Re: IIS Version and Interanl IP being Revealed



http://blogs.msdn.com/david.wang/archive/2006/03/29/Silly_Security_Scans.aspx

There is no way to control the Server: header. URLScan makes a reasonable
attempt but will not set/remove it in all cases. And we are fine with that
because this is not a security issue, per the rationale from the blog entry.

--
//David
IIS
http://blogs.msdn.com/David.Wang
This posting is provided "AS IS" with no warranties, and confers no rights.
//

"DoktorWho" <DoktorWho@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:9780DC83-3923-4385-93A5-AD81B0AFEF36@xxxxxxxxxxxxxxxx
Thanks I will try that.

"Funkadyleik Spynwhanker" wrote:


"DoktorWho" <DoktorWho@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DD36D2B3-9ECB-41A1-90EA-8644A6377093@xxxxxxxxxxxxxxxx
During a recent security scan of our IIS 6 box, it was shown that the
II
Version, 6 in this case, and the Internal IP address of the box were
being
shown externally.

Why would this be and how can I fix this.

The box is natted behind a firewall.

For IIS 5, you could control the version via URLscan. So maybe take a
look
in whatever that interface was migrated to with version 6.





.



Relevant Pages

  • Re: Combobox Display Problem
    ... Header section of the Sub-form, and it was invisible when run as I mentioned. ... ' Find the record that matches the control. ... Header section of the form (subform), ... The Control Source for cboItem on fsubGroup is chrItem, ...
    (microsoft.public.access.forms)
  • Re: ToolTipText and the ListView control in VB6
    ... control setup. ... '* Description: Process MouseMove event. ... If .ToolTipText objListItem.Key Then ... '' the mouse must be in the header area. ...
    (microsoft.public.vb.controls)
  • RE: Filter records based on user input
    ... No, I did not put it in the header, I just uses an unbound text box in the ... I thought that the bookmark line would set the focus to the control in the ... which would filter your form based on the text in the textbox. ... It should filter the records as the user types the number. ...
    (microsoft.public.access.formscoding)
  • Re: Another GridView Bug -> PagerSettings.Visible
    ... GridView control is based on templates ... stage is the only time you can build the control structure. ... set to true and capture the pager row ... note that the header should be enabled when the pager is visible and ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Blank Lines in report
    ... Asset Finance Fraud Forum ... The header finishes after "Distributed to Group List" ... > Duane Hookom ... >> I have a report that has a header for one control and the detail showing ...
    (microsoft.public.access.reports)