[TOOL] IISBanner, IIS Banner Changer
From: SecuriTeam (support_at_securiteam.com)
To: firstname.lastname@example.org Date: 19 Jun 2003 14:35:03 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
Latest attack techniques.
You're a pen tester, but is google.com still your R&D team?
Now you can get trustworthy commercial-grade exploits and the latest
techniques from a world-class research group.
Learn more at http://www.coresecurity.com/promos/sit_e1,
or call 617-399-6980
- - - - - - - - -
IISBanner, IIS Banner Changer
ISAPI Filters are the only "safe" way of managing (changing, altering,
customizing) some of the core parts of IIS. Customizing the response
header "Server" is one of those tasks. IISBanner provides a simple yet
powerful, although demonstrative, way of achieving such objective.
IISBanner may be useful at a security perspective by disguising the web
server banner (security by obscurity), but keep in mind that there are
much more powerful ways of detecting a server type using tools like NMap.
* Changes IIS "Server" response header value to "Powered By IISBanner/1.0
* Installation of this ISAPI Filter must be done at the WebServer level;
* Although the Response Value could be set in a file (ex: ini), the
author decided to "hard code" it to make it simple to understand the
* IISBanner is installed at http://www.kodeit.com and may be viewed by a
network sniffer at each HTTP response received, or through this simple VBS
Set oHTTP = WScript.CreateObject("Microsoft.XMLHTTP")
Call oHTTP.Open("HEAD", "http://www.kodeit.com", False)
Set oHTTP = Nothing
The tool can be downloaded from:
The information has been provided by <mailto:email@example.com> Tiago
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: firstname.lastname@example.org
In order to subscribe to the mailing list, simply forward this email to: email@example.com
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.