<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: ISA Server error 12217</title>
	<atom:link href="http://www.tomrafteryit.net/isa-server-error-12217/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tomrafteryit.net/isa-server-error-12217/</link>
	<description>Tom Raftery, social media consultant, speaker, blogger and podcaster</description>
	<pubDate>Sat, 06 Sep 2008 22:21:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Baruch</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-115368</link>
		<dc:creator>Baruch</dc:creator>
		<pubDate>Tue, 18 Mar 2008 21:12:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-115368</guid>
		<description>Hey Stuart, 

I am sure you are long past your carriage return problem. However, I have an answer for the next guy that sees your post. After talking to microsoft, they state they intentionally break urls with an encoded CRLF (%0d%0a) to prevent cross site scripting. A work around is to use HTTP authentication (we were using forms auth). We ended up changing our code to use a POST instead of a GET.</description>
		<content:encoded><![CDATA[<p>Hey Stuart, </p>
<p>I am sure you are long past your carriage return problem. However, I have an answer for the next guy that sees your post. After talking to microsoft, they state they intentionally break urls with an encoded CRLF (%0d%0a) to prevent cross site scripting. A work around is to use HTTP authentication (we were using forms auth). We ended up changing our code to use a POST instead of a GET.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-109251</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Thu, 09 Aug 2007 13:35:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-109251</guid>
		<description>Just ran into the exact problem listed for one of our newly published internal pages.  Googled, found your page, fixed problem, partied like a rock star.  Thanks!</description>
		<content:encoded><![CDATA[<p>Just ran into the exact problem listed for one of our newly published internal pages.  Googled, found your page, fixed problem, partied like a rock star.  Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mickel</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-95750</link>
		<dc:creator>Mickel</dc:creator>
		<pubDate>Fri, 19 Jan 2007 17:07:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-95750</guid>
		<description>Thanks a lot for your comment. You saved my day, man!</description>
		<content:encoded><![CDATA[<p>Thanks a lot for your comment. You saved my day, man!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Helder Mansur</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-44532</link>
		<dc:creator>Helder Mansur</dc:creator>
		<pubDate>Thu, 19 Oct 2006 14:18:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-44532</guid>
		<description>I tried it in my isa server, but I can't edit http protocol under general tab. the "filtering" option isn't available for clicking. Any ideas???? isa server is 2004 sp1.</description>
		<content:encoded><![CDATA[<p>I tried it in my isa server, but I can&#8217;t edit http protocol under general tab. the &#8220;filtering&#8221; option isn&#8217;t available for clicking. Any ideas???? isa server is 2004 sp1.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Naveed</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-5950</link>
		<dc:creator>Naveed</dc:creator>
		<pubDate>Fri, 10 Mar 2006 04:43:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-5950</guid>
		<description>yes tom i am confirm.. however i tried to uninstall isa 2004 but it dosent by saying ( failed to unregister vpn ) .. after that it start creating diffrent kinds of problem. so then i again install win 2003 and isa 2004... 

my problem is solved but i again facing problem .. my application event log always gets full with these events 

[The daily summary for day "03/08/2006" was not created.  Use the source location 1001.470.4.0.2161.50 to report the failure.]

plz guide me .. also tell me the best way to uninstall.

Regards</description>
		<content:encoded><![CDATA[<p>yes tom i am confirm.. however i tried to uninstall isa 2004 but it dosent by saying ( failed to unregister vpn ) .. after that it start creating diffrent kinds of problem. so then i again install win 2003 and isa 2004&#8230; </p>
<p>my problem is solved but i again facing problem .. my application event log always gets full with these events </p>
<p>[The daily summary for day "03/08/2006" was not created.  Use the source location 1001.470.4.0.2161.50 to report the failure.]</p>
<p>plz guide me .. also tell me the best way to uninstall.</p>
<p>Regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Raftery</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-5879</link>
		<dc:creator>Tom Raftery</dc:creator>
		<pubDate>Thu, 09 Mar 2006 09:01:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-5879</guid>
		<description>Naveed,

have you confirmed that ISA is causing the problem (i.e. does turning ISA off allow the graphics to display)?</description>
		<content:encoded><![CDATA[<p>Naveed,</p>
<p>have you confirmed that ISA is causing the problem (i.e. does turning ISA off allow the graphics to display)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Naveed</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-5871</link>
		<dc:creator>Naveed</dc:creator>
		<pubDate>Thu, 09 Mar 2006 07:03:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-5871</guid>
		<description>I am facing  problem regarding mail.yahoo.com .. i am running isa 2004 

on workstations mail.yahoo.com dosent display full graphics 

what should i do ?</description>
		<content:encoded><![CDATA[<p>I am facing  problem regarding mail.yahoo.com .. i am running isa 2004 </p>
<p>on workstations mail.yahoo.com dosent display full graphics </p>
<p>what should i do ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Raftery</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-3257</link>
		<dc:creator>Tom Raftery</dc:creator>
		<pubDate>Fri, 23 Dec 2005 16:35:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-3257</guid>
		<description>Stuart,

I'm afraid I'm a bit of an ISA Server novice as well - sorry I can't answer this one for you - if you figured it out, you might leave a comment here so others will find it...

