Re: URL Scan on OWA

From: Karl Levinson [x y] mvp (levinson_k_at_despammed.com)
Date: 07/31/03


Date: Thu, 31 Jul 2003 10:43:09 -0400


For any URLScan problem, generally you view the URLScan.log file and then
edit the URLSCAN.ini file and restart IIS. It's a good idea to repeat this
every so often, especially after first installing URLScan, to see if
legitimate requests are being blocked accidentally. See here for more info:

http://securityadmin.info/faq.htm#urlscan

"Björn Johansson" <bjornN0@$PAMjohansson.gs> wrote in message
news:OeCKjY0VDHA.1744@TK2MSFTNGP12.phx.gbl...
> Hello,
>
> I've set up a OWA (front end) on our DMZ. The recommended template for OWA
> is used on URLScan.
>
> The problem is that it blocks URLs containing "&" and ".." signs. This is
> very disturbing for our users because many emails contains .. and "&" and
> ".." signs in subject line.
> Is there any workaround or tools to solve this problem without
comprimising
> security?
>
> According to last months logs there are no attempted attacks using "&" and
> ".." in URLs, just our users trying to access email containing the blocked
> sequences.
>
>
>
> Thanks in advance!
>
>
> /B.
>
>



Relevant Pages

  • Re: URL Scan on OWA
    ... For any URLScan problem, generally you view the URLScan.log file and then ... It's a good idea to repeat this ... The recommended template for OWA ...
    (microsoft.public.inetserver.iis.security)
  • Re: URL Scan on OWA
    ... The recommended template for OWA ... >> is used on URLScan. ... >> security? ... >For any URLScan problem, generally you view the URLScan.log file and then ...
    (microsoft.public.security)
  • Re: URL Scan on OWA
    ... The recommended template for OWA ... >> is used on URLScan. ... >> security? ... >For any URLScan problem, generally you view the URLScan.log file and then ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS Lockdown
    ... My recommendation for this and every other URLscan problem is the same. ... URLscan is blocking it, test the application and then check the urlscan.log. ... >>files in the install folder, you could edit those and see ... >>> I want to run IIS Lockdown before exposing IIS5 server ...
    (microsoft.public.inetserver.iis.security)
  • Re: URLScan
    ... The first thing I do with any URLscan problem is view the urlscan.log file ... > the browser just displays the header content on the page ... > with the html following. ...
    (microsoft.public.inetserver.iis.security)