Re: identify disabled users and bad bad passwords

From: Ken Schaefer (kenREMOVE_at_THISadopenstatic.com)
Date: 12/22/04


Date: Wed, 22 Dec 2004 16:16:04 +1100

In my experience, it doesn't really matter if you customise those files -
it's up to the browser to decide what to display, and they will display (a)
login prompt (for the first three goes), and then (b) Access Denied message
(after three unsuccessful attempts)

Cheers
Ken

"Bernard" <qbernard@hotmail.com.discuss> wrote in message
news:uqT3Rv95EHA.3120@TK2MSFTNGP12.phx.gbl...
> My guess for 401 only support file is because 401.X is related to access
> error. which probably related to dynamic scripting, etc, hence IIS only
> allows you to send back static file content that doesn't need to be
> 'intepret' by all isapi filter. inetinfo.exe will read the content and
> send it back to clients.
>
> --
> Regards,
> Bernard Cheah
> http://www.tryiis.com/
> http://support.microsoft.com/
> http://www.msmvps.com/bernard/
>
>
>
> "Scilabop" <scilabop@Xuvic.ca> wrote in message
> news:e2z9ww65EHA.1452@TK2MSFTNGP11.phx.gbl...
>> Thank you, Bernard.
>>
>> I tried. The sc-win32-status codes for disabled account and bad
>> username/passward are all "5".
>> But the security event log did give the specific failure reasons. I am
>> now
>> wondering how I can program with the system log.
>>
>> Here I got another question.
>> I suppose to be able to customize the HTTP error messages by mapping a
>> file
>> or URL. But HTTP 401 (-1,-2,-3,-4, -5) just offer the option of mapping
>> to a
>> file, but not URL, while all other HTTP errors have the options of both
>> file
>> and URL. I found this problem when I was trying to redirect HTTP 401.1
>> message to an ASP script. Any one else ever had such problem?
>>
>> Thanks a lot.
>>
>> Ally
>>
>>
>>
>> "Bernard" <qbernard@hotmail.com.discuss> wrote in message
>> news:OwDkQoy5EHA.3368@TK2MSFTNGP10.phx.gbl...
>>> Well, 401.1 stands for login failed, hence it could be username/password
>>> wrong, it could be account disabled and lockout. Not sure if the win32
>>> status code field will give you more detail, but you can try enable it
>>> in
>>> the w3c extended iis log format.
>>>
>>> as for the login prompt, it's actually client browse control. IIS only
>>> return authentication header and it's up to client browser to react.
>>>
>>> --
>>> Regards,
>>> Bernard Cheah
>>> http://www.tryiis.com/
>>> http://support.microsoft.com/
>>> http://www.msmvps.com/bernard/
>>>
>>>
>>>
>>> "Scilabop" <scilabop@Xuvic.ca> wrote in message
>>> news:%23pBcz6H5EHA.1404@TK2MSFTNGP11.phx.gbl...
>>> > Hello,
>>> >
>>> > We are using IIS5.0 and integrated windows authentication to protect
>>> > network
>>> > resource.
>>> > The system takes both disabled accounts and bad username and password
>>> > pairs
>>> > as HTTP401.1 error. My task is to distinguish these errors, and then
>> take
>>> > corresponding actions. But I have problem to retreive the unauthorized
>>> > username.
>>> >
>>> > I am really curious about what triggers those .htr files within
>>> > /inetsrv/iisadmpwd. Is that the iisadminpwd.dll file controls
>> everything?
>>> > If
>>> > I could look into the source code for the little popup authentication
>>> > window, my task would be easy to get done.
>>> >
>>> > Any helps are appreciated.
>>> >
>>> > Ally
>>> >
>>> >
>>> >
>>> >
>>>
>>>
>>
>>
>
>



Relevant Pages

  • customising dnserror.html
    ... I want to be able to customise the standard dnserror.html page that ... but the local server needs to stop the web server each ... customised one to display our company logo, ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Run Box Disappeared
    ... select Properties and then Customise. ... On that screen enable 'Display Run' - OK your way out. ... Will Denny ... MS-MVP Windows - Shell/User ...
    (microsoft.public.windowsxp.basics)
  • Re: Custom Error pages
    ... You can attempt to customise the page (and IIS will send the customised ... Most browsers will *not* display custom ... measure on the part of the browser. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Locked User Accounts On IIS 5.0
    ... You can create a customised 401 error page BUT it is up to the browser to ... decide what to display to the user. ... Access Denied message that you see - you can't customise that. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Connect Computer
    ... Here is the exact error I am getting: ... This error can occur if you are trying to display an HTML page ... HTTP Error 403.2 - Forbidden: ... Internet Information Services (IIS) ...
    (microsoft.public.windows.server.sbs)