We help IT Professionals succeed at work.

How to disable Double Escape filter in URLScan ?

Medium Priority
1,549 Views
Last Modified: 2012-05-07
Hello,

I'm using URLScan 3.1 to help improve a IIS 6.0 + Exchange
OWA Security.
I'm getting a lot of "Rejected URL+is+double+escaped" errors.
How can I disable the URLScan Double Escape filter ??

Thanks in advance!
Comment
Watch Question

Expert of the Quarter 2009
Expert of the Year 2009

Commented:
Is the server dedicated to Exchange? If so then you shouldn't run URLSCAN on the machine. It isn't required and will simply break OWA.

Simon.
FabioConsultant

Author

Commented:
Hello Simon,

Thanks for the tip...

The only problem I noticed using URLScan with OWA is that boring error message about "double escaped urls".

Do you know how may I disable it?

Thanks in advance!

Best Regards,
Expert of the Quarter 2009
Expert of the Year 2009
Commented:
Unlock this solution and get a sample of our free trial.
(No credit card required)
UNLOCK SOLUTION

Commented:
So why does it keep SQL injection attacks out?
Unlock the solution to this question.
Thanks for using Experts Exchange.

Please provide your email to receive a sample view!

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.