RE: Basic Authentication

From: Susan Hayden [MS] (shayden@online.microsoft.com)
Date: 07/05/02


From: shayden@online.microsoft.com (Susan Hayden [MS])
Date: Fri, 05 Jul 2002 19:54:32 GMT


Gabriela,

You wrote:

I have a web site.
The security configuration in IIS is:
- Basic authentication
- I specify the domain name

Is there any way to know from the applicattion (web site) which is the
domain that I specify at IIS confguration?

The default domain information is stored in the registry. Are you
concerned about security? Since you are using basic, a sniffer will get the
domain, username and password as they must be passed over the network.

I'm not really sure I understand the questions
Susan Hayden
IIS Newsgroup Support

Please do not send email directly to this alias. This is our online account
name for newsgroup participation only.

This posting is provided “AS IS” with no warranties, and confers no rights.
You assume all risk for your use. © 2001 Microsoft Corporation. All rights
reserved.

Please remember to subscribe to our security bulletins at
<http://www.microsoft.com/technet/security/notify.asp>



Relevant Pages

  • Re: Cant connect using ADOMD.NET
    ... > setting in IIS under Directory Security or is there another way to ... > connect to the Analysis server that will specify I want to use basic? ... production without using HTTPS because the Basic authentication mechanism is ...
    (microsoft.public.data.xmlanalysis)
  • Re: Authentication against trusting domains in IIS 6.0
    ... I am looking specifically for basic authentication ... against "Trusted domains" in IIS 6.0. ... specify "\" as the default domain in basic authentication, ...
    (microsoft.public.inetserver.iis.security)
  • Re: Mac Server Hacked In Less Than 6 Hours
    ... Windows has RAS, and for it is built in since NT 3.1 ... | A typical IIS box and this Mac are not the same thing so the comparison ... IIS has been subject to quite a few bugs and so have ... Security isn't a proprietary attribute. ...
    (sci.crypt)
  • Re: DCOM calls fails - access denied
    ... That's exactly how I understood the ASP.NET security. ... But why does one configuration work but not the other? ... should get the token from IIS. ... If you set there a domain account, ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: How to secure IIS?
    ... XP as well, because even if you don't install IIS, there are still a number ... If you think Windows 98 is secure, ... easy to attack, if there's no firewall... ... IIS security checklists] 3) install firewall and antivirus, ...
    (microsoft.public.inetserver.iis.security)