IIS 10.0 Error 404.11
- A "404.11 Not Found" error indicates that the web server's request filtering module is configured to deny requests containing a double escape sequence.
- The following details provide specific information about the error:
- This security feature is designed to prevent malicious attacks.
HTTP Error 404.11: Request Filtering Blocks Double Escape Sequence
Table of Contents
- HTTP Error 404.11: Request Filtering Blocks Double Escape Sequence
- HTTP Error 404.11: Request Filtering Blocks Double Escape Sequence – A Extensive Guide
- What is HTTP Error 404.11?
- What Causes the 404.11 Error?
- How Does Double Escaping Work and Why Is It Blocked?
- How to Troubleshoot and Fix the 404.11 Error
- Were to Find the `requestFiltering` Setting
- Understanding the Detailed Error Information: Breakdown of Table Data
- Security Considerations and Best Practices
- When is it acceptable to Allow Double Escaping?
- Key Takeaways
- Further Reading & Resources
A “404.11 Not Found” error indicates that the web server’s request filtering module is configured to deny requests containing a double escape sequence.
Possible Causes
- The URL contained a double escape sequence, and the web server’s request filtering is configured to block such sequences.
Troubleshooting Steps
- Verify the
configuration/system.webServer/security/requestFiltering@allowDoubleEscapingsetting in theapplicationhost.configorweb.configfile.
Detailed Error Details
The following details provide specific information about the error:
| Category | Details |
|---|---|
| Module | RequestFilteringModule |
| Notification | BeginRequest |
| Handler | Staticfile |
| Error Code | 0x00000000 |
| Requested URL | (Unavailable) |
| Physical Path | D:inetpubEbsBopotdistiCationImeeogara %20Torre%20Aunziata.htm |
| Logon Method | Not yet resolute |
| Logon user | Not yet determined |
| Request tracing Directory | D:LogFilesFailedReqLogFiles |
Additional Information
This security feature is designed to prevent malicious attacks. Modifying the allowDoubleEscaping setting should only be done with a complete understanding of the potential risks.A network trace is recommended before making changes to confirm the request is not malicious.
If the server is intended to allow double escape sequences, adjust the configuration/system.webServer/security/requestFiltering@allowDoubleEscaping setting accordingly. This error can be triggered by a malformed URL sent by a malicious user.
For more information, visit Microsoft’s documentation.
HTTP Error 404.11: Request Filtering Blocks Double Escape Sequence – A Extensive Guide
What is HTTP Error 404.11?
HTTP Error 404.11, often displayed as “404.11 Not Found,” arises when a web server’s request filtering module prevents access to a requested resource. Specifically, this error indicates that the server has encountered a URL containing a double escape sequence, which the server is configured to block. This is a security measure designed to mitigate potential malicious attacks.
What Causes the 404.11 Error?
The primary cause of the 404.11 error is the presence of a double escape sequence within the requested URL. Double escape sequences can sometimes be used to bypass security measures, so they are often prohibited by default.
How Does Double Escaping Work and Why Is It Blocked?
Double escaping refers to the practice of encoding characters twice in a URL. Such as, a space (” “) might be encoded as “%20” and then further encoded as ”%2520.” Attackers might use this technique to attempt to bypass security rules, gain unauthorized access, or inject malicious code.Web servers, thus, employ request filtering to block requests that utilize double escape sequences to safeguard against these potential exploits.
How to Troubleshoot and Fix the 404.11 Error
If you encounter this error, here’s a step-by-step guide to address it:
- Check the URL: Carefully examine the URL being requested. Look for any instances of double encoding, such as “%2520” or other similar sequences, and correct as necessary.
- Examine the configuration Files: The primary configuration file is typically
web.config(for individual applications) orapplicationhost.config(for the entire server).In these files, you’ll need to locate the request filtering settings. - Locate the `allowDoubleEscaping` setting: within the request filtering section, look for the
allowDoubleEscaping setting. - Modify the
allowDoubleEscapingsetting: This setting controls whether double escape sequences are permitted.- If the setting is set to `true`, double escaping is *allowed*.
