IIS 7 and Above
Recommended setting for allowHighBitCharacters
Last post Mar 16, 2012 11:44 AM by fab777
Mar 16, 2012 11:14 AM|SaintNick|LINK
IIS7 configuration security
Mar 16, 2012 11:21 AM|fab777|LINK
IIS 7 include natively what has to be added with URLScan in IIS6.
Without URLScan, IIS6 will have the same behavior as IIS7 with a default configuration on this point.
So it's strongly recommended to filter High bit characters, so I recommend you to set to false on your IIS 7 configuration
[code]appcmd.exe set config /section:requestfiltering /allowhighbitcharacters:false[/code]
Mar 16, 2012 11:35 AM|SaintNick|LINK
Mar 16, 2012 11:44 AM|fab777|LINK
Why the recommended setting is 'false'? For security purpose I guess... ;)
It will prevent somme attacks, that's it.