IIS-ASP to access network resource

From: Jacky Lu (lujacky@hotmail.com)
Date: 11/01/02


From: "Jacky Lu" <lujacky@hotmail.com>
Date: Fri, 1 Nov 2002 11:35:27 -0500


I'm trying to access source safe database from ASP, the source safe database
is on different machine with web server.

I'm using W2k, IIS 5.0, and source safe is 6.0.
When start, inside my global.asa, I will do:

objVSSDb = new ActiveXObject("SourceSafe");
objVSSDb.Open("\\ssserver\VSSDb\srcsafe.ini", "UserName", "pwd");

But it failed at open method, my guess is web access to that source safe's
file is denied. The error message sometimes are "Out of memory" or "can't
find database UserName,...". I tried different security config, but I'm
still out of luck. I only got once worked(it only worked at web server, not
the other machine to browse it.), but I can't remember what exactly I did,
since I can't get it back, but I do remember that time I removed the check
for anonymous access.
I can run it from script on my local desk, which works fine.

I'm not too much concern about security issue here, since it only works at
our local network, but I'd like to know about how to setup security on
browser, web server, IIS config, to make this works.

Thanks,

Jacky Lu

Microsoft Certified Solution Developer



Relevant Pages

  • [NT] Poisoning Cached HTTPS Documents in Internet Explorer
    ... Get your security news from a reliable source. ... "poison" a user's browser cache with a malicious document that will later ... The attacker can exploit this vulnerability for "replacing" HTML ... to communicate with a malicious web server over HTTPS without the browser ...
    (Securiteam)
  • [NT] Webserver 4D Weak Password Preservation Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... complete Web Server environment written entirely on top of 4th Dimension, ... WS4D web server saves the passwords somewhere insecure. ...
    (Securiteam)
  • Re: 2003 Web Server Security flaw
    ... "Locked-down windows 2003 Web Server used only to host web sites". ... What is your logic/rationale for Media Player being a required install ... The Media Player patch was the ONLY that FAILED. ... > When talking about computer security, there are areas that have no such ...
    (microsoft.public.windows.server.security)
  • Web session tracking security prob. Vulnerable: IIS and ColdFusion (maybe others)
    ... SECURITY PROBLEMS WITH WEB SERVERS' SESSION TRACKING MECHANISMS. ... 2001 we reported the following problem (with specifics to IIS and SITESERVER) to the Microsoft Security Response Center. ... These vulnerabilities, especially when combined with well-known cross-site scripting vulnerabilities, could cause loss of confidentiality, failure of non-repudiation and fraud. ... The browser stores and returns the "ASPSESSIONID" or "CFID/CFTOKEN" values with each subsequent request to the web server. ...
    (Vuln-Dev)
  • [NT] Easy File Sharing Web Server File Access and DoS
    ... Get your security news from a reliable source. ... Easy File Sharing Web Server also provides a Bulletin Board System ... It allows remote users to post messages and files to the forum. ...
    (Securiteam)