Re: Header Referrer-based Filtering

From: Craig Humphrey (CraigHumphreyHatesSpam_at_newsgroup.nospam)
Date: 12/21/04

  • Next message: Craig Humphrey: "Re: How to? Certificate Server 1.0 root certificate renewal"
    Date: Tue, 21 Dec 2004 12:26:46 +1300
    
    

    Yeah, an ISAPI filter is what you need.
    Check out the custom authentication one, you should be able to modify that
    to work for you.

    The catch.... the referrer value can be forged...

    Hope that helps.

    Later'ish
    Craig

    "Adam Baum" <Adam Baum@discussions.microsoft.com> wrote in message
    news:2F7C1F70-5F8E-48C6-AE7F-0FE68AB05EBA@microsoft.com...
    > Hello,
    >
    > I am running several websites on IIS5 w/ all patches and the LockDown
    Tool.
    > With all but one website I am able to use either NTLM auth or IP filtering
    to
    > secure and limit access to the sites. The last site is the problem.
    >
    > We have several off-site systems that provide services to remote clients.
    > Occasionally these systems have to referrer the client to the webserver
    for
    > data files. Since it is the client that is connecting to the webserver the
    IP
    > is different each time so we cannot use IP filters and usernames and
    > passwords cannnot be used as well.
    >
    > How do you configure IIS5 to scan the HTTP Request Header for the Referrer
    > value and compare to a list of authorized users before allowing the
    traffic?
    > The referrers are always static so I need to configure the ACL based on
    the
    > referrer instead of the client ip.
    >
    > Article links and Suggestions will be much appreciated!
    >
    > Thanks!


  • Next message: Craig Humphrey: "Re: How to? Certificate Server 1.0 root certificate renewal"

    Relevant Pages

    • Re: Header Referrer-based Filtering
      ... referer value that was sent by the client. ... need to use an ISAPI filter. ... Since it is the client that is connecting to the webserver the ... > How do you configure IIS5 to scan the HTTP Request Header for the Referrer ...
      (microsoft.public.inetserver.iis.security)
    • Re: Header Referrer-based Filtering
      ... The task is really not that hard and is pretty standard ISAPI Filter ... If the referrer is one of our secondary servers then allow it, ... > referer value that was sent by the client. ... Since it is the client that is connecting to the webserver ...
      (microsoft.public.inetserver.iis.security)
    • Re: Please help with a serious issue
      ... does a filter statement on an adotable happen on the client machine or the ... >>User 1 selects customer 1. ... >>server db for all the clients. ...
      (borland.public.delphi.database.ado)
    • Re: TDI driver event queueing
      ... filter connections on TDI level. ... Also, I feel that TDI queueing is not very simple task, and it even may not ... S> occurrs) not by the kernel-mode client. ... S> (which is the clients handler). ...
      (microsoft.public.development.device.drivers)
    • Re: 2 plans - 1 a sub set of another
      ... Dave Eade wrote: ... Putiing all client ... What I was hoping was that I could have a plan 'linked' to the main plan ... I don't just want to 'filter' one plan and show the Client, ...
      (microsoft.public.project)