Basic Authentication

From: Michael (raterus_at_localhost)
Date: 12/03/03


Date: Wed, 3 Dec 2003 10:06:18 -0500

I have a quick question about basic authentication.

The only way I've found to get a non-administrator user successfully logged
into the website using basic authentication, is to allow the user "Log on
Locally" rights under the domain controller security policy.

Am I missing something?, this just seems to be a big security risk? They
could technically walk up to our servers and log in!

Thanks,
--Michael



Relevant Pages

  • Re: Basic Authentication
    ... > I have a quick question about basic authentication. ... this just seems to be a big security risk? ... That's why you should keep your servers in server rooms behind locked doors. ... Tom Kaminski IIS MVP ...
    (microsoft.public.inetserver.iis.security)
  • Re: Driving a website using VFP
    ... URL, if you're using basic authentication, e.g. ... > Further to the IE automation stuff above, ... > without user intervention. ... >> In another section of the program, I want to log onto another website, ...
    (microsoft.public.fox.programmer.exchange)
  • Re: Integrated windows authentication problems
    ... Post the relevant logon failure events here (if you open the event, ... Basic Authentication enabled at the same time when you want to test Basic. ... Recently I created a website that uses Integrated Windows Authentication ... NOTE: frontpage server extensions gave ...
    (microsoft.public.inetserver.iis.security)
  • Re: Do i need to got Https:// throught the website ???
    ... If they use Basic authentication then it is absolutely ... necessary to protect the password of the user. ... "Ananth Ramasamy Meenachi" ... An organization has a website which goes with windows ...
    (microsoft.public.dotnet.security)
  • Re: Basic Authentication
    ... Our original solution was to simply redirect to the website using this format: ... I have found a few places that indicate that I can add headers to the ... I know that basic authentication is really insecure. ...
    (microsoft.public.dotnet.languages.csharp)