RE: IIS6.0 and UrlScan

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: WenJun Zhang[msft] (v-wzhang_at_online.microsoft.com)
Date: 02/12/04


Date: Thu, 12 Feb 2004 01:12:22 GMT

Hello Ali,

We say that IIS6 has already been locked down, so that there will not
be a IIS6 version lockdown wizzard. However, URLScan does have some
additional features that IIS6 built-in hasn't involved, such as: deny
HTTP verb/header, filter character sequences in URL. That's why the
new released 2.5 version UrlScan tool is supported to be deployed on
IIS6.

Please refer to the following TechNet page, which contains download
link and the detailed comparison between URLscan and IIS 6.0 secure
features:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/sec
urity/tools/urlscan.asp

Let us know anytime you meet issues related to IIS. Our pleasure to
be of assistance.

Have a nice day,

WenJun Zhang
Microsoft Online Support
This posting is provided "AS IS" with no warranties, and confers no
rights.
Get Secure! - www.microsoft.com/security



Relevant Pages

  • Re: Install/Use UrlScan on 6.0?
    ... IIS6 is secure without using URLScan. ... URLScan has additional features not in IIS6 ...
    (microsoft.public.inetserver.iis.security)
  • RE: UrlScan and IISLockdown
    ... Subject: IIS6.0 and UrlScan ... We say that IIS6 has already been locked down, ... Let us know anytime you meet issues related to IIS. ... Get Secure! ...
    (microsoft.public.inetserver.iis.security)
  • Re: URLScan 2.5 for SBS2003?
    ... URLScan that you will find useful, that aren't included in IIS6. ... these features is the ability to strip the IIS6 header from the server, ... > Is URLscan safe to install on SBS2003? ...
    (microsoft.public.windows.server.sbs)
  • Re: Securing IIS 6
    ... IIS6 comes in a secured and locked down configuration, ... Do I have to use URLScan or IIS lockdown on my W2k3 IIS 6? ... secure my IIS. ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS 6 2003
    ... It is still your misconfiguration of URLScan. ... which is a URL with an extension of ASP. ... IIS6 do not have such limitations since it is directly rigged to the static ... best guess effort at determining the extension of a URL; IIS6 features know ...
    (microsoft.public.inetserver.iis)