Web Server PROPFIND Method Internal IP Disclosure

The remote installation of IIS leaks a private IP address through the
WebDAV interface. This may expose internal IP addresses that are
usually hidden or masked behind a Network Address Translation (NAT)
Firewall or proxy server.
This is typical of IIS installations that are not configured properly
please suggest to resolve this risk.
Yogesh_Exchange_ExpertAsked:
Who is Participating?
 
Tony JConnect With a Mentor Lead Technical ArchitectCommented:
Well I don't know specifically for IIS 7, but earlier versions used to have the following workaround:

adsutil.vbs set w3svc/UseHostName True

Bear in mind though that I've heard reports of it breaking OWA.

0
 
Yogesh_Exchange_ExpertAuthor Commented:
if we disable webdav then it will resolve the issue or not?
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.