Groups | Blog | Home
all groups > iis security > december 2004 >

iis security : denyurlsequences


rrwillu
12/3/2004 12:13:02 PM
Hi

I have IIS 6.0 and URLscan 2.5. In IIS 6.0 there is no need to include
characters we need to block under 'denyurlsequences'. this is frustrating
because I can't remove/add to this list. In IIS 6.0 where does the
application store denyurlsequences list so i can modify?

I want to remove + from 'denyurlsequences' list, but I can't. HOw can
unblock/remove + character?

Thanks in advance.
Ken Schaefer
12/7/2004 11:58:10 AM
Why can't you just edit the urlscan.ini file? URLScan doesn't work any
differently under IIS6 than it did under IIS5.

How to configure the URLScan Tool
http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;326444

After editing urlscan.ini you may need to restart something (not sure
whether you need to restart IIS, or restart http.sys)

Cheers
Ken


[quoted text, click to view]

AddThis Social Bookmark Button