Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: URL Scan for IIS

From: <securityarchitect(at)hush.com>
Date: Sun Feb 23 2003 - 15:47:30 EST

"blocks all known attacks"....wow thats a powerful statement ! Whats that based on ? Do I thow away my application IDS now then ;-) I could write bad code and this will stop it all then ? eeeek....

Unless I missed something the IIS lockdwon wizard selection doesn't change the URL scan ini file. It turns of services and mappings. If you select an html only site it will not map ASP etc as well as all the unmapping of htw, htr etc

What I was really looking for was something more like

by adding the < and > strings you can stop XSS..

My real question is this seems to be reversed to good practice for inout filtering, ie i want to say only allow this in the ini file and automaticaly block the meta-chars...

On Sun, 23 Feb 2003 00:06:37 -0800 Maher Odeh <rax@netvision.net.il> wrote:
>regarding your question about URLScan ...

Concerned about your privacy? Follow this link to get FREE encrypted email: https://www.hushmail.com/?l=2

Do you need help?X

Big $$$ to be made with the HushMail Affiliate Program: https://www.hushmail.com/about.php?subloc=affiliate&l=427 Received on Sun Feb 23 15:50:06 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:49 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library