Re: IIS 6.0 Directory Transversal Error with OWA.

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 09/22/04


Date: Wed, 22 Sep 2004 16:54:20 GMT

On Wed, 22 Sep 2004 06:43:01 -0700, Nathan Kodak
<NathanKodak@discussions.microsoft.com> wrote:

>I am having an issue with my Win2K3 IIS 6.0 box and my OWA. The problem is
>that IIS 6.0 by default KILLS any request that have ".." in the URL. Is there
>a way to modify this to look for "../" instead without installing URLScan
>2.5? I can install that if I have to, but was trying to avoid the extra
>hassles involved. This is a default problem with URLScan and IISLockdown, but
>I know how to solve it with those. Any help or direction would be appreciated.

See:

Enable Parent Paths Is Disabled by Default in IIS 6.0:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;332117

Jeff



Relevant Pages

  • Re: ASP.NET 2.0 maximum URL length?
    ... explicitly installed on my IIS7/Vista system? ... URLScan - an add-on tool I have not installed. ... It's a recommended install for IIS 4.0 and 5.0, ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Challenge in software distribution
    ... It was something like what you are doing I was thinking of, but was kind of hoping to avoid as I have a couple of tousand objects defined already, and was hoping to avoid doubling those.... ... switch to perform an upgrade. ... > didn't install the first version. ... > recoqnizes if the advertisement was invoked by the useror is ...
    (microsoft.public.sms.swdist)
  • Re: ASP.NET 2.0 maximum URL length?
    ... URLScan - an add-on tool I have not installed. ... It's a recommended install for IIS 4.0 and 5.0, ... MaxUrl specifies the maximum length of the request URL, ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Urlscan 2.5 unattended install
    ... I will pass this information along as a feature request (note that this does ... UrlScan does not have any dependencies, ... > Bernard Cheah ... >> it as easy as possible to install URLScan on servers. ...
    (microsoft.public.inetserver.iis.security)
  • Re: IIS Lockdown
    ... killed FP counters and search forms. ... allowing *.exe extensions in URLscan. ... >files in the install folder, you could edit those and see ... >> I want to run IIS Lockdown before exposing IIS5 server ...
    (microsoft.public.inetserver.iis.security)