Re: Disabling HTTP Trace Without using URL Scan

From: Wade A. Hilmo [MS] (wadeh_at_microsoft.com)
Date: 01/07/04


Date: Tue, 6 Jan 2004 16:32:50 -0800

Hi Jerry,

As Sean says, you can install UrlScan 2.5 without the lockdown tool. If you
do this and configure UrlScan so that it only blocks TRACE requests and
nothing else, then OWA and Proxy server should work just fine.

If you have a hard core goal of disabling TRACE without any additional
tools, then you should consider IIS 6, which has this ability.

Thank you,
-Wade A. Hilmo,
-Microsoft

PS: Just to be technically accurate, UrlScan is a filter, not an extension.

"SECOVEL" <secovel at yahoo dot com> wrote in message
news:uG1jYUJ1DHA.2604@TK2MSFTNGP09.phx.gbl...
> Did you run the whole lockdown tool or just URLScan? If you were "backing
> out" changes, sounds like you ran the whole lockdown tool.
>
> URLScan is just an ISAPI Extension. You should be able to download the
> latest (2.5 I think) and install it stand-alone. It should be able to
block
> TRACE without hosing your server. Edit the urlscan.ini to block the
options
> you want.
>
> Sean
>
> "Jerry Farkas" <jerry.farkas@sas.siemens.com> wrote in message
> news:276401c3d493$b86da3e0$3101280a@phx.gbl...
> > Hiyas,
> > I need to disable HTTP Trace without using the URLScan
> > tool. I have a OWA/Proxy Sevrer combo and I ran the scan
> > tool and it hosed MS Proxy. It would even crash trying to
> > back out of the changes. DOes anyone know how to disable
> > HTTP Trace without using the URLScan tool? THis is for
> > IIS 4.0 pls.
> >
> >
> > Thanks.
>
>



Relevant Pages

  • Re: security advice (possible hacker activity?)
    ... I ran an antivirus software and haven't found any virus/ ... Note that if you install the full-blown IIS Lockdown Tool (instead of just ... URLScan on its own), there is the option to restrict access to system ... I'd highly recommend URLScan. ...
    (microsoft.public.inetserver.iis.security)
  • Re: OWA and Replys
    ... If URLSCAN or the Lockdown tool have ... Troubleshoot Problems After You Run the IIS Lockdown Wizard ... Modify the Default URLScan Configuration File ...
    (microsoft.public.exchange.clients)
  • RE: IIS Lockdown Blues
    ... If you're having that many problems just running iislockd and the URLScan ... unrelated to IIS or the Lockdown Tool. ... > installing the corrupted URLScan installation. ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS Lockdown and ASP pages failure
    ... It is almost certainly an unwise choice to remove URLScan or the Lockdown tool. ... If URLScan is rejecting *.asp, ...
    (microsoft.public.inetserver.iis.security)
  • Re: Disable trace and track verbs
    ... I understand what u are saying, but URLscan will not ... intercept that command yet as IIS will still respond to ... an OPTIONS and TRACE command even with it disabled. ...
    (microsoft.public.inetserver.iis.security)