NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Tools & Applications

Tools & Applications


Download UrlScan 3.1

The successor of version 3.0

By Marius Oiaga, Technology News Editor

3rd of November 2008, 12:11 GMT

Adjust text size:



Enlarge picture
UrlScan is a free security tool available for download from Microsoft designed to bulletproof websites developed and running on top of Windows server operating systems and Internet Information Services. Delivered in order to filter SQL injection attacks, UrlScan is now at version 3.1, less than three months following the introduction of UrlScan 3.0 RTW. In fact, v3.0 was offered specifically to deal with the increasing wave of SQL injection attacks; however, at the same time, it managed to backfire. Microsoft's Wade Hilmo indicated that the UrlScan 3.0 filtering caused attackers to diversify and adapt their techniques.

“Very recently, our internal security team brought it to our attention that they'd seen a new variation on the attacks. This new variation is trying to exploit a behavior in ASP's parsing of the query string for the Request.QueryString function. Note that ASP.NET's behavior in this area is different and ASP.NET applications are not vulnerable to this specific new technique,” Hilmo explained. “The specific behavior in ASP results when the query string contains a name/value pair where the value contains a '%' sign that has not been escape encoded.”

In this context, version 3.1 of UrlScan brings an extension to the restricted HTTP requests that are processed by IIS. Via UrlScan 3.1, website administrators now have the possibility to block unescaped '%' signs in a request form being processed by web applications running on the server. According to Hilmo, query strings, headers (be it in a header name or value) can now benefit from the filtering enhancements introduced with the new feature of UrlScan 3.1.

“It was possible for certain escape sequences to get past filtering rules. This has been fixed. Certain query string rules did not work properly on IIS 5.1. This has been fixed. The behavior of the [ AlwaysAllowedUrls ] section has been changed. In UrlScan 3.0, any URLs listed in that section were not subject to filtering of anything that applied specifically to the URL. Effective with UrlScan 3.1, any URLs in that section are not subject to any UrlScan rules. This means that adding a URL to this section will prevent query string or other rules from blocking the URL,” Hilmo added.

UrlScan 3.1 is available for download here.

TAGS:

UrlScan | SQL injection | IIS | Windows Server
Read by 1,320 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
NOT RATED 0 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Web Application Installer for Vista RTM/SP1

Vista SP1 Microsoft Assessment and Planning Toolkit 3.2 Beta

Filter Pack for Windows Search 4.0 in XP SP3 and Vista SP1

Microsoft Surface and Business Intelligence

The Evolution of the Web Platform Installer for Windows 7

SQL Server 2008: 1 Trillion Row Query in Seconds

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM