Psst! Did you know DevelopmentNow is a mobile web site design agency?

Contact us for help mobilizing your site, or to sign up for our beta Mobile Web SDK!
all groups > iis security > march 2006 >

iis security : IIS Version and Interanl IP being Revealed


DoktorWho
3/28/2006 11:20:02 AM
During a recent security scan of our IIS 6 box, it was shown that the II
Version, 6 in this case, and the Internal IP address of the box were being
shown externally.

Why would this be and how can I fix this.

DoktorWho
3/29/2006 8:39:01 AM
Thanks I will try that.

[quoted text, click to view]
Funkadyleik Spynwhanker
3/29/2006 8:51:35 AM

[quoted text, click to view]

For IIS 5, you could control the version via URLscan. So maybe take a look
in whatever that interface was migrated to with version 6.

David Wang [Msft]
3/29/2006 1:41:31 PM
http://blogs.msdn.com/david.wang/archive/2006/03/29/Silly_Security_Scans.aspx

--
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//

[quoted text, click to view]

David Wang [Msft]
3/29/2006 7:13:37 PM
http://blogs.msdn.com/david.wang/archive/2006/03/29/Silly_Security_Scans.aspx

There is no way to control the Server: header. URLScan makes a reasonable
attempt but will not set/remove it in all cases. And we are fine with that
because this is not a security issue, per the rationale from the blog entry.

--
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//

[quoted text, click to view]

Funkadyleik Spynwhanker
3/30/2006 10:01:11 AM
Hey, that's a great rant.

Going in my bookmarks.

[quoted text, click to view]

AddThis Social Bookmark Button