Solved

Redirect rewrite back to same address

Posted on 2016-10-26
3
81 Views
Last Modified: 2016-10-27
Hi,

I can not modify code on this problem must do  it in IIS. It is a Microsoft .net frameworks 4.0 website iis6

I have a website that I want a user to get into only from a specific refereed address

Let's ay it is http://www.contoso.com   

there is a page http://www.contoso.com/profile.aspx    I do not want the user going right to http://www.contoso.com/profile.aspx     but want them to go to http://www.contoso.com/default.aspx  .   in default.aspx it will set a security session variable then redirect back to http://www.contoso.com/profile.aspx

How can I do this strictly with IIS?  I can  not change the applications code.
0
Comment
Question by:Charles Baldo
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 52

Expert Comment

by:Ryan Chong
ID: 41861677
in your existing codes, is that profile.aspx  will be redirected to default.aspx if there is not session variable being stored?
0
 
LVL 28

Accepted Solution

by:
Dan McFadden earned 500 total points
ID: 41861794
This is not something that IIS can do.  In general, the AppPool that hosts the site/app, has no knowledge of any sessions that exist or not.  The AppPool do not have any configurable interface to talk to the application code to pull a session and check if it valid or not.

The only way I can think of this working is to use the "HTTP_Referer" field in the inbound HTTP request.  This is easily accomplished with the URL Rewrite feature that is available for IIS7+.

Here is an IIS.NET forum dicussion on the same issue.

Link:  https://forums.iis.net/t/1189057.aspx

But you have a technology challenge, namely IIS6.  There are builtin URL Rewrite options for IIS6.  You need to use either a 3rd party commercial ISAPI filter like something from Helicon (Apache compatible URL rewriting for IIS :  http://www.isapirewrite.com/) or an open source product like Ionics Isapi Rewrite Filter (http://iirf.codeplex.com/).

Dan
0
 

Author Closing Comment

by:Charles Baldo
ID: 41862175
Thank you
0

Featured Post

How to Defend Against the WCry Ransomware Attack

On May 12, 2017, an extremely virulent ransomware variant named WCry 2.0 began to infect organizations. Within several hours, over 75,000 victims were reported in 90+ countries. Learn more from our research team about this threat & how to protect your organization!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Blackberry and SMS logging 5 40
Documents do not open in Protected View. 5 76
Wannacry 44 105
Enable TLS 1.2 for SQL 2012 Web Edition 1 25
If you are looking at this article, you have most likely been hit by some version of ransomware and are trying to find out if there is anything you can do, or what way you should react - READ ON!
Do you know what to look for when considering cloud computing? Should you hire someone or try to do it yourself? I'll be covering these questions and looking at the best options for you and your business.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question