I like it!
As a nice by-product it keeps refused requests from getting in to the IIS logs. Plus
since it keeps its own log I now have a centralized log for bogus requests. Nice.
Thanks for the heads-up.
---------------------------------------
Matt Robertson [EMAIL PROTECTED]
MSB Designs, Inc., www.mysecretbase.com
---------------------------------------
---------- Original Message ----------------------------------
from: Dave Watts <[EMAIL PROTECTED]>
Reply-To: [EMAIL PROTECTED]
date: Wed, 12 Sep 2001 18:50:02 -0400
There's a new IIS tool from Microsoft called URLScan, which allows you to
create filtering rulesets that can prevent malicious requests. I just
downloaded it, and it looks like it might be worth taking a look at, if
you're using IIS:
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
urlscan.asp
Dave Watts, CTO, Fig Leaf Software
http://www.figleaf.com/
voice: (202) 797-5496
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Get the mailserver that powers this list at http://www.coolfusion.com
FAQ: http://www.thenetprofits.co.uk/coldfusion/faq
Archives: http://www.mail-archive.com/[email protected]/
Unsubscribe: http://www.houseoffusion.com/index.cfm?sidebar=lists