another test, I created an identical user/pw no another VM on the same workgroup and after adding the local intranet entry in IE it also lets me right in. I change the pw and now I'm prompted.. so pw seems to matter, but this does not explain why work can go right in since domain and pw are different unless authenication memory is stored somewhere that rebooting and clearing cache does not reset.

Reply With Quote
  #2  
Old November 17th, 2010, 02:21 PM
Doug G Doug G is offline
Grumpier Old Moderator
Dev Shed God 19th Plane (14000 - 14499 posts)
 
Join Date: Jun 2003
Posts: 14,238 Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level)Doug G User rank is General 52nd Grade (Above 100000 Reputation Level) 
Time spent in forums: 1 Month 4 Weeks 15 h 7 m 57 sec
Reputation Power: 4445
I don't have an answer, sorry. It sounds to me like you're dealing with some IE issue rather than IIS, but that's just a guess. I haven't done much with IIS and intranet-type sites.
__________________
======
Doug G
======
It is a truism of American politics that no man who can win an election deserves to. --Trevanian, from the novel Shibumi

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationIIS > Integrated Windows Security bypassed by simply adding domain to IE 8 Local Intranet ?

Developer Shed Advertisers and Affiliates



Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 


Powered by: vBulletin Version 3.0.5
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

© 2003-2013 by Developer Shed. All rights reserved. DS Cluster - Follow our Sitemap