- If the setting is set to `false`, which is generally the default, double escaping is *disallowed*.
You can modify the
allowDoubleEscapingsetting to allow or disallow the use of double escaping. Be very cautious and only make this change if absolutely necessary. - Consider the Security Implications: Before changing this setting, understand the security implications. allowing double escaping *potentially* increases the risk of malicious attacks.Ensure you’re aware of the risks before taking such a step. Network tracing, explained below, can also help determine whether they are malicious.
- Test Your Changes: After modifying the configuration, test your website thoroughly to ensure the issue is resolved and no new problems are introduced.
- Further Troubleshooting wiht Network Tracing: If the error persists,or if you suspect the URL itself is malicious,or need more facts,consider initiating a Network Trace (e.g.,using Wireshark). This helps provide a raw view into the requests the server is seeing. Doing so helps to identify the exact characters being sent in the URL.
Were to Find the `requestFiltering` Setting
The location of the `allowDoubleEscaping` setting within the configuration files is usually found in the section related to `system.webServer` and then under `security`. Here’s a general example:
In the above example, the `allowDoubleEscaping` attribute within the `requestLimits` element determines whether double escaping is allowed.
Understanding the Detailed Error Information: Breakdown of Table Data
The error details provide valuable insight into the problem. Here’s a breakdown of the information presented in the table you provided:
| Category | Details |
|---|---|
| Module | RequestFilteringModule – The module responsible for request filtering,including blocking double escape sequences. |
| Notification | BeginRequest - Indicates that the error occurred during the beginning of the request processing. |
| Handler | Staticfile – The handler that was attempting to serve the static file (e.g., an HTML file, an image, etc.). |
| Error code | 0x00000000 – A general success code, even if an error occurs. |
| Requested URL | (Unavailable) - The direct requested URL to your website. |
| physical Path | D:inetpubebsBopotdistiCationImeeogara %20Torre%20Aunziata.htm – Identifies the path of the physical file on the server that was requested.The ‘%20’ represents a space in the filename. |
| Logon Method | Not yet resolute - Indicates the logon method has yet to be implemented. |
| Logon user | Not yet determined – The user is not yet set while beginning the request to the website. |
| Request tracing Directory | D:LogFilesFailedReqLogFiles – The file location of the failing request files, as a more in depth explanation of what has exactly happened. |
Security Considerations and Best Practices
Modifying the `allowDoubleEscaping` configuration setting should be approached with caution. Security is paramount. Here’s what you should keep in mind:
- Risk Assessment: Thoroughly assess the potential risks before changing the setting. Understand the security implications of allowing double escaping in your specific environment.
- Network Tracing: Before modifying any settings,capturing a network trace (using tools like Wireshark) is strongly recommended.A network trace can confirm the *exact* request being sent by the client,which might reveal if there are malicious attempts.
- URL Validation: Implement robust URL validation and sanitization techniques to mitigate the risk of malicious URLs. If your application accepts user-supplied input to generate URLs, always carefully validate and, if necessary, escape input.
- keep Software Updated: Regularly update your web server software (IIS, Apache, etc.) and any related modules to patch security vulnerabilities.
- Web Application Firewall (WAF): Consider using a Web Application Firewall to provide an additional layer of security against web attacks, including those that attempt to exploit double escaping.
When is it acceptable to Allow Double Escaping?
Generally,you should avoid allowing double escaping. Consider reviewing your application’s design to avoid this configuration. This setting should only be changed if you have a *very specific* and *well-understood* reason and if security considerations have been carefully addressed. If you absolutely *must* allow it because of *legacy* application compatibility, perform a thorough risk assessment and ideally restrict this allowance only to the path or virtual directory where required.
Key Takeaways
in summary:
- The 404.11 error indicates request filtering is blocking double escaped characters.
- The error frequently arises due to misconfigured settings or a potentially malicious URL.
- Carefully check
allowDoubleEscapingin your configuration files,understanding the security impacts. - Always conduct security tests and network analysis before changing settings, and utilize an active website firewall.
Further Reading & Resources
For more detailed information, consult the official Microsoft documentation:
