How to configure URLScan 2.5 to allow .stm files?

From: DJO (djo.oconnor_at_NOSPAMverizon.net)
Date: 08/21/04


Date: Sat, 21 Aug 2004 19:27:42 GMT


We have a W2K Server SP4 running IIS 5.0. IIS Lockdown 2.1 and
URLScan 2.5 were run on the box.

We need to allow .stm files to run. When I remove URLScan from the
server the .stm files will run. However, I want all the other
functions of URLScan, so I want to configure URLScan to allow .stm
files.

I've made the following changes to the urlscan.ini file, but .stm
files are still being blocked by URLScan.

Changes to urlscan.ini:

I left the default UseAllowExtensions=0 and I commented out first and
then removed .stm ; Maps to ssinc.dll, for Server Side Includes,
from [Deny Extensions].

I then tried setting UseAllowExtensions=1 and added .stm to
[AllowExtensions], but I still receive the following message in the
urlscan log:

URL contains extension '.stm', which is disallowed. Request will be
rejected. Site Instance='4', Raw URL=''

I stopped/started the web site for each of the above changes.

Any help would be appreciated.

Thanks,

Dave

*If responding by e-mail please remove the "NOSPAM".



Relevant Pages

  • How to configure URLScan 2.5 to allow .stm files
    ... URLScan 2.5 were run on the box. ... We need to allow .stm files to run. ... server the .stm files will run. ... I stopped/started the web site for each of the above changes. ...
    (microsoft.public.inetserver.iis)
  • Re: rpc over http with URLScan 2.5
    ... Thanks Charles, the information provided works to resolve the issue (so far, ... To be clear of the steps that I took from original install of URLScan 2.5, ... > of requests reaching the server. ...
    (microsoft.public.windows.server.sbs)
  • Re: URLscan problem
    ... I did indeed restart the IIS server after ... I took a look at the URLscan log files and found my ... >URLscan seems to be causing a problem with public folder ...
    (microsoft.public.inetserver.iis.security)
  • RE: W3SVC, SMTP, IISAdmin services stopping..hacking?
    ... That SEARCH request is indicative of an attempt to exploit the ... of URLScan blocks SEARCH requests such as this one. ... Internet Services Manager -> right click on your server name -> Properties ... does contain a number of other very important security fixes for IIS. ...
    (microsoft.public.inetserver.iis.security)
  • Re: security advice (possible hacker activity?)
    ... I test URLScan before installing. ... server for virus, nothing found... ... Account Used for Logon by: ... I'd recommend installing it from the Lockdown ...
    (microsoft.public.inetserver.iis.security)

Loading