RE: ISA and OWA

  • From: Glenn Maks <gmaks@xxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Fri, 13 Jun 2003 11:19:33 -0400

Just a point of interest, if you have anonymous enabled on your OWA web
site, and publicly announce it using DNS, then anyone can at the very least
get to the Default Login Page, and with Microsoft smattering all over the
OWA default login page what exactly this web site does, it is not hard to
figure  that you have reached a Web based mail system. I have turned off
anonymous and  Basic authentication enabled integrated windows
authentication, this way, you have to provide your login credentials to open
the Welcoming OWA Login Page, this prevents free advertising of what your
web site does, basically you have to have a valid login account to open the
page, it avoids curiosity and wondering finger tips at the key board.  Just
a suggestion.
 
 Cheers
  G.

-----Original Message-----
From: Winston Akin-Cole [mailto:wcole@xxxxxxx] 
Sent: Friday, June 13, 2003 8:26 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: ISA and OWA


http://www.ISAserver.org



I was looking at the authentication on the MS Exchange 2000 Backend Server.
I looked at the OWA server and I am using Basic authentication.  I guess I
am back where I started from.

 

 

-----Original Message-----
From: David V. Dellanno [mailto:ddellanno@xxxxxxxxxx] 
Sent: Friday, June 13, 2003 3:47 AM
To: Winston Akin-Cole
Subject: RE: ISA and OWA

 

Hi Winston,

    Did the fix work?  If so, would you please post a quick statement back
to the newsgroup so others can find this sucess thread.

 


  _____  


Regards,

 

David V. Dellanno - MCSE, MCP+I, MCP

MSDEMO Consultants

Williams Place

2564 Bridgewood Lane

Snellville, Georgia 30078 USA

(770) 736-8794 (Office)

 <http://msdemo.net/> msdemo.net

 

Confidentiality Notice:
This e-mail message, including any attachments, is for the sole use of the
intended recipient(s) and may contain confidential and privileged
information. Any unauthorized review, use, disclosure or distribution is
prohibited. If you are not the intended recipient, please contact the sender
by reply e-mail and destroy all copies of the original message.

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
gmaks@xxxxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub') 

Other related posts: