?????? ??? ???? ???? ????? ????? ???????? ??? ????? ???? URLScan ?? Microsoft ????? ??????? ?????? (IIS). ????? ????? URLScan ?? ???? Microsoft ??? ????? ???????? ??????? ???????? ?? ??? ???????. ??? ????? URLScan ????? ???? ?????? ???? ???.
????? ?????? URLScan
????? ????? ????? ?? ????? ?? ????? ????? ??? ?? ????? ????? ? ??? ????? ?????? ??? ???? ???. ????? ?????? ???? URLScan ????? ?????? ??? ???? ??? ??????. ?????? ??? ?????? ???????? URLScan ?? ?????? ???? Microsoft ?????? ??? ?????:
????? ??? ??????? URLScan ?????????
??? ?? ?????? ??????? ????????? URLScan ?? ????? FrontPage ? ????? ??? ????? ??????? ??? ???? FrontPage "???? ???? ???? ??? ??? ?????? ??? ??????? FrontPage ??????. ??????? ??????? ??? ??????. ?????? ??? ??????? ?????? ??? ??????? URLScan ???? ??? "
References" ?????? ?? ??? ???????.
- ???? ??? ?????? ?????? ??? ???? ?? ???? ??? ???????. ??? ???? ?????? ??????:
%windir%\system32\inetsrv\urlscan
??? ?? %windir% ???? Windows (??? ???? ??????? C:\Windows ?? C:\Winnt). - ???? ??? ?????? ?????? ??? ????? Urlscan.ini ?? ???? ??? ???. ???? ??? ?????? ?????? ??? ?????? ?? ???? ??? ???. ??? ????? ??? Urlscan.ini ???? ????? ??????.
- ???? ????? ??????? ??? ????? Urlscan.ini. ??? ??? ????? ?? "???????".
- ?? ?????? ????????? ???????:
- ?? ?????? [??????] ? ?? ?????? ????? ???????:
[options]
UseAllowVerbs=1 ; use the [AllowVerbs] section
UseAllowExtensions=0 ; use the [DenyExtensions] section
NormalizeUrlBeforeScan=1 ; canonicalize URL before processing
VerifyNormalization=1 ; canonicalize URL twice, reject on change
AllowHighBitCharacters=0 ; deny high bit (UTF8 or MBCS) characters
AllowDotInPath=0 ; deny dots in path
EnableLogging=1 ; log activity
PerDayLogging=1 ; change log files daily
PerProcessLogging=0 ; do not change log files by process ID
RemoveServerHeader=0 ; do not remove "Server" header
AlternateServerName=
UseFastPathReject=0 ; use RejectResponseUrl or log the request
RejectResponseUrl=
AllowLateScanning=1 ; allow URLScan to be loaded low priority
- ?? ?????? [AllowVerbs] ? ?????? ????? ??????? ???. ?? ??? ?????? ??? ????.
[AllowVerbs]
GET ; allow GET (most Web requests)
HEAD ; allow HEAD requests
OPTIONS ; allow OPTIONS (Web Folders need this)
POST ; allow POST (FrontPage Server Extensions and HTML forms need this)
- ?? ?????? [DenyHeaders] ? ?????? ????? ??????? ???. ?? ??? ?????? ??? ????.
[DenyHeaders]
If: ; deny (used with WebDAV)
Lock-Token: ; deny (used with WebDAV)
- ?? [DenyExtensions] ?????? ????? ????? ???????:
[DenyExtensions]
.asa ; deny active server application definition files
.bat ; deny batch files
.btr ; deny FrontPage dependency files
.cer ; deny x509 certificate files
.cdx ; deny dynamic channel definition files
.cmd ; deny batch files
.cnf ; deny FrontPage metadata files
.com ; deny server command-line applications
.dat ; deny data files
.evt ; deny Event Viewer logs
.exe ; deny server command-line applications
.htr ; deny IIS legacy HTML admin tool
.htw ; deny Index Server hit-highlighting
.ida ; deny Index Server legacy HTML admin tool
.idc ; deny IIS legacy database query files
.inc ; deny include files
.ini ; deny configuration files
.ldb ; deny Microsoft Access Record-Locking Information files
.log ; deny log files
.pol ; deny policy files
.printer ; deny Internet Printing Services
.sav ; deny backup registry files
.shtm ; deny IIS Server Side Includes
.shtml ; deny IIS Server Side Includes
.stm ; deny IIS Server Side Includes
.tmp ; deny temporary files
- ?? ?????? [DenyUrlSequences] ? ?? ?????? ????? ???????:
[DenyUrlSequences]
.. ; deny directory traversals
./ ; deny trailing dot on a directory name
\ ; deny backslashes in URL
: ; deny alternate stream access
% ; deny escaping after normalization
& ; deny multiple CGI processes to run on a single request
/fpdb/ ; deny browse access to FrontPage database files
/_private ; deny FrontPage private files (often form results)
/_vti_pvt ; deny FrontPage Web configuration files
/_vti_cnf ; deny FrontPage metadata files
/_vti_txt ; deny FrontPage text catalogs and indices
/_vti_log ; deny FrontPage authoring log files
- ????? ??? ?? ?????? ??? ????????? [DenyVerbs] ??? ????? ??????? [AllowExtensions] ??????? ?? ??? ??? ??????? ?? ??? ???????. ????? ?? ????????? ??? ??? ??????? ?? ??? ??????? "? ???? ??? ??? ??????? ?????? ?????? ??" ????? ??????? ?? Microsoft:
307608
(http://support.microsoft.com/kb/307608/
)
???????? URLScan ??? IIS
- ??? ????? ?? ?????? "???????".
