Re: MS IIS Internal IP Address/Hostname Vulnerability

From: Chris Weber [Security MVP] (chris_at_dev.nul)
Date: 06/15/05


Date: Tue, 14 Jun 2005 22:18:17 -0700

That's the thing, it's not really a big deal. Sure it's information
disclosure, but what's in your hostname?

"SteveC" <SteveC@discussions.microsoft.com> wrote in message
news:9358889D-F4E8-4B3C-AF00-CBB1EB0BB1F7@microsoft.com...
> My vulnerability scanner is flagging my OWA website because of the MS IIS
> Internal IP Address/Hostname Vulnerability. I have issued the following
> command "adsutil set w3svc/UseHostName True" and rebooted the server. The
> vulnerability scan no longer picks up the internal IP address. However, it
> picks up the INTERNAL hostname and still flags me for the same
> vulnerability.
> That leaves me in catch22. Set the flag to True and use the internal
> hostname
> or False and display the IP address. Anyone know a fix for this? How can I
> get it to show my EXTERNAL hostname or IP address?
> Thanks
> --
> Steve



Relevant Pages

  • Re: MS IIS Internal IP Address/Hostname Vulnerability
    ... just know that my vulnerability scanner flags me for this. ... but what's in your hostname? ... >> My vulnerability scanner is flagging my OWA website because of the MS IIS ...
    (microsoft.public.inetserver.iis.security)
  • Re: MS IIS Internal IP Address/Hostname Vulnerability
    ... FIX: IP address is revealed in the content-location field in the TCP header ... > My vulnerability scanner is flagging my OWA website because of the MS IIS ... > picks up the INTERNAL hostname and still flags me for the same ...
    (microsoft.public.inetserver.iis.security)
  • cqure.net.20020412.netware_client.a
    ... cqure.net Security Vulnerability Report ... If one would run the command ping with a long hostname an access ... Install patch from Novell as soon as it becomes available. ...
    (Bugtraq)

Quantcast