all groups > iis security > december 2003 >
You're in the

iis security

group:

anyone seen this problem?


anyone seen this problem? Mike Larson
12/29/2003 12:44:53 PM
iis security:
Re: anyone seen this problem? Karl Levinson [x y] mvp
12/29/2003 9:21:57 PM
I don't work for Microsoft, but several people here have seen it, and I'm
fairly sure Microsoft has seen it [although the person who reported it
didn't give Microsoft any advance notice].

I personally would not be worried about this. While this is a questionable
security decision in Windows 2000, you can use HTTP GET to make such
requests, and while they would be logged, would probably not be noticed by
most admins. Also, if you are using the free URLScan, you are blocked from
most of such trickery, and you can edit the URLSCAN.INI file to log and
block this if you wish. The article you link to says that there is no
solution, but two solutions were mentioned by the original author several
paragraphs later. All in all, I'm saving my panic for another occasion.


[quoted text, click to view]

Re: anyone seen this problem? Mike Larson
12/30/2003 5:25:37 AM
I added it to urlscan just to be safe. I guess Security
Tracker didn't mention the solution.

[quoted text, click to view]
AddThis Social Bookmark Button