Thanks,

Tom</description>
		<content:encoded><![CDATA[<p>Stuart,</p>
<p>I&#8217;m afraid I&#8217;m a bit of an ISA Server novice as well - sorry I can&#8217;t answer this one for you - if you figured it out, you might leave a comment here so others will find it&#8230;</p>
<p>Thanks,</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stuart Holding</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-2943</link>
		<dc:creator>Stuart Holding</dc:creator>
		<pubDate>Thu, 08 Dec 2005 05:13:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-2943</guid>
		<description>Hi Tom,

I am getting this error on an ASP.NET web site I have hosted in the DMZ behind my ISA Server 2004 Firewall. I have enabled high bit characters on the HTTP filter as you mentioned above but still seem to get the error (on pages where a carriage return character is likely to be appearing. 
Is there any other configuration settings I should be looking for (sorry, but I am a bit of an ISA novice)</description>
		<content:encoded><![CDATA[<p>Hi Tom,</p>
<p>I am getting this error on an ASP.NET web site I have hosted in the DMZ behind my ISA Server 2004 Firewall. I have enabled high bit characters on the HTTP filter as you mentioned above but still seem to get the error (on pages where a carriage return character is likely to be appearing.<br />
Is there any other configuration settings I should be looking for (sorry, but I am a bit of an ISA novice)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Raftery</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-2546</link>
		<dc:creator>Tom Raftery</dc:creator>
		<pubDate>Wed, 16 Nov 2005 15:28:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-2546</guid>
		<description>Great Tyler,

happy I was able to help someone else with this,

Cheers,

Tom</description>
		<content:encoded><![CDATA[<p>Great Tyler,</p>
<p>happy I was able to help someone else with this,</p>
<p>Cheers,</p>
<p>Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-2545</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Wed, 16 Nov 2005 14:58:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-2545</guid>
		<description>Thank you for this... I was running into an error with our client database, which had a lot of French names with Ã´'s and various other accented characters.  

A quick Google search turned up your blog.  Problem solved in under 1 minute.

Cheers!</description>
		<content:encoded><![CDATA[<p>Thank you for this&#8230; I was running into an error with our client database, which had a lot of French names with Ã´&#8217;s and various other accented characters.  </p>
<p>A quick Google search turned up your blog.  Problem solved in under 1 minute.</p>
<p>Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Hanna</title>
		<link>http://www.tomrafteryit.net/isa-server-error-12217/#comment-49</link>
		<dc:creator>Jon Hanna</dc:creator>
		<pubDate>Sun, 07 Nov 2004 14:46:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/views/?p=96#comment-49</guid>
		<description>I've come across a similar thing with the filter Microsoft offer for IIS. I suspect the original intention was to block attacks based on overlong UTF-8 encodings (I say a bit about this issue at http://www.hackcraft.net/xmlUnicode/#sect4220 and the Unicode Standard itself has information on it). However, it's relatively easy to get secure UTF-8 parsing right - and to know you have it right.

There are also phishing opportunities with Internationalised URIs, but only a small subset of these would be prevented by this blocking (though if you let people create their own sections on your site then someone with control of http://example.net/ThisBit could have customers phished from http://example.net/ThisBit where the letter before "hisBit" is actually a Cyrillic letter Te, not the Latin letter "Tee").

Another reason for blocking is that we've only relatively recently had a standard on how to deal with characters in the range U+0080 and higher in URIs (although it's been clear for some time that the standard would use UTF-8 encoding escaped as per the existing URI character escape rules), and there is still some variation in practice and hence scope for difficulties. The ISA Server people may just have considered it best to block those who didn't know what they were doing and force them to stick to the US-ASCII range.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve come across a similar thing with the filter Microsoft offer for IIS. I suspect the original intention was to block attacks based on overlong UTF-8 encodings (I say a bit about this issue at <a href="http://www.hackcraft.net/xmlUnicode/#sect4220">http://www.hackcraft.net/xmlUnicode/#sect4220</a> and the Unicode Standard itself has information on it). However, it&#8217;s relatively easy to get secure UTF-8 parsing right - and to know you have it right.</p>
<p>There are also phishing opportunities with Internationalised URIs, but only a small subset of these would be prevented by this blocking (though if you let people create their own sections on your site then someone with control of <a href="http://example.net/ThisBit">http://example.net/ThisBit</a> could have customers phished from <a href="http://example.net/ThisBit">http://example.net/ThisBit</a> where the letter before &#8220;hisBit&#8221; is actually a Cyrillic letter Te, not the Latin letter &#8220;Tee&#8221;).</p>
<p>Another reason for blocking is that we&#8217;ve only relatively recently had a standard on how to deal with characters in the range U+0080 and higher in URIs (although it&#8217;s been clear for some time that the standard would use UTF-8 encoding escaped as per the existing URI character escape rules), and there is still some variation in practice and hence scope for difficulties. The ISA Server people may just have considered it best to block those who didn&#8217;t know what they were doing and force them to stick to the US-ASCII range.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
