Code Comments

Programming Forum and web based access to our favorite programming groups.
For Programmers: Free Programming Magazines | New: Database administration forum
Registration is free! Edit your profileCalendarFind other membersFrequently Asked QuestionsSearch -> 
Post New Thread











Thread
Author

Parent Paths
If I've enabled Parent Paths (PP) in IIS, but have installed the URL Filter
and disallowed ".." and "../" within links, am I covered from the
vulnerabilities of PP's?

This allows me to use PP's in #Include statements, but doesn't allow
visitors to use PP's in their links to access directories on my server.

Is this correct?

TIA



Report this thread to moderator Post Follow-up to this message
Old Post
news.microsoft.com
10-26-04 08:55 PM


Re: Parent Paths
Sounds like it would work...are you able to test it and see?

--
Ben Strackany
www.developmentnow.com


"news.microsoft.com" <me@here.com> wrote in message
news:%230nt8W4uEHA.1308@TK2MSFTNGP09.phx.gbl...
> If I've enabled Parent Paths (PP) in IIS, but have installed the URL
Filter
> and disallowed ".." and "../" within links, am I covered from the
> vulnerabilities of PP's?
>
> This allows me to use PP's in #Include statements, but doesn't allow
> visitors to use PP's in their links to access directories on my server.
>
> Is this correct?
>
> TIA
>
>



Report this thread to moderator Post Follow-up to this message
Old Post
Ben Strackany
10-28-04 08:55 PM


Re: Parent Paths
Yes, it does work. I was just wondering if there were any other
vulnerabilities that I might have missed (in regards to using Parent Paths)


"Ben Strackany" <infoNOSPAM@developmentnow.nospam.com> wrote in message
news:%23YyORXQvEHA.1400@TK2MSFTNGP11.phx.gbl...
> Sounds like it would work...are you able to test it and see?
>
> --
> Ben Strackany
> www.developmentnow.com
>
>
> "news.microsoft.com" <me@here.com> wrote in message
> news:%230nt8W4uEHA.1308@TK2MSFTNGP09.phx.gbl... 
> Filter 
>
>



Report this thread to moderator Post Follow-up to this message
Old Post
Mike
10-29-04 01:55 AM


Sponsored Links




Last Thread Next Thread Next
Search this forum -> 
Post New Thread

ASP archive

Show a Printable Version Send to friend Email This Page to Someone! subscribe to this thread Receive updates to this thread
Computer Consultants
Programming Jobs
Visual Basic Controls
SQL Server Programming
Webservices
Java Security
Visual Studio
C# Programming
Visual J++
Software engineering
Open source Software
Perl Programming
PHP Programming
ASP Programming
ASP .NET Programming
Visual Basic Programming
Windows Scripting Host
Java Programming
Java Help
Java Beans
VBScript
Cobol
MAC Applications
Unix Programming
Forum Jump:
All times are GMT. The time now is 04:59 AM.

 
Free MCSE Braindumps | Real Estate Topics

Programming forum archive

Copyrights CodeComments.com 2004 - 2006

Powered by vBulletin Copyright 2000-2006 Jelsoft Enterprises Limited.