<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.iis.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:cs="http://blogs.iis.net/"><channel><title>Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx</link><description>Dissecting the SQL injection sample in the walkthrough I will spend some time dissecting the SQL injection rule posted in the walkthrough for UrlScan. Before I do so, I want to re-iterate the fact that SQL injection is a web application issue, and hence</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#3486210</link><pubDate>Fri, 30 Oct 2009 18:51:57 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:3486210</guid><dc:creator>capturetr</dc:creator><description>&lt;p&gt;thanks good post. i am forward it... &amp;lt;a href = &amp;quot;&lt;a rel="nofollow" target="_new" href="http://saglikli-yasam-onerileri.blogspot.com/&amp;quot;&amp;gt;Saglikli"&gt;saglikli-yasam-onerileri.blogspot.com/&amp;quot;&amp;gt;Saglikli&lt;/a&gt; Yasam&amp;lt;/a&amp;gt;&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=3486210" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#3043802</link><pubDate>Fri, 27 Mar 2009 20:36:29 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:3043802</guid><dc:creator>Rovastar</dc:creator><description>&lt;p&gt;For those that are interested here is a guide to use some of the techniques I discussed here for reducing the false positives.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.iisportal.com/articles-and-news/advanced-sql-injection-protection-with-urlscan-3x.aspx"&gt;www.iisportal.com/.../advanced-sql-injection-protection-with-urlscan-3x.aspx&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=3043802" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2888837</link><pubDate>Sat, 24 Jan 2009 10:25:21 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2888837</guid><dc:creator>orjinal lida</dc:creator><description>&lt;p&gt;thank you&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2888837" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2874682</link><pubDate>Sun, 18 Jan 2009 16:33:33 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2874682</guid><dc:creator>oyun oyna</dc:creator><description>&lt;p&gt;Goodd Jobb!! thanks for this post admin i like it&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2874682" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2842901</link><pubDate>Fri, 02 Jan 2009 14:36:13 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2842901</guid><dc:creator>mirc mirç mırc</dc:creator><description>&lt;p&gt;Aciklama Sohbet Portali Ws&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2842901" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2842897</link><pubDate>Fri, 02 Jan 2009 14:35:05 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2842897</guid><dc:creator>mirc mirç mırc</dc:creator><description>&lt;p&gt;mirc mırc mır&amp;#231; mirc yukle sohbet&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2842897" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2780164</link><pubDate>Tue, 02 Dec 2008 18:17:45 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2780164</guid><dc:creator>sohbet</dc:creator><description>&lt;p&gt;It is interesting blog. Pleasant to me. I wish you a nice day! &lt;/p&gt;
&lt;p&gt;Thank you &lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2780164" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2688441</link><pubDate>Thu, 16 Oct 2008 22:10:36 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2688441</guid><dc:creator>Gazeteler</dc:creator><description>&lt;p&gt;good article&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2688441" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2680553</link><pubDate>Tue, 14 Oct 2008 03:36:40 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2680553</guid><dc:creator>naziml</dc:creator><description>&lt;p&gt;nustyle -&lt;/p&gt;
&lt;p&gt;This is just a sample list. I can't grow this because the more I do, the more false positives I would be introducing for the various applications out there. I expect admins to use this as a starting point and then add and remove from it as need be. HTH.&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2680553" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2645538</link><pubDate>Thu, 25 Sep 2008 12:53:17 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2645538</guid><dc:creator>nustyle</dc:creator><description>&lt;p&gt;hi there,&lt;/p&gt;
&lt;p&gt;can you please explain why your list is very short now?&lt;/p&gt;
&lt;p&gt;i have a long list now, and i want to cut some from it.&lt;/p&gt;
