Solution to malicious download of Access Database

Source: Internet
Author: User
Tags mdb database
There are many methods to prevent mdb from being downloaded, such as some weird names, odbc data sources, and extensions. This article may not be of great use to you, but it can still help beginners learn something, such as some mechanisms of iis! There is a home directory label in the properties of the iis Site, and there is an application in it

There are many methods to prevent mdb from being downloaded, such as some weird names, odbc data sources, and extensions. This article may not be of great use to you, but it can still help beginners learn something, such as some mechanisms of iis! There is a home directory label in the properties of the iis Site, and there is an application in it

There are many methods to prevent mdb from being downloaded, such as some weird names, odbc data sources, and extensions. This article may not be of great use to you, but it can still help beginners learn something, such as some mechanisms of iis!

There is a "main directory" label in the properties of the iis Site, which has a "configuration" for "application settings", mainly used to configure the processing engine of files with a different Suffix in the iis server, example :. the ASP file processing engine is: C: WINNTSystem32inetsrvASP. dll. When the client requests ASP files from the iis server, the iis server uses C: WINNTSystem32inetsrvASP. dll to process the request. ASP file. Those familiar with idq and ida vulnerabilities should be very familiar with it.

Go to the topic: How to Prevent mdb from being downloaded? If the path of the mdb database is obtained, you can easily enter the location of the mdb database in the address bar of the browser to download the mdb, because the iis does not set how to process the mdb file requested by the user, the mdb database is downloaded, So we add an engine for processing the mdb suffix file.

Go to "configuration" of "application settings" and "add" the executable file: C: WINNTSystem32inetsrvASP. dll (using the ASP processing engine, other can also be), extension :. mdb, Action: all actions, single-Choice "check whether the file exists ".

Okay, it's done. Try entering the address of the mdb database in your ie Address Bar and try netant for "cannot be displayed ~ The principle is that when the client submits a. mdb file to iis, iis forwards it to the ASP processing engine for Processing Based on the settings, and the results cannot be displayed!

Note: The database is still in normal use in ASP programs!

Juven notes: these are all set by the server administrator, so we also hope that the service provider can set them in the iis of the server for your security considerations.

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.