Solved

IIS and server banner info

Posted on 2013-12-10
3
308 Views
Last Modified: 2014-01-21
How do you disable the server type banner on an http request?  Right now ours is publsihing server:  MicrosoftIIS/7.5.  If it can be disabled, can it be disabled without messing up exchange?
0
Comment
Question by:bnussbaum
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39709292
Why do you want to do that? You don't get security by obscurity.
If you are running Exchange on the server then it will take an attacker about 5 seconds to realise what server you are running.

Simon.
0
 

Author Comment

by:bnussbaum
ID: 39709393
We hire a 3rd party audit comany to audit our systems, and they have flagged this as a medium vulnerability.  They said to use urlscan tool to obscure the header info, but it appears that with IIS 8, that tool can't be used.  I was hoping there was an easy way to just disable it.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 500 total points
ID: 39709654
Third party audit companies working to a predefined scripts are nothing but a pain in...

The fact that they have said to use URLSCAN means that
a. They are using old information
b. They have no clue what they are on about, because as you said URLSCAN cannot be used with the later versions of Windows.

Medium Vulnerability. That is a joke.

I do a lot of high risk deployments with high risk financial services clients, this has never been requested. As I already said, hiding something doesn't provide any additional security and in most cases just breaks functionality.

Simon.
0

Featured Post

Is Your AD Toolbox Looking More Like a Toybox?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Bing Maps Add-in in Exchange 2016 1 77
Services disabled 1 28
Can you repair a Windows 2012 R2 HyperV installation 13 49
Powershell - getting input from CSV File 9 21
This article lists the top 5 free OST to PST Converter Tools. These tools save a lot of time for users when they want to convert OST to PST after their exchange server is no longer available or some other critical issue with exchange server or impor…
This article explains how to install and use the NTBackup utility that comes with Windows Server.
In this Micro Tutorial viewers will learn how they can get their files copied out from their unbootable system without need to use recovery services. As an example non-bootable Windows 2012R2 installation is used which has boot problems.
This video demonstrates how to sync Microsoft Exchange Public Folders with smartphones using CodeTwo Exchange Sync and Exchange ActiveSync. To learn more about CodeTwo Exchange Sync and download the free trial, go to: http://www.codetwo.com/excha…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question