????? ?????? URLScan (???????)
???????? ?????????? ???? URLScan ?? IIS ????. ?? ?????? ??? ?????? ?????? ?? ????? ??????? ?????? ?????? ???? ??????? ??????? ????? (ISAPI) "???? ????? ??? ????? ?????? ??? ?? ??? ??????? URLScan. ???? ????? ISAPI ?????? ???? FrontPage (Fpexedll.dll) ?? ???? ???????. ??? ????? ?? ?? ????????? ?? ??? ????? ???? ??? ??????? ????? ????? URLScan ????? ??? ???? ????? ISAPI Fpexedll.dll ? ????? ?????? ?????? ??? ??????? ?????? URLScan ?? ????? ????? ISAPI ??????. ????? ?? ?????????? ???? ????? ????? ????? ISAPI ???? ???????.
?????? ??? ?? ????? ?? ????? ??????? ?????? ????? ??? ????? ???? ???? ?? AllowLateScanning = 1 ??????? ?? ????? Urlscan.ini ????? URLScan ????? ????? ?????? ??????. ?????? ????? ???? ??????? ?? ??? "
Modifying the default URLScan configuration
file" ?? ??? ???????.
- ??? ????? ????? ????? ??????. ?????? ????? ???? ??????? ???????? ????? IIS:
- ?? IIS 4.0:
- ?? ??????? ???? ? ???? ??? ??????? ?? ???? ??? Windows NT 4.0 Option Pack.
- ???? ??? ???? ??????? ?????? Microsoft.
- ??? ????? ????? ??????.
- ?? IIS 5.0:
- ?? ??????? ???? ? ???? ??? ??????? ?? ???? ??? ????? ??????.
- ??? ????? ????? ??????.
- ?? IIS 5.1:
- ??? ??????? "????" ? ???? ??? "???? ??????".
- ???? ????? ??????? ??? ????? ??????.
- ???? ????? ??????? ??? ????? ??????? ??????.
- ???? ??? ?????? ?????? ??? ???? ????????? ?? ???? ??? ?????.
- ??? ?????? ????? ???? WWW ???????? ?? ???? ??? ???? ?????.
- ???? ??? ????? ??????? ????? ????? ISAPI.
- ???? ??? UrlScan ?? ???? ??? ???? "?????" ?????? UrlScan ????? Fpexedll.dll.
- ???? ??? ?????.
- ???? ??? ????? ??? ????.
????? ????? IIS ?????? URLScan
??? ??? ????? IIS ??? ?????? ??? ??????? URLScan ????? ????????? ?? ??? Urlscan.ini. ????? ??? ????? ????? IIS ??? ???? ??????? ??????? ??????? ????? ???????. ?????? ????? ???? ??????? ???????? ????? IIS:
- ?? IIS 4.0:
- ?? ???? ???????? ???? ????? ??????:
STOP NET /Y "???? ????? IIS"
- ??? ??? ??? ?????? ?? ??????? ??????? ???????? ??? ?? ??????? ????? ????? ???? ????? ????? ????? ??? ??????? ??????.
- ????? ????? ??????? ???????
?? ????? ???? ???? ????? IIS ?????.
????? ????? ???? IIS ?? ???. ?????? ????? ???? ??????? ??????? ?? ???? ??????? ????? ??? ??????? ENTER ??? ?? ???:??? NET "??? ???? ?????"