&lt;p&gt;but i dont know what i can cut. can you help me please? where can i find answers :)&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2645538" width="1" height="1"&gt;</description></item><item><title>Using SPF to Protect Against SQL Injection Worms - Gotham Digital Science</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2610291</link><pubDate>Tue, 09 Sep 2008 16:49:05 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2610291</guid><dc:creator>Using SPF to Protect Against SQL Injection Worms - Gotham Digital Science</dc:creator><description>&lt;p&gt;Pingback from &amp;nbsp;Using SPF to Protect Against SQL Injection Worms - Gotham Digital Science&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2610291" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2520915</link><pubDate>Tue, 29 Jul 2008 05:25:39 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2520915</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;UrlScan does not look at request entity and cannot deal with request.form. Check &lt;a rel="nofollow" target="_new" href="http://blogs.iis.net/nazim/archive/2008/06/30/urlscan-v3-0-filtering-based-on-request-entity.aspx"&gt;blogs.iis.net/.../urlscan-v3-0-filtering-based-on-request-entity.aspx&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2520915" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2507738</link><pubDate>Wed, 23 Jul 2008 07:01:21 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2507738</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;Does UrlScan also Filter Request.Form attach?&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2507738" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2497007</link><pubDate>Thu, 17 Jul 2008 17:53:08 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2497007</guid><dc:creator>naziml</dc:creator><description>&lt;p&gt;Rovastar,&lt;/p&gt;
&lt;p&gt;I get your point, but here is what I am getting at.&lt;/p&gt;
&lt;p&gt;a) UrlRewriter is not a magic bullet either ... however it IS more powerful than UrlScan in its ability to specify complex rules. You can only specify substring matches in UrlScan, but you can do a lot more with UrlRewriter in terms of expressing rules. But I still get your point ... I am coming across as recommending the use of UrlRewriter over UrlScan. This is not my intent ... I believe UrlScan does its job well. There are a few folks who demand a lot of flexibility in their rules ... to them I recommend UrlRewriter. In my opinion the added overhead of maintaining regexs overrules any benefit they provide.&lt;/p&gt;
&lt;p&gt;b,c) I can't really argue here :) Regex is complicated and not exactly readable by mere mortals. UrlRewriter module will come with a bunch of UI to make this task easier ... but not foolproof.&lt;/p&gt;
&lt;p&gt;d) You would put the capture group in your log file for regex.&lt;/p&gt;
&lt;p&gt;All I am saying is that you can't have your cake and eat it too. You can't have a lot of flexibility while still maintaining ease of use. If you are willing to sacrifice the latter for the former, go ahead and use UrlRewriter. Otherwise, stick with UrlScan (I know I do :)).&lt;/p&gt;
&lt;p&gt;Hope that clarifies my position.&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2497007" width="1" height="1"&gt;</description></item><item><title>re: Using the new rules configuration in UrlScan v3.0 Beta (Part 2)</title><link>http://blogs.iis.net/nazim/archive/2008/06/30/using-the-new-rules-configuration-in-urlscan-v3-0-beta-part-2.aspx#2491377</link><pubDate>Tue, 15 Jul 2008 18:06:21 GMT</pubDate><guid isPermaLink="false">50bcf3b4-f6fe-4638-adff-0c150e922e99:2491377</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;Simply you must know the sql queries running in your app, i. e. I never use any create in my apps runnig for all people, so, I can block create for any sql query (generally it is the used for creating temp tables in a &amp;quot;hand made attack&amp;quot;). With Asprox botnet now, you can be sure than varchar(4000) is a proof af attack and generally there is no a similar clause in any asp/aspx-SQL app. I never use &amp;quot;&amp;lt;&amp;quot; or &amp;quot;&amp;gt;&amp;quot; characters in any sql query in my app, so current automatic setting in URLscan 3.0 is useful against many sql injection attacks, included writing scripts directly to your database. I. e. Declare is generally used only in generated SQL scripts but none in any application, perhaps is more secure creating tables in database and later integrate they with app. You could create an index of used SQL sentences in your internet app and you'll be sure what &amp;quot;keywords&amp;quot; you could block. URLScan is a very good tool, and losing traffic is more related with a missuse than other fact. You can also &amp;quot;normalize&amp;quot; your page naming scheme and your queries scheme to avoid composite characters or spaces and blocking any white space in: be sure than many of attacks will include any %20, included all hexa queries.&lt;/p&gt;
&lt;img src="http://blogs.iis.net/aggbug.aspx?PostID=2491377" width="1" height="1"&gt;</description></item></channel></rss>