Register   Login
     
  Latest Posts  
RE: Ligtbox effect does not working in DNN 5
by smcculloch on 1/09/2009 9:49 AM
RE: Embed the coolest google local search map control
by aviavia on 1/09/2009 8:06 AM
RE: Embed the coolest google local search map control
by odove on 1/09/2009 6:43 AM
RE: Ligtbox effect does not working in DNN 5
by David Eccles on 1/09/2009 6:11 AM
Changing The Home Directory.
by rtnovak on 1/09/2009 1:03 AM
RE: Updating Simple Gallery
by rtnovak on 1/09/2009 12:54 AM
RE: Select Image Button does not work.
by rtnovak on 1/09/2009 12:53 AM
Updating Simple Gallery
by rtnovak on 1/08/2009 9:59 PM
Has pay-per-ad. been added yet?
by wpmilk on 1/08/2009 7:13 PM
Has pay-per-ad. been added yet?
by wpmilk on 1/08/2009 7:13 PM
  Forums  
Subject: Cannot use a leading .. to exit above the top directory
Prev Next
You are not authorized to post a reply.

Author Messages
BarrySUser is Offline
Gold Membership
Nuke Wiz
Nuke Wiz
Posts:138


10/05/2006 3:03 PM  

Hi Scott,

I've just seen one of these errors, it has only happened once that I can see.  Is there any other info that might help debug? Or is it user error?

 


 

AssemblyVersion: 04.03.05
PortalID: -1
PortalName:
UserID: -1
UserName:
ActiveTabID: -1
ActiveTabName:
RawURL: /Default.aspx?tabid=36&error=Cannot+use+a+leading+..+to+exit+above+the+top+directory.&content=0
AbsoluteURL: /Default.aspx
AbsoluteURLReferrer:
UserAgent: Mozilla/5.0 (compatible; Yahoo! Slurp; http://help.yahoo.com/help/us/ysearch/slurp)
DefaultDataProvider: DotNetNuke.Data.SqlDataProvider, DotNetNuke.SqlDataProvider
ExceptionGUID: bfcfffa9-302e-4bfb-84a1-b8a52f658396
InnerException: Unhandled Error:
FileName:
FileLineNumber: 0
FileColumnNumber: 0
Method: DotNetNuke.HttpModules.UrlRewriteModule.SecurityCheck
StackTrace:
Message: System.Exception: Unhandled Error: ---> System.Web.HttpException: Not Found at DotNetNuke.HttpModules.UrlRewriteModule.SecurityCheck(HttpApplication app) at DotNetNuke.HttpModules.UrlRewriteModule.OnBeginRequest(Object s, EventArgs e) at System.Web.HttpApplication.SyncEventExecutionStep.System.Web.HttpApplication.IExecutionStep.Execute() at System.Web.HttpApplication.ExecuteStep(IExecutionStep step, Boolean& completedSynchronously) --- End of inner exception stack trace ---
Source:
Server Name: INETC528


 

Scott McCullochUser is Offline
Administrators
Nuke Master
Nuke Master
Posts:12820


10/05/2006 5:03 PM  
With the core and the provider on this site, one of the security checks is to check for the "../" sequence, if it is found, throw an exception.

There must be a bad link somewhere on your site that does this.

Scott McCulloch
Site Administrator
Mariette KnapUser is Offline
Registered Users
Nuke Master
Nuke Master
Posts:650


10/05/2006 11:54 PM  

Check you web.config for:

<authentication mode="Forms">

<forms name=".SMALLBIZ" protection="All" timeout="7200" cookieless="UseCookies" slidingExpiration="true" />

authentication>

make sure it has set cookieless="UseCookies"



Subscribe for great articles and howtos. Get unlimited access to all content.
Mariëtte Knap
www.smallbizserver.net
You are not authorized to post a reply.
Forums > Projects > Friendly Urls > Cannot use a leading .. to exit above the top directory



ActiveForums 3.7