Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

How to disable Double Escape filter in URLScan ?

Posted on 2009-06-30
4
Medium Priority
?
1,487 Views
Last Modified: 2012-05-07
Hello,

I'm using URLScan 3.1 to help improve a IIS 6.0 + Exchange
OWA Security.
I'm getting a lot of "Rejected URL+is+double+escaped" errors.
How can I disable the URLScan Double Escape filter ??

Thanks in advance!
0
Comment
Question by:itfly
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 65

Expert Comment

by:Mestha
ID: 24748187
Is the server dedicated to Exchange? If so then you shouldn't run URLSCAN on the machine. It isn't required and will simply break OWA.

Simon.
0
 

Author Comment

by:itfly
ID: 24748526
Hello Simon,

Thanks for the tip...

The only problem I noticed using URLScan with OWA is that boring error message about "double escaped urls".

Do you know how may I disable it?

Thanks in advance!

Best Regards,
0
 
LVL 65

Accepted Solution

by:
Mestha earned 2000 total points
ID: 24748587
Never used URLSCAN on Windows 2003 as it is unnecessary. No idea how to disable that - even if you should.

Simon.
0
 
LVL 1

Expert Comment

by:maduko
ID: 25236409
So why does it keep SQL injection attacks out?
0

Featured Post

Survive A High-Traffic Event with Percona

Your application or website rely on your database to deliver information about products and services to your customers. You can’t afford to have your database lose performance, lose availability or become unresponsive – even for just a few minutes.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out this step-by-step guide for using the newly updated Experts Exchange mobile app—released on May 30.
How to deal with a specific error when using the Enable-RemoteMailbox cmdlet to create a mailbox in the cloud-based service, for an existing user in an on-premises Active Directory.
In this video we show how to create an email address policy in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.:  First we need to log into the Exchange Admin Center. Navigate to the Mail Flow…
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

670 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question