Re: Web Server Address Diclosure Vulnerability

From: Alessandro Perilli (peris_at_tiscali.it)
Date: 05/22/03


Date: Thu, 22 May 2003 13:03:29 +0200


On Thu, 22 May 2003 01:41:52 -0700, Gary wrote:

> prevent IIS from returning
> a 'Location' response-header containing an internal web
> server IP address

This solution should be what you're looking for:
http://www.securiteam.com/windowsntfocus/5VP021P6KY.html

-- 
Alessandro Perilli
Security Consultant / Trainer
MCT - MCSE 2000 - LINUX+
CCSI - CCSE 2000 - CCSE+ NG
CCNA - CIWP - CIWSA - CCA XP
SECURITY+ 


Relevant Pages

  • Re: What Happening
    ... >I didn't noticed anything strange. ... >Alessandro Perilli ... >Security Consultant / Trainer ...
    (microsoft.public.inetserver.iis.security)
  • Re: Content Advisor: Lost supervisor password
    ... Alessandro Perilli ... Security Consultant / Trainer ... CCSI - CCSE 2000 - CCSE+ NG ...
    (microsoft.public.inetserver.iis.security)
  • Re: Hacker Marketing - Access Denied when I try to delete...
    ... Alessandro Perilli ... Security Consultant / Trainer ... CCSI - CCSE 2000 - CCSE+ NG ...
    (microsoft.public.inetserver.iis.security)
  • Re: Hacking into Firewall
    ... on the market will be ok? ... Alessandro Perilli ... Security Consultant / Trainer ... CCSI - CCSE 2000 - CCSE+ NG ...
    (microsoft.public.inetserver.iis.security)
  • Re: ISS directory .com .exe
    ... > file and called the page from my browser. ... > The server returned the page by displaying the source ... Security Consultant / Trainer ... CCSI - CCSE 2000 - CCSE+ NG ...
    (microsoft.public.inetserver.iis.security)

Loading