<?xml version="1.0"?><?xml-stylesheet type="text/xsl" href="http://www.codeplex.com/rss.xsl"?><rss version="2.0"><channel><title>IisShield - Application Layer Firewall</title><link>http://www.codeplex.com/iisshield/Project/ProjectRss.aspx</link><description>IisShield is an IIS ISAPI Filter preventing any known and unknown attacks from disrupting IIS. The preventive approach of IisShield is an added value preventing IIS from even trying to interpret re...</description><item><title>UPDATED WIKI: Features</title><link>http://www.codeplex.com/iisshield/Wiki/View.aspx?title=Features&amp;version=1</link><description>&lt;div class="wikidoc"&gt;
&lt;h2&gt;
Features
&lt;/h2&gt; &lt;br /&gt;IisShield protects IIS by parsing each http request coming into the web server and inspecting each token of the http protocol against several rules defined in the configuration files. The available rules allow for a deep analysis of the requests at a low level providing a thorough and robust filtering engine.&lt;br /&gt; &lt;br /&gt;IisShield is flexible enough so that rules can be split into zones allowing the filtering process to be applied in a per-zone scope versus a per-server scope. Zones are used to specify which requests are included or excluded requests from the filtering engine. A zone contains the following optional items:&lt;br /&gt; &lt;br /&gt;&lt;ul&gt;
&lt;li&gt;target address&lt;/li&gt;&lt;li&gt;target port&lt;/li&gt;&lt;li&gt;target url&lt;/li&gt;&lt;li&gt;rules file&lt;/li&gt;
&lt;/ul&gt; &lt;br /&gt;A zone can also override the default rules file by specifying a rules file to be applied to all requests part of the zone. For a request t be considered part of a zone, the following steps are taken whenever a request comes into IIS:&lt;br /&gt; &lt;br /&gt;&lt;ul&gt;
&lt;li&gt;If target address is defined, then the target address of the request must match target address&lt;/li&gt;&lt;li&gt;If target port is defined, then the target port of the request must match target port&lt;/li&gt;&lt;li&gt;If target url is defined, then the url of the request must start with target url&lt;/li&gt;
&lt;/ul&gt; &lt;br /&gt;The zone that first matches a request is the chosen zone. Zones are checked in the order they are defined in the configuration file. Zones that do not define target address, target port and target url are ignored.&lt;br /&gt; &lt;br /&gt;&lt;b&gt;Behavior&lt;/b&gt;&lt;br /&gt; &lt;br /&gt;When an http request is blocked by IisShield, the reason is logged into the appropriate rules log file and afterwards there can be 2 outcomes:&lt;br /&gt; &lt;br /&gt;&lt;ul&gt;
&lt;li&gt;If the RejectPage configuration option is defined, the request does not progress further and the RejectPage content is sent back using a 404 http status. &lt;/li&gt;&lt;li&gt;If the RejectPage configuration option is not defined, then IisShield lets the request progress further into IIS. This option is most useful for lab testing.&lt;/li&gt;
&lt;/ul&gt; &lt;br /&gt;In case there is a critical error while filtering the request, IisShield logs the error to the trace file and drops the tcp/ip connection.&lt;br /&gt; &lt;br /&gt;IisShield takes advantage of the features available in IIS 4.0, IIS 5.x and IIS 6.0 to perform the filtering of the requests. In IIS 6.0, both native mode and IIS5 mode are supported.&lt;br /&gt;
&lt;/div&gt;</description><author>thalm</author><pubDate>Mon, 10 Sep 2007 22:06:50 GMT</pubDate><guid isPermaLink="false">UPDATED WIKI: Features 20070910100650P</guid></item><item><title>UPDATED WIKI: Home</title><link>http://www.codeplex.com/iisshield/Wiki/View.aspx?title=Home&amp;version=4</link><description>&lt;div class="wikidoc"&gt;
&lt;b&gt;Project Description&lt;/b&gt;&lt;br /&gt;IisShield is an IIS ISAPI Filter preventing any known and unknown attacks from disrupting IIS. The preventive approach of IisShield is an added value preventing IIS from even trying to interpret requests trying to break-in. With a detailed logging engine, IisShield helps IIS administrators to know in advance and protect IIS from known or unknown HTTP attacks that flow over the Internet.
&lt;br /&gt; &lt;br /&gt;Today's Internet exposure must be protected at all levels and Application Layer Firewalls are an emerging technology providing a needed higher level of protection to Web Servers given the new class of attacks over the HTTP protocol layer.&lt;br /&gt; &lt;br /&gt;The configuration is quite detailed giving the ability to precisely decide over what is accepted and what is not regarding the HTTP Layer. RFC Compliance is just one of the core features of IisShield offering an assurance of quality of service to the IIS Administrator.&lt;br /&gt; &lt;br /&gt;&lt;b&gt;IisShield runs in IIS 4.0, IIS 5.x and IIS 6.0.&lt;/b&gt;&lt;br /&gt; &lt;br /&gt;&lt;b&gt;&lt;a href="http://www.codeplex.com/iisshield/Wiki/View.aspx?title=Features&amp;amp;referringTitle=Home"&gt;More Information&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;/div&gt;</description><author>thalm</author><pubDate>Mon, 10 Sep 2007 22:04:10 GMT</pubDate><guid isPermaLink="false">UPDATED WIKI: Home 20070910100410P</guid></item><item><title>UPDATED WIKI: Home</title><link>http://www.codeplex.com/iisshield/Wiki/View.aspx?title=Home&amp;version=3</link><description>&lt;div class="wikidoc"&gt;
&lt;b&gt;Project Description&lt;/b&gt;&lt;br /&gt;IisShield is an IIS ISAPI Filter preventing any known and unknown attacks from disrupting IIS. The preventive approach of IisShield is an added value preventing IIS from even trying to interpret requests trying to break-in. With a detailed logging engine, IisShield helps IIS administrators to know in advance and protect IIS from known or unknown HTTP attacks that flow over the Internet.
