URLScan ÊÇÒ»¸ö¿É¹©ÍøÕ¾¹ÜÀíԱʹÓõļÓÔØÏ¾ß¡£¹ÜÀíÔ±¿ÉÒÔ¿ØÖÆ URLScan µÄ²Ù×÷²¢ÏÞÖÆ·þÎñÆ÷´¦ÀíµÄ HTTP ÇëÇóµÄÀàÐÍ¡£
ĬÈÏ°²×° UrlScan »á£¬»á½ûÓà Web ·þÎñÀ©Õ¹ ¨C Active Server Pages£¬µ±ÊÖ¹¤ÆôÓÃʱ£¬Ò²²»¿ÉÓã¬ÔÚUrlScanµÄÅäÖÃÎļþÖÐ UrlScan.ini ĬÈϵÄÑ¡ÏîÒ²»á½ûֹʹÓÃһЩÀ©Õ¹£¨ÈÃÎÒµ÷ÊÔÁ˺ðëÌ죬ÒÔΪUrlScan ºÍ asp ISAPI ÓгåÍ»£©£¬ÒÔÏÂΪĬÈϽûÖ¹À©Õ¹Ñ¡Ï
<span style="font-family:'Microsoft YaHei'; font-size:13px">; Deny ASP requests<br />.asp<br />.cer<br />.cdx<br />.asa</span>
|
ÕâÑùÒ»°ã»á½ûÖ¹µôijЩ cer,asa Ö®Ààδ¹ýÂ˵ÄÉÏ´«Â©¶´¡£
»¹ÓÐһЩѡÏî¿ÉÒÔ½ûÖ¹µô TRACE ÇëÇó£¬RemoveServerHeader Ñ¡Ïî¿ÉÒÔɾ³ýÇëÇó°üÖеÄIIS°æ±¾ÐÅÏ¢£¨Server: Microsoft-IIS/6.0
£©£¬ÒÔ¼°IIS Ŀ¼½âÎö©¶´£ºhttp://www.woyigui.cn/test.asp/1.txt ¸ÃÇëÇó»á±»×èÖ¹¡£
Link:
ÏÂÔØUrlScan: http://download.microsoft.com/download/iis50/Utility/2.1/NT45XP/EN-US/iislockd.exe
ÏÂÔØÍêºóÓ㺠iislockd.exe /q /c ÃüÁîÌáÈ¡ UrlScan °²×°³ÌÐò¡£
ÈçºÎʹÓà URLScan http://msdn.microsoft.com/zh-cn/library/aa302368.aspx
ÈçºÎÅäÖà URLScan ¹¤¾ß: http://support.microsoft.com/kb/326444/zh-cn
¶Ô IIS ʹÓà URLScan: http://support.microsoft.com/default.aspx?scid=307608