Re: OWA and URLScan

From: Deus, Attonbitus (Thor@HammerofGod.com)
Date: 04/19/02


Date: Fri, 19 Apr 2002 11:28:54 -0700
To: "Mike Brentlinger" <mdbrentlinger@hotmail.com>, FOCUS-MS@SECURITYFOCUS.COM
From: "Deus, Attonbitus" <Thor@HammerofGod.com>


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

At 10:56 AM 4/19/2002, Mike Brentlinger wrote:
>http://support.microsoft.com/default.aspx?scid=kb;EN-US;q309508
>
>more specifically.
>
>http://support.microsoft.com/default.aspx?scid=kb;EN-US;q309508#4

Hi Mike-

thanks for the links... However, if you look at both of those, you will see
the default DenyURLSequence tags are the 'standard' defaults for URL Scan...
i.e., "..","./ ","\ ",":","%", and "&" are all set to be filtered.

The issue is that with the recommended OWA URLScan ini's, any email with
those characters in the subject line will be inaccessible by the OWA
client. So far, it looks like the only way to allow a user to read email
with these characters in the subject line would be to allow at least "..",
"&", and "%" through, which I *really* don't want to do- particularly on an
OWA server...

Ya know?

Thanks-

t

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.1

iQA/AwUBPMBh5ohsmyD15h5gEQIT1gCffxqOZCFvuRD1ufeWwLAGDwlY8WcAn1V5
QRfP461xKTDJcYFuv8dkficX
=03rv
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: password change for OWA 2007
    ... It's just a security function of AD and OWA. ... refreshes the view every 2 minutes (I might be wrong with this default ... Here's the details on the Password Complexity Setting in the Security ... Be at least six characters in length ...
    (microsoft.public.exchange.admin)
  • Re: Webdav and Form based Authentication
    ... From the very meagre documentation on the subject I can find ... I need to do a POST to the owaauth.dll, which returns two cookies. ... contain characters I am not allowed to use. ... OWA For WAP: ...
    (microsoft.public.exchange2000.development)
  • OWA - Exchange 2007 - Change Password - - The password supplied does not meet the m
    ... I have tried every possible password - many many characters - combos upper ... case lower case numbers etc - it has nothing to do with the group policy ... complexity requirement as I can make even simple passwords e.g. 6 ... Something isn't functional in OWA as far as I can tell. ...
    (microsoft.public.exchange.setup)
  • Re: Changing Password through OWA 2007
    ... can reset their password to as little as 3 characters. ... the settings are those defined in Group Policy. ... Doesn't sound like an OWA problem at the moment. ...
    (microsoft.public.exchange.admin)