URLScan 3.1 Released
The IIS Team released a new version of the URLScan tool this weekend
to help mitigate against SQL Injection attacks, and a few other
issues. You can see the info and get the download here.
In addition to that, I wanted to point out an important additional page
that gives out info on how to configure the .ini file. That page,
Common URLScan Scenarios, is located here.
The documentation on the download page indicates that you need to
uninstall any previous versions of URLScan, however the FAQ indicates
that if version 3.0 beta is installed the 3.1 version .dll will be
installed, but the .ini file will not be updated. You can get the new
.ini file from here.
Many thanks to the IIS team for the constant series of updates they've been providing.