Parth, I think you will find that IIS doesn't log the unicode values, as they are translated into plain ascii before being processed (and then logged) The IIS logfile for the /..%c0%af../ original unicode is logged as /../../ I think the same would go for cmd.exe in the log file. Checking for unicode variants would only work if you were performing on the wire monitoring. (Which is ineffective on an SSL site anyway... Blurred _____________________________________________________________________________ http://messenger.yahoo.com.au - Yahoo! Messenger - Voice chat, mail alerts, stock quotes and favourite news and lots more!
This archive was generated by hypermail 2b30 : Mon May 28 2001 - 21:17:32 PDT