Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 185629
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 11, 20262026-05-11T15:30:14+00:00 2026-05-11T15:30:14+00:00

If I uncheck the Enable anonymous access checkbox in IIS, so as to password

  • 0

If I uncheck the ‘Enable anonymous access’ checkbox in IIS, so as to password protect a site, i.e. by restricting read access to designated Windows accounts, does the resulting password dialogue which is then presented to all anonymous http requests, represent a security risk in that it (seemingly) offers all and sundry an unlimited number of attempts to guess at any Windows account password?

EDIT: Okay, not much joy with this so far, so I’m attaching a bounty. Just 50 points sorry, I am a man of modest means. To clarify what I’m after: does disabling anonymous access in IIS offer a password guessing opportunity to the public which did not exist previously, or is it the case that the browser’s user credentials dialogue can be simulated by including a username and password in a http request directly, and that the response would indicate whether the combination was correct even though the page was open to anonymous users anyway? Furthermore, are incorrect password attempts submitted via http subject to the same lockout policy enforced for internal logins, and if so does this represent a very easy opportunity to deliberately lock out known usernames, or alternatively, if not, is there anything that can be done to mitigate this unlimited password guessing opportunity?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. 2026-05-11T15:30:15+00:00Added an answer on May 11, 2026 at 3:30 pm

    When you choose an authentication other than Anonymous, you certainly can be subject to password hacking. However, the account that is uses is subject to the standard account lockout policies set in Local Security Policy and your Domain’s security policy.

    For example, if you have a local account ‘FRED’ and the account lockout policy is set to 5 invalid attempts within 30 minutes, then this effectively prevents account password guessing, at the risk of a denial of service attack. However, setting the reset window to a value (15 minutes?) effectively limits the DOS.

    • Basic Authentication is not recommeded for a non-SSL connection since the password will travel in plain text.

    • Digest Authentication requires passwords to be stored on the server using a reversible encryption, so while better than Basic, Digest has its flaws.

    • Windows Integrated Authentication includes NTLM and Kerberos.

      • The IIS Server should be configured via Group Policy or Local Security settings to disable LM authentication ( Network security: LAN Manager authentication level set to ‘Send NTLMv2 response only’ or higher, preferred is ‘Send NTLMv2 response only\refuse LM & NTLM’) to prevent trivial LM hash cracking and to prevent NTLM man in the middle proxy attacks.

      • Kerberos can be used, however it only works if both machines are members of the same domain and the DC’s can be reached. Since this doesn’t typically happen over the internet, you can ignore Kerberos.

    So the end result is, yes, disabling anonymous does open you up for password cracking attempts and DOS attacks, but these can be prevented and mitigated.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I have a PreferenceScreen, where the user can check/uncheck a checkbox. To get access
Is there a way to uncheck/check a checkbox within a webpage that is loaded
Can I unchoose a radio button like you uncheck a checkbox? I'm running a
How can I make the comboBox available when the checkBox was uncheck (vice versa)
Does anyone know how to get the list of items and check/uncheck items in
My requirement is to uncheck the checkbox if the textbox value is greater than
i am trying to check/uncheck all checkboxes upon clicking on select all/deselect all checkbox
I am trying to add a disabled checkbox using Zend_Form and then enable it
I've managed to uncheck the Xcode 4 'show this screen when Xcode starts' checkbox
im trying to uncheck programaticaly a checkbox while in a change event: $(#target).change(function() {

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.