Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: Using the ISA Firewall to Block Cross-Site Scripting Attacks

Using the ISA Firewall to Block Cross-Site Scripting Attacks

I’m often asked if the ISA Firewall can help block cross site scripting attacks. Blocking this types of attacks can be challenging, because often when you configure a security device to help protect you against these attacks, you run the risk of blocking accept to legitimate sites. However, with that said, you can use the ISA Firewall to help block cross site scripting attacks and then monitor for the effects your changes have made for legitimate Web site access.

What you need to do is block keywords common used in cross site scripting attacks. You can do this with the HTTP Security Filter included with the ISA Firewall. Examples of the keywords include:

 

ActiveXObject

applet

cookie

CopyFile

copyparentfolder

CreateObject

CreateTextRange

DeleteFile

DriveType

EMBED

FileExist

GetFile

GetFolder

GetParentFolder

GetSpecialFolder

javascript

livescript

mocha

object

OnAbort

OnBlur

OnChange

OnClick

OnDragDrop

OnFocus

OnKeyDown

OnKeyPress

OnKeyUp

OnLoad

OnMouseDown

OnMouseMove

OnMouseOut

OnMouseOver

OnMouseUp

OnMove

OnResize

OnSelect

OnSubmit

OnUnload

OpenAsTextStream

OpenTextFile

RegWrite

Replace

SCRIPT

vbscript

For more information on using the ISA Firewall to block Cross Site Scripting attacks, check out:

http://www.microsoft.com/technet/isa/2006/http_fil...#8230;

 

HTH,

Tom

Thomas W Shinder, M.D.
Site: www.isaserver.org

Blog: http://blogs.isaserver.org/shinder/
Book: http://tinyurl.com/3xqb7

Email: tshinder@isaserver.org

MVP — Microsoft Firewalls (ISA)

One Response to “Using the ISA Firewall to Block Cross-Site Scripting Attacks”

  1. Zohaib Ashraf Says:

    October 13th, 2006 at 7:03 pm

    nothing.

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center