Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!
all groups > inetserver iis > september 2007 >

inetserver iis : Server Variables


Pirooz Javan
9/21/2007 8:09:54 PM
I'm at an agency that is not permitted to let the internal IPs of the
web servers get out. Since we support
many different applications, its difficult to filter all the content
being uploaded to the web servers (500+ apps).

How can i block or set the return value to an empty string for a
server variable such as LOCAL_ADDR

PJ
David Wang
9/21/2007 10:50:49 PM
[quoted text, click to view]



What you want to do is impossible. There is no access control model
for server variables. Besides, it is not possible for the server to
filter its applications to prevent leakage of internal IP. The
security policy of this agency needs to be revised because it is not
enforceable.


//David
http://w3-4u.blogspot.com
http://blogs.msdn.com/David.Wang
//
AddThis Social Bookmark Button