??? NET "Simple Mail ???????? ????? (SMTP)"
??? NET "???? ????? FTP"
??? NET "???? ????? ?????? IIS"
- ???? ???? ???????.
- ?? IIS 5.0:
- ???? ??? ?????? ?????? ??? ??? ?????? ??? ?? ???? ??? ????? ????? IIS.
- ???? ??? ????? ????? ????? ?????? ??? Your Computer.
- ???? ??? ?????.
- ?? IIS 5.1:
- ???? ??? ?????? ?????? ??? ???? ????????? ? ??? ??? ???? ?????? ?? ???? ??? ????? ????? IIS.
- ???? ??? ????? ????? ????? ?????? ??? Your Computer.
- ???? ??? ?????.
236166
(http://support.microsoft.com/kb/236166/
)
???????? STOP NET ? START NET ???? ????? IIS re-read ???????
202013
(http://support.microsoft.com/kb/202013/
)
?????? ???? ?????? 5.0 ?????? ??????? ??? ??????? ?? Iisreset.exe
??????? ??????? ????????
- ???? ????????? ???????? ?? ??? "Modifying the default URLScan configuration file" ?? ??? ??????? ?? EnableLogging = 1 ??????? ?? [??????] ?????? ?? ????? Urlscan.ini. ???? ??? URLScan ???????? ??? ???? URLScan ???? ??? ?????. ??? ??? ??? ????? ??? ?? ??? ?????? ??? ????? Urlscan.dll. ??? ?????? ??? ?????? ???????? FrontPage ?? ?????? IIS ??????? ????? ????? URLScan ?????? ???? ????????? ?? ??? ????? ?????? ??? ??????? ??? ??? ????? ??.
- ??? ??? ?????? ??????? ?????? ??? ??? Urlscan.ini ?????? ??? ????? Urlscan.ini ????? ??????? Urlscan.001 ? Urlscan.002 ? ?? ???? ??? ? ???? ???? ???? ??????? ?????????? ???? ???????. ????? ??? ?? ??? ????? ????? ??? ??? ?????? ????? ????? ???? ????.
- ?? ???? ?? ???? ?? ????????? ???? ?????? ??? URLScan ????? ??????? ? ??? ??????? ??? ????? ????? ????? IIS. ??? ??? ????????? ?? ???? ?? ???? ????? ??????? ? ????? ????? ???? ???.
?????? ??? ???? ?? ????????? ??? ????? ????? ???? URLScan ???? ??? ????? ???????? ??????? ?????? ?? "????? ??????? ?? Microsoft:
307608
(http://support.microsoft.com/kb/307608/
)
???????? URLScan ??? IIS
307976
(http://support.microsoft.com/kb/307976/
)
???? ????? ??? ??? ??????? FrontPage ?? URLScan
309508
(http://support.microsoft.com/kb/309508/
)
IIS ????? ???????? URLscan ?? ???? Exchange
???? ???????: 309394 - ????? ??? ??????: 03/???/1428 - ??????: 6.2
????? ???
- Microsoft FrontPage 2000 Server Extensions
- Microsoft SharePoint Team Services
- Microsoft Internet Information Server 4.0
- Microsoft Internet Information Services 5.0
- Microsoft Internet Information Services version 5.1
| kbmt kbdownload kbsetup kbconfig kbwebserver kbwebservices kbhowtomaster KB309394 KbMtar |
????? ???????: ??? ????? ??? ?????? ???????? ?????? ????? ???? ????? ?????????? ????? ?? ????????? ?????? ????. ???? ???? ?????????? ???? ?? ???????? ???????? ?????? ????????? ????? ????????? ???????? ????? ???????? ?????? ?? ?????? ??? ?? ???????? ???????? ?? ????? ??????? ?????? ??? ??????? ?????? ??. ?????? ?? ???? ??? ??????? ???????? ????? ?? ???? ????? ?????? ??? ????? ??? ????? ??????? ?? ????? ?? ?????? ??? ??? ??????? ??????? ?? ????? ????? ????? ????? ?????. ?? ????? ???? ?????????? ??????? ??? ????? ?? ??????? ?? ????? ?????? ?? ??? ????? ?? ????? ??????? ?? ???????? ?? ??? ???????. ???? ???? ?????????? ???????? ??? ????? ?????? ??????? ??????
???? ??? ????? ??????? ?????? ??????????
309394
(http://support.microsoft.com/kb/309394/en-us/
)