Security Software Zone Security Software Zone
Home Contact Us
Search in
Forum SecurityToolbox Submit Software
Security Software Zone Login
Security Software Categories
News - Articles - Reviews
Free Newsletter
Join our mailing list and receive
security software news and
advice from our experts.
Submit
  Security Software Zone » Software Reviews » Privacy » How to Prevent Log Evasion in IIS

How to Prevent Log Evasion in IIS

Category: Privacy
Published: 02/02/2007, 11:49  
Editor: Security Software Zone
 
Print article
Send to a friend
Search in reviews

Microsoft released a security hardening tool for IIS dubbed "UrlScan" allowing server admin to set various security lockdown measures including the ability to restrict the size of a user's request. With "Urlscan" not only can we set request size restrictions (blocking an attackers attempt to thwart IIS's logging capabilities), but we can also log the entire request string sent by the attacker for further analysis. To start, first download "UrlScan" software and configure it to block long requests. Blocking long requests ensures that the request never reaches the target application, which thwarts an attacker's attempt to mask the attack against a specific application.

Installation Steps:

1. After downloading Setup.exe from Microsoft's site, double-click it.

2. If, after carefully reviewing the End User License Agreement, you agree to the installation of UrlScan, click "Yes."

3. When you see a pop-up box stating, "UrlScan has been successfully installed", installation is complete. Two files (UrlScan.ini and UrlScan.dll) will be installed under %windir%\system32\inetsrv\urlscan, which is usually under C:\WINNT\system32\inetsrv\urlscan on a Windows 2000 server.

Configuration Steps:

1. Go to the directory created by UrlScan (as stated above) and open the UrlScan.ini file.

2. The default setting "MaxQueryString=2048" is an acceptable default that will prevent query strings longer than 2,048 characters from being passed to the application.

3. Configure any other options you may need. In URLScan 2.5, Microsoft introduced the "LogLongUrls" option that allows logging up to 128k of a request. This option can be enabled in UrlScan.ini by changing "LogLongUrls=0" to "LogLongUrls=1". By setting this option, you can log any attempts by an attacker who is trying to exploit this issue.

You must restart IIS for this change to take effect. Conclusions Microsoft's URLScan is a very useful tool that every IIS administrator should take the time to investigate. This document outlines steps to harden your system against a specific threat. Documentation on how to enable length restrictions on request header data can be found at the URLScan homepage .  Readers of this document are encouraged to explore other configuration options in URLScan to further lock down their machine. Microsoft confirms that this behavior works as designed. Previous versions of IIS (version 4.0 and below) were not tested for this vulnerability and may also be affected.

Bookmark to:
Add 'How to Prevent Log Evasion in IIS' to Del.icio.us Add 'How to Prevent Log Evasion in IIS' to digg Add 'How to Prevent Log Evasion in IIS' to FURL Add 'How to Prevent Log Evasion in IIS' to reddit Add 'How to Prevent Log Evasion in IIS' to Technorati Add 'How to Prevent Log Evasion in IIS' to Yahoo My Web Add 'How to Prevent Log Evasion in IIS' to Stumble Upon Add 'How to Prevent Log Evasion in IIS' to Google Bookmarks Add 'How to Prevent Log Evasion in IIS' to RawSugar Add 'How to Prevent Log Evasion in IIS' to Squidoo Add 'How to Prevent Log Evasion in IIS' to Spurl Add 'How to Prevent Log Evasion in IIS' to Netvouz Add 'How to Prevent Log Evasion in IIS' to Rojo Add 'How to Prevent Log Evasion in IIS' to Bloglines Add 'How to Prevent Log Evasion in IIS' to Tailrank
Add comment
Security Software Zone is not responsible for the content of these User comments. The views and opinions expressed are those of the individual poster and not the Security Software Zone.
User comments (0):

There is no comment for this review.

 
Reviews related to How to Prevent Log Evasion in IIS
 

Personal and Financial Information Security is a Big Concern for Two Thirds of All American Adults
 "People should not assume the best, but the worst. When it comes to protecting the privacy and security of your financial and personal records, it is better to be safe than sorry."said Mickey Macedo from Taxsoftware.com
Read More >
03/13/2007, 15:57
 

Federal Trade Commission's Online ID Theft Complaint Form is Vulnerable to Keylogger Attacks
 A warning about the personal information submitted via the Federal Trade Commission's online ID Theft Complaint Form.
Read More >
04/06/2007, 18:12
 

VASCO's VACMAN Controller and Digipass GO6 offered by Leading Japanese Mizuho Bank
 An important Breakthrough for VASCO in Strategically Important Japanese Market is the fact that Mizuho is First Bank in Japan to Use VASCO's Products
Read More >
02/27/2008, 10:35
 

Phishing - How criminals commit identity theft
 Definition of "phishing" and how to protect from such things.
Read More >
11/20/2006, 17:53
 

Bloxx Web Filtering Installed by Glasgow School
 The enterprise web filtering specialist, Bloxx, announced today that The High School of Glasgow has deployed Bloxx web filtering technology to monitor pupil and staff online activity and to provide enhanced security for its IT network.
Read More >
02/29/2008, 19:48

Sponsored