Solved

The server allows capture of the HTTP service banner. Service banners can contain sensitive information, such as application and Operating System (OS) version numbers. An attacker can use the version

Posted on 2009-03-29
8
370 Views
Last Modified: 2012-05-06
The server allows capture of the HTTP service banner. Service banners can contain sensitive information, such as application and Operating System (OS) version numbers. An attacker can use the version information from your Web server to determine if there are any known vulnerabilities present, or can use such information to create attacks towards the specific application or OS.
0
Comment
Question by:Brijeshk9
  • 5
  • 3
8 Comments
 
LVL 15

Expert Comment

by:Tray896
ID: 24019996
The easiest and most common way of removing the server header info is by using URLScan.  You can download and find step by step instructions for configuring it here: http://learn.iis.net/page.aspx/473/using-urlscan
0
 

Author Comment

by:Brijeshk9
ID: 24025006
should i run it from the server where the website is hosted and what will be the next step on it.
0
 

Author Comment

by:Brijeshk9
ID: 24025518
any other solution...?
0
U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

 
LVL 15

Expert Comment

by:Tray896
ID: 24028636
Yes, you configure URLScan on the web server.  I would highly recommend you use it, as it is free and widely used so you can find plenty of documentation on it.  Another option is Server Mask, which is a product from Port80Software.  You can download a free 30 day trial here: http://www.port80software.com/products/servermask/

0
 

Author Comment

by:Brijeshk9
ID: 24029642
will there be any impect of it on my Productioin Server...! like performance or any kind of backup required...!
0
 
LVL 15

Expert Comment

by:Tray896
ID: 24030127
No, there should not be a performance impact to your server.  The configuration is all text based.
0
 

Author Comment

by:Brijeshk9
ID: 24084010
I have installed url scan 2.5 on windows 2000 server what to do next.....because there is one .ini file and another is .dll: where i need to make changes to remove these type of Vulnerabilities.?
0
 

Accepted Solution

by:
Brijeshk9 earned 0 total points
ID: 24428682
Ok , i have done the required changes with URL scan and problem is resolved now.
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Exchange 2013 Activesync connectivity issue 4 67
IIS Question 8 61
Editing XSL files, 2 49
slow IIS responses after Microsoft December 2016 patches 3 34
What is an ISAPI filter?   •      It's an assembly (.dll file) that can add or change the way IIS works.   •      They can be enabled globally for your web server or on a site-by-site basis.   When the IIS server receives a request, enabling the ISAPI fi…
If you don't have the right permissions set for your WordPress location in IIS, you won't be able to perform automatic updates. Here's how to fix the problem.
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now