11.07.2015 Views

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

Improving Web Application Security: Threats and - CGISecurity

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 16: Securing Your <strong>Web</strong> Server 437The 404.dllIISLockdown installs the 404.dll, to which you can map file extensions that must notbe run by the client. For more information, see “Step 12. Script Mappings.”URLScanIf you install the URLScan ISAPI filter as part of IISLockdown, URLScan settings areintegrated with the server role you select when running IISLockdown. For example, ifyou select a static <strong>Web</strong> server, URLScan blocks the POST comm<strong>and</strong>.Reversing IISLockdown ChangesTo reverse the changes that IISLockdown performs, run IISLockd.exe a second time.This does not remove the URLScan ISAPI filter. For more information, see “RemovingURLScan” in the next topic.More InformationSee the following articles for more information about the IISLockdown tool:●●●For more information on running IISLockdown, see “How To: UseIISLockdown.exe” in the “How To” section of this guide.For information on troubleshooting IISLockdown, see Microsoft Knowledge Basearticle 325864, “How To: Install <strong>and</strong> Use the IIS Lockdown Wizard.” (The mostcommon problem is receiving unexpected “404 File Not Found” error messagesafter running IISLockdown.)For information on automating IISLockdown, see Microsoft Knowledge Basearticle 310725, “How To: Run the IIS Lockdown Wizard Unattended in IIS.”Install <strong>and</strong> Configure URLScanURLScan is installed when you run IISLockdown, although you can download it <strong>and</strong>install it separately. To install URLScan without running IISLockdown1. Download IISlockd.exe from http://download.microsoft.com/download/iis50/Utility/2.1/NT45XP/EN-US/iislockd.exe.2. Run the following comm<strong>and</strong> to extract the URLScan setup:iislockd.exe /q /cURLScan blocks requests that contain unsafe characters (for example, characters thathave been used to exploit vulnerabilities, such as “..” used for directory traversal).URLScan logs requests that contain these characters in the %windir%\system32\inetsrv\urlscan directory.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!