How to deny URL sequence from IIS?

Request Filtering is a built-in security feature of IIS. Using Request Filtering feature one can assign maximum URL length, Query String size, content request length and many other restrictions server wide as well as website wide. Deny URL Sequences element of Request Filtering helps to deny access for URL sequence patterns that an attacker might try to exploit. Follow these steps to deny URL sequence from IIS.

  1. Login to your VPS.

  2. Open IIS Manager. Unde Connections pane, click on VPS Name.

    IIS Manager

  3. Open Request Filtering as shown in below image.

    Click on Request Filtering Option

  4. Move to URL tab and click on Deny Sequence.

    Click on Deny Sequence Link

  5. An Add Deny Sequence dialog box will appear, enter the URL sequence which you wish to block. For Example, if you wish to block the common SQL Injection term 'varchar', enter 'varchar' character sequence in the Deny Sequence box. When you wish to block entire directory access, give '..' as shown in below image.

    Add URL Sequence

  6. Click OK. Now, when anyone tries to enter any of the mentioned terms into your URL Sequence, they will receive the HTTP Error 404.5 – URL Sequence denied error message.
 
NOTE: Choose your character sequence wisely. If your site uses any of the terms that you deny, your site visitor will receive the HTTP Error 404.5.

  • 29 Users Found This Useful

Was this answer helpful?

Related Articles

How to set periodic recycling for application pool in IIS 7?

Following are the steps to set periodic recycling for the application pool in IIS 7: Login to...

Fix :: Operation must use an updateable query." for ASP pages

Problem Statement Operation must use an updateable query." for ASP pages Cause There might be...

Fix :: ASP Session Times Out Before Session Timeout Value in IIS

Problem Statement Session times out before session timeout valueIn many case wherein,...

How to Fix HTTP Error 500 (or 500.21) - Internal Server Error Handler SSINC-shtml?

Error Message HTTP Error 500 (or 500.21) - Internal Server Error Handler SSINC-shtm' handler...

How to create a certificate signing request [CSR] from IIS 7.5 in your VPS?

Follow the below mentioned steps to create Certificate signing request from IIS 7.5 in your VPS:...