Skip to main content

URLScan Error: The Web Server Has Been Locked Down and Is Blocking the DEBUG Verb

Today I installed URLScan 2.5 and experienced following error: “The Web Server Has Been Locked Down and Is Blocking the DEBUG Verb” while I tried to debug my project. I tried several thing apart from restarting my IIS, but nothing worked !

" UrlScan version 2.5 is a security tool that restricts the types of HTTP requests that Internet Information Services (IIS) will process. By blocking specific HTTP requests, the UrlScan security tool helps prevent potentially harmful requests from reaching the server. UrlScan 2.5 will now install as a clean installation on servers running IIS 4.0 and later."

Then I tried developers' best friend yes, Google! , and I got the solution from microsoft site.



--------------------------------------------------------------------------------
To enable debugging on a Web server with URLScan installed

1.Locate the Urlscan.ini file. Normally, you will find it in a directory that looks something like this:
%windir%\System32\Inetsrv\urlscan2.Create a copy of the file and name it Urlscan.old.
3.Open the original copy of the Urlscan.ini file using Notepad or the text editor of your choice.
4.In Urlscan.ini, locate the [AllowVerbs] section. Add DEBUG to the [AllowVerbs] section. If you see ;DEBUG in the [AllowVerbs] section, you can remove the semicolon (which comments out the verb).
5.Locate the [DenyVerbs] section. If DEBUG appears in the [DenyVerbs] section, remove it.
6.Save the file.
7.Restart the server or restart IIS.

Source:
http://geekswithblogs.net/ram/archive/2006/02/28/70937.aspx
http://msdn.microsoft.com/en-us/library/6ax8x46y(VS.71).aspx
http://technet.microsoft.com/en-us/security/cc242650.aspx

Comments

Popular posts from this blog

IUSR vs IUSR_MachineName vs IIS_WPG

ni satu lagi hal yang memeningkan aku 2 3 hari. apalah IIS ni, len kali habaq la hangpa dah tukar pasal IIS_IUSR. jenuh aku mencari solution sebab2 application tak mo jalan. apa raa. secara ringkasnya IIS kata: In earlier versions of IIS, a local account called IUSR_MachineName is created during installation. IIS used the IUSR_MachineName account by default whenever anonymous authentication was enabled. This was used by both the FTP and HTTP services. lepas tu dia kata lagi: In summary, IIS 7 and above offer the following: The IUSR built-in account replaces the IUSR_MachineName account. The IIS_IUSRS built-in group replaces the IIS_WPG group. alhamdulillah boleh jalan :D source: https://www.iis.net/learn/get-started/planning-for-security/understanding-built-in-user-and-group-accounts-in-iis

SSD Microsoft Surface buat hal

 Bagi korang yang pakai MS Surface, hmmm ssd kalau dah mula menunjukkan "cannot boot", keluar blue screen yang dia cakap cari SSD tak jumpa buat pertama kali, hangpa kena beringat, Surface dah kasi warning pertama supaya cepat2 backup fail dalam SSD tu bila hangpa dapat access masuk semula. Kadang2 dapat masuk 30 minit je ke Windows. cepat2 keluarkan fail yang penting. kalau tak.. hmm SDD tu kaput. backup lah segera dan selalu, jangan jadi macam aku. fail tak boleh recover.. naya woo

MYSQL TO MSSQL

Aduss berpeluh2 hampir 3 minggu cari solution utk convert db mysql to mssql. mula2 aku pakai phpmyadmin untuk generate sqldump. then aku terai import masuk ke mssql gunakan new query. rupa2nya phpmyadmin ni pon bengong. dia tak create ikut mssql punya format syntac, dia generate ikut kepala dia saja walaupun aku dah klik checkbox pada OPTION MSSQL format. patut le mssql tak mau terima, even barus yg paling mudah skali iaitu komen pon phpmyadmin tak tukar!!! ade ke format komen mssql si phpmyadmin masih pakai "--" (dash dash). mssql pakai syntax "/*" utk buka blok komen dan "*/" utk tutup blok komen. adusss.  banyak plak tu dalam sqldump aku nak kena tukar.. lemau aku. 160MB punya textfile. gilo apo nak ubah satu persatu baris.. berjuta baris woo.. 8 tahun pon tak siap nak ubah. tapi ada satu software boleh buat semua tu secara auto. SQL2MSS. aku cuma pakai demo set je. dia boleh sedut semua structure, tapi rekod cuma dapat 5 per table. jadi la 5 re...