Skip to main content

URLScan Error: The Web Server Has Been Locked Down and Is Blocking the DEBUG Verb

Today I installed URLScan 2.5 and experienced following error: “The Web Server Has Been Locked Down and Is Blocking the DEBUG Verb” while I tried to debug my project. I tried several thing apart from restarting my IIS, but nothing worked !

" UrlScan version 2.5 is a security tool that restricts the types of HTTP requests that Internet Information Services (IIS) will process. By blocking specific HTTP requests, the UrlScan security tool helps prevent potentially harmful requests from reaching the server. UrlScan 2.5 will now install as a clean installation on servers running IIS 4.0 and later."

Then I tried developers' best friend yes, Google! , and I got the solution from microsoft site.



--------------------------------------------------------------------------------
To enable debugging on a Web server with URLScan installed

1.Locate the Urlscan.ini file. Normally, you will find it in a directory that looks something like this:
%windir%\System32\Inetsrv\urlscan2.Create a copy of the file and name it Urlscan.old.
3.Open the original copy of the Urlscan.ini file using Notepad or the text editor of your choice.
4.In Urlscan.ini, locate the [AllowVerbs] section. Add DEBUG to the [AllowVerbs] section. If you see ;DEBUG in the [AllowVerbs] section, you can remove the semicolon (which comments out the verb).
5.Locate the [DenyVerbs] section. If DEBUG appears in the [DenyVerbs] section, remove it.
6.Save the file.
7.Restart the server or restart IIS.

Source:
http://geekswithblogs.net/ram/archive/2006/02/28/70937.aspx
http://msdn.microsoft.com/en-us/library/6ax8x46y(VS.71).aspx
http://technet.microsoft.com/en-us/security/cc242650.aspx

Comments

Popular posts from this blog

IUSR vs IUSR_MachineName vs IIS_WPG

ni satu lagi hal yang memeningkan aku 2 3 hari. apalah IIS ni, len kali habaq la hangpa dah tukar pasal IIS_IUSR. jenuh aku mencari solution sebab2 application tak mo jalan. apa raa. secara ringkasnya IIS kata: In earlier versions of IIS, a local account called IUSR_MachineName is created during installation. IIS used the IUSR_MachineName account by default whenever anonymous authentication was enabled. This was used by both the FTP and HTTP services. lepas tu dia kata lagi: In summary, IIS 7 and above offer the following: The IUSR built-in account replaces the IUSR_MachineName account. The IIS_IUSRS built-in group replaces the IIS_WPG group. alhamdulillah boleh jalan :D source: https://www.iis.net/learn/get-started/planning-for-security/understanding-built-in-user-and-group-accounts-in-iis

MYSQL TO MSSQL

Aduss berpeluh2 hampir 3 minggu cari solution utk convert db mysql to mssql. mula2 aku pakai phpmyadmin untuk generate sqldump. then aku terai import masuk ke mssql gunakan new query. rupa2nya phpmyadmin ni pon bengong. dia tak create ikut mssql punya format syntac, dia generate ikut kepala dia saja walaupun aku dah klik checkbox pada OPTION MSSQL format. patut le mssql tak mau terima, even barus yg paling mudah skali iaitu komen pon phpmyadmin tak tukar!!! ade ke format komen mssql si phpmyadmin masih pakai "--" (dash dash). mssql pakai syntax "/*" utk buka blok komen dan "*/" utk tutup blok komen. adusss.  banyak plak tu dalam sqldump aku nak kena tukar.. lemau aku. 160MB punya textfile. gilo apo nak ubah satu persatu baris.. berjuta baris woo.. 8 tahun pon tak siap nak ubah. tapi ada satu software boleh buat semua tu secara auto. SQL2MSS. aku cuma pakai demo set je. dia boleh sedut semua structure, tapi rekod cuma dapat 5 per table. jadi la 5 re...

Internet Hotspot dah "Licin", Tiba2 boleh "Hidup" kembali.

 Aduhai, lama tak bersembang2 ye. Aku termenung bila hotspot 12GB Yes 5G aku abes. Rasa quota aku disedut laju je. Tiba2 aku cari solution dalam Google, terjumpa seorang brader kongsikan cara2 nak bypass hotspot yang mana pakai pc/laptop dan hotspot melalui fon lah. Kalau lain dari cara sambungan tu, jangan ditanya ler, aku pun tak tau. ni aku sharekan juga petua dari dia. Hangpa semua boleh je baca kat web blog dia. Give a credit to him. taip di command promt (administrator level) seperti dibawah. satu persatu, tekan enter. netsh int ipv4 set glob defaultcurhoplimit=65 netsh int ipv6 set glob defaultcurhoplimit=65 lepas dah taip 2 baris tu. try ler ping mana2 url yang korang tau. ada respon? atau buka browser. Aku berjaya dan menjadi, sebab tu aku tulis dan korang boleh baca artikel ni. hahaha. Selamat mencuba ye. berapa lama dapat bertahan? entah la bos! Sumber:    Cara Buat Unlimited Data Hotspot Pada Semua Telco Secara Percuma (blogfaiz.com)