URLScan 2.5 SRP

From: Davis, Matt (matt.davis@countryfinancial.com)
Date: 04/19/02


From: "Davis, Matt" <matt.davis@countryfinancial.com>
To: "FOCUS-MS (E-mail)" <FOCUS-MS@SECURITYFOCUS.COM>
Date: Fri, 19 Apr 2002 12:24:12 -0500

FYI- I haven't seen this publicized anywhere...

As I was checking Microsoft's website today, I did notice that there is yet
another version of UrlScan out called UrlScan 2.5 SRP, which eliminates the
Chunked Encoding vulnerabilities listed in 02-018...

http://www.microsoft.com/technet/treeview/default.asp?url=/TechNet/security/
tools/tools/urlscan.asp

Matt Davis, MCSA
Intermediate Client/Server Analyst
Client/Server Business Support
mailto:matt.davis@countryfinancial.com



Relevant Pages

  • IIS 5 Log FIle Question
    ... We are in the process of bringing our website in house. ... Below is a snippet from the logs. ... Does the fact the it says <Rejected by urlscan> imply ...
    (Security-Basics)
  • Allowing site redirection with URLScan
    ... second website and return info to the requesting site that is specific ... URLScan doesn't want to allow this behavior. ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
    (Focus-Microsoft)
  • Re: Allowing site redirection with URLScan
    ... Allowing site redirection with URLScan ... The main URL for the website will launch ... Network with over 10,000 of the brightest minds in information security ... most highly-anticipated industry event of the year. ...
    (Focus-Microsoft)
  • 7.5 Gig File Wont Download
    ... I have a file 7.5 Gig file on a website. ... When I try and download the file ... URLScan & BlackIce is running. ...
    (microsoft.public.inetserver.iis)
  • Re: guest log
    ... >with my guestlog file on my website. ... >write to it they get the error FrontPage Error. ... Did you configure URLScan for FrontPage Extensions? ...
    (microsoft.public.inetserver.iis.security)