Browse by Tags

All Tagsiis 6iis 6.0URlScan SQL Injection (RSS)
  • URLScan 3.0 RTW: [AlwaysAllowedQueryStrings]

    Doing some testing, currently, and running into some issues with this. We've got a couple cases where things like 'cast' or 'open' are appropriate for our webpages. I've setup an AlwaysAllowedQueryStrings section: [AlwaysAllowedQueryStrings] branch=Openshaw branch=Newcastle+upon...
    Posted to Forum by jgraham on 09-02-2008, 9:46 AM
  • Re: urlScan 3.0 rtw [AlwaysAllowedUrls] not working? Wildcard/regex in [AlwaysAllowedQueryStrings]

    Hi Zhao, Thank you for your reply. I now understand how [AlwaysAllowedUrls] works and where the query string check is still performed on the allowed Urls. To clarify, here is what I would like to achieve. For instance, I would like the following 'url+query string' to be valid: http://www.domain...
    Posted to Forum by ytkaczyk on 08-28-2008, 11:46 AM
  • urlScan 3.0 rtw [AlwaysAllowedUrls] not working?

    I would like to allow a search page to accept all text in the query string. To do this I added the result page to the [AlwaysAllowedUrls]. One thing that is ambiguous from the documentation is if the [AlwaysAllowedUrls] settings also bypasses the custom rules and if the pages listed in [AlwaysAllowedUrls...
    Posted to Forum by ytkaczyk on 08-25-2008, 2:30 PM
Page 1 of 1 (3 items)
Page view counter