Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

IIS and server banner info

Posted on 2013-12-10
3
Medium Priority
?
315 Views
Last Modified: 2014-01-21
How do you disable the server type banner on an http request?  Right now ours is publsihing server:  MicrosoftIIS/7.5.  If it can be disabled, can it be disabled without messing up exchange?
0
Comment
Question by:bnussbaum
  • 2
3 Comments
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 39709292
Why do you want to do that? You don't get security by obscurity.
If you are running Exchange on the server then it will take an attacker about 5 seconds to realise what server you are running.

Simon.
0
 

Author Comment

by:bnussbaum
ID: 39709393
We hire a 3rd party audit comany to audit our systems, and they have flagged this as a medium vulnerability.  They said to use urlscan tool to obscure the header info, but it appears that with IIS 8, that tool can't be used.  I was hoping there was an easy way to just disable it.
0
 
LVL 63

Accepted Solution

by:
Simon Butler (Sembee) earned 1500 total points
ID: 39709654
Third party audit companies working to a predefined scripts are nothing but a pain in...

The fact that they have said to use URLSCAN means that
a. They are using old information
b. They have no clue what they are on about, because as you said URLSCAN cannot be used with the later versions of Windows.

Medium Vulnerability. That is a joke.

I do a lot of high risk deployments with high risk financial services clients, this has never been requested. As I already said, hiding something doesn't provide any additional security and in most cases just breaks functionality.

Simon.
0

Featured Post

Keep up with what's happening at Experts Exchange!

Sign up to receive Decoded, a new monthly digest with product updates, feature release info, continuing education opportunities, and more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

As much as Microsoft wants to kill off PST file support, just as they tried to do with public folders, there are still times when it is useful or downright necessary to export Exchange mailboxes to PST files. Thankfully, it is still possible to e…
Steps to fix error: “Couldn’t mount the database that you specified. Specified database: HU-DB; Error code: An Active Manager operation fail”
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
how to add IIS SMTP to handle application/Scanner relays into office 365.
Suggested Courses

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question