ISAPI filters

can anyone give a beginners introduction into isapi filters (what they do), and any risks associated with not disabling them on a production web server (running IIS)? In what circumstances would you need to enable these isapi filters, and where in iis manager can you see if they are enabled or not? I am not from a development background so please go easy in your responses!
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Prashant ShrivastavaConsultantCommented:
ISAPI filters are DLL (Dynamic Link Library) files that can be used to modify and enhance the functionality provided by IIS. When IIS server runs ISAPI filters run on an IIS server. This filters and block every request until they find one they need to process.

Filters are registered at either the site level or the global level and are initialized when the worker process is started. A filter listens to all requests to the site on which it is installed.

ISAPI filters can be registered with IIS to modify the behaviour of a server. For example, filters can perform the following tasks:
Change request data (URLs or headers) sent by the client, Control which physical file gets mapped to the URL, Control the user name and password used with anonymous or basic authentication
Modify or analyse a request after authentication is complete , Modify a response going back to the client, Run custom processing on "access denied" responses, Run processing when a request is complete, Run processing when a connection with the client is closed ,Perform special logging or traffic analysis, Perform custom authentication, Handle encryption and compression.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
pma111Author Commented:
why are they a security risk then?
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft IIS Web Server

From novice to tech pro — start learning today.