&lt;br /&gt; &lt;br /&gt;Today's Internet exposure must be protected at all levels and Application Layer Firewalls are an emerging technology providing a needed higher level of protection to Web Servers given the new class of attacks over the HTTP protocol layer.&lt;br /&gt; &lt;br /&gt;The configuration is quite detailed giving the ability to precisely decide over what is accepted and what is not regarding the HTTP Layer. RFC Compliance is just one of the core features of IisShield offering an assurance of quality of service to the IIS Administrator.&lt;br /&gt; &lt;br /&gt;&lt;b&gt;IisShield runs in IIS 4.0, IIS 5.x and IIS 6.0.&lt;/b&gt;&lt;br /&gt; &lt;br /&gt;&lt;b&gt;&lt;a href="http://www.kodeit.org/products/iisshield" class="externalLink"&gt;More Information&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;/div&gt;</description><author>thalm</author><pubDate>Mon, 10 Sep 2007 22:00:45 GMT</pubDate><guid isPermaLink="false">UPDATED WIKI: Home 20070910100045P</guid></item><item><title>RELEASED: IisShield 2.2.1 (Sep 10, 2007)</title><link>http://www.codeplex.com/iisshield/Release/ProjectReleases.aspx?ReleaseId=6955</link><description>This release is production ready.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This release includes:&lt;br /&gt;* Binary Installation&lt;br /&gt;* Documentation&lt;br /&gt;</description><author></author><pubDate>Mon, 10 Sep 2007 21:58:42 GMT</pubDate><guid isPermaLink="false">RELEASED: IisShield 2.2.1 (Sep 10, 2007) 20070910095842P</guid></item><item><title>UPDATED RELEASE: IisShield 2.2.1 (Sep 10, 2007)</title><link>http://www.codeplex.com/iisshield/Release/ProjectReleases.aspx?ReleaseId=6955</link><description>This release is production ready.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This release includes:&lt;br /&gt;* Binary Installation&lt;br /&gt;* Documentation&lt;br /&gt;</description><author></author><pubDate>Mon, 10 Sep 2007 21:58:42 GMT</pubDate><guid isPermaLink="false">UPDATED RELEASE: IisShield 2.2.1 (Sep 10, 2007) 20070910095842P</guid></item><item><title>Source code checked in</title><link>http://www.codeplex.com/iisshield/SourceControl/ListDownloadableCommits.aspx</link><description>Source code upload</description><author>thalm</author><pubDate>Mon, 10 Sep 2007 21:50:45 GMT</pubDate><guid isPermaLink="false">Source code checked in 20070910095045P</guid></item><item><title>UPDATED WIKI: Home</title><link>http://www.codeplex.com/iisshield/Wiki/View.aspx?title=Home&amp;version=2</link><description>&lt;div class="wikidoc"&gt;
&lt;b&gt;Project Description&lt;/b&gt;&lt;br /&gt;IisShield is an IIS ISAPI Filter preventing any known and unknown attacks from disrupting IIS. The preventive approach of IisShield is an added value preventing IIS from even trying to interpret requests trying to break-in. With a detailed logging engine, IisShield helps IIS administrators to know in advance and protect IIS from known or unknown HTTP attacks that flow over the Internet.
&lt;br /&gt; &lt;br /&gt;Today's Internet exposure must be protected at all levels and Application Layer Firewalls are an emerging technology providing a needed higher level of protection to Web Servers given the new class of attacks over the HTTP protocol layer.&lt;br /&gt; &lt;br /&gt;The configuration is quite detailed giving the ability to precisely decide over what is accepted and what is not regarding the HTTP Layer. RFC Compliance is just one of the core features of IisShield offering an assurance of quality of service to the IIS Administrator.&lt;br /&gt; &lt;br /&gt;&lt;b&gt;IisShield runs in IIS 4.0, IIS 5.x and IIS 6.0.&lt;/b&gt;&lt;br /&gt; &lt;br /&gt;&lt;b&gt;&lt;a href="http://www.kodeit.org/products/iisshield" class="externalLink"&gt;More Information&lt;span class="externalLinkIcon"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;/div&gt;</description><author>thalm</author><pubDate>Sat, 08 Sep 2007 17:13:24 GMT</pubDate><guid isPermaLink="false">UPDATED WIKI: Home 20070908051324P</guid></item></channel></rss>