New IIS Security Tool Released

Microsoft is making a new security tool, dubbed URLScan, available to customers immediately. The company says that URLScan is designed to help customer protect IIS-based web servers from the most common types of attacks

Paul Thurrott

September 12, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Microsoft has released a new security tool, dubbed URLScan, to customers. The company says that it designed URLScan to help customers protect Microsoft IIS-based Web servers from the most common types of attacks by helping to ensure that servers respond only to legitimate requests.

"URLScan is effective in protecting Web servers because most attacks share a common characteristic--they involve the use of a request that's unusual in some way," the company says in its release about the tool. "For instance, the request might be extremely long, request an unusual action, be encoded using an alternate character set, or include character sequences that are rarely seen in legitimate requests. By filtering out all unusual requests, URLScan prevents them from reaching the server and potentially causing damage."

Microsoft says that URLScan will protect Web servers against virtually every known security vulnerability that affects IIS, even if users haven't installed the previously released security patches. The tool complements the IIS Lockdown Tool (released 2 weeks ago), which makes sure that IIS servers are securely configured. URLScan runs in the background after the lockdown tool is finished, ensuring that the server responds only to legitimate Web requests.
 
For more information about URLScan and Microsoft's other IIS security tools, visit the Microsoft Web site.

About the Author

Paul Thurrott

Paul Thurrott is senior technical analyst for Windows IT Pro. He writes the SuperSite for Windows, a weekly editorial for Windows IT Pro UPDATE, and a daily Windows news and information newsletter called WinInfo Daily UPDATE.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like