Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


July 2002

URLScan 2.5 Adds Protection

RSS
Subscribe to Windows Web Solutions | See More Internet Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
Main Article    Protect Your IIS Server with URLScan

URLScan 2.5 offers additional configuration options that help you further lock down your servers. You can download URLScan 2.5 at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/tools/tools/urlscan.asp. URLScan 2.5's new features include the ability to change the log-file directory, to log long URLs, and to restrict the size of requests. Note that you should install URLScan 2.0 before you install URLScan 2.5.

When you install URLScan 2.5, the tool adds settings to urlscan.ini that correspond to the new features. If you've configured an earlier version of URLScan for your site, URLScan 2.5 doesn't overwrite your current settings when it adds new entries. However, you will want to configure the new default options just as you configured the default options for URLScan 2.0.

When you download URLScan 2.5, you must choose between the baseline variant or the Security Rollup Package (SRP) variant. The difference lies in the values that URLScan 2.5 sets for the new urlscan.ini settings. According to the Microsoft documentation, the main difference between the URLScan-SRP configuration and the Baseline URLScan configuration lies in how each handles chunked-encoding data transfers. By default, URLScan-SRP blocks chunked-encoding transfers. The baseline variant doesn't block these transfers by default. In addition, the URLScan-SRP configuration restricts uploads to the server to 30MB. All other features of the SRP variant are the same as those of the baseline variant.

The SRP variant rejects "chunked" transfers of data because of vulnerabilities in IIS's chunked-encoding mechanism. (You use chunk transfers when you must transfer dynamic content without knowing the content's length in advance.) You won't find a simple way to determine whether your Web site uses chunked encoding short of enabling the feature to reject chunked encoding and fully exercising your Web site.

Note that if you installed the cumulative IIS patch that Microsoft announced in Microsoft Security Bulletin MS02-018 (Cumulative Patch for Internet Information Services) at http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms02-018.asp, you're already protected against known exploits related to chunked encoding. However, because I always recommend the strictest possible security configuration as protection against yet-to-be discovered vulnerabilities, I recommend installing the SRP variant on a test copy of your Web site and fully exercising your Web site's functionality to make sure you haven't broken any pages or operations. After you perform tests and otherwise verify that your Web site doesn't use chunked encoding, deploy the SRP variant in production. If your Web site uses chunked encoding or if your clients need to upload files larger than 30MB, you must use the baseline variant.

Be aware that for protection against buffer overflows, both the baseline and SRP variants impose a few new restrictions on various sections of incoming requests. I'll review these and all the other settings in an upcoming article's discussion of urlscan.ini.

End of Article



Reader Comments
your intellitext popups are garbage.
they have no business on your page.

Anonymous User January 10, 2005


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
WinInfo Short Takes: Week of November 23, 2009

An often irreverent look at some of the week's other news, including some post-PDC some soul searching, a Google Chrome OS announcement and a Microsoft response, Windows 7 off to a supposedly strong start, the Jonas Brothers and Xbox 360, and so much more ...

2009 Windows IT Pro Editors' Best and Community Choice Awards

Picking a favorite product from an impressive crowd of competitive offerings is never an easy task, and such was the case with our Editors' Best and Community Choice awards this year. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events Managing IT Across Multiple Locations

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement