Library code snippets

Limit the HTTP request buffer

Not long ago, it was discovered that some Web sites are vulnerable 
to a kind of attack in which executable code is sent to the Web page 
through the HTTP request buffer. In response to this threat, 
Microsoft introduced a new IIS registry key, MaxClientRequestBuffer. 
In IIS4, the default maximum size of the request buffer is 2MB, while 
in IIS5, it has shrunk to 128KB. If you wish to increase (not 
recommended) or decrease the size of the buffer, simply navigate to 
the following registry key:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\w3svc\parameters

Then edit the MaxClientRequestBuffer key. If this key doesn't exist, 
add it, and set its data type to REG_DWORD. Then, in the DWORD Editor, 
select Decimal under Radix, and then enter the number of bytes for 
the buffer.

Comments

  1. 01 Jan 1999 at 00:00

    This thread is for discussions of Limit the HTTP request buffer.

Leave a comment

Sign in or Join us (it's free).

AddThis

Related discussion

Related podcasts

  • ASP.NET Caching and Performance

    Steve Smith, owner of ASP Alliance and Lake Quincy Media joins us today to teach us about some hidden gems in ASP.NET caching and performance. Steve’s expertise in this area comes from first-hand experience as Lake Quincy’s ad system serves over 60 requests per second and handles over 150 million...

Related jobs