pf » Howto Disable the Server Header in IIS

Howto Disable the Server Header in IIS

web

Steven Erat just pointed me to a technote from Macromedia Adobe called: Configuring ColdFusion MX 7 Server Security in the comments of my securing apache config article. In the technote I found that you can disable the Server header on IIS by setting the HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\DisableServerHeader registry entry to 1.

Why is this a good idea? It makes you less of a target for attackers who scan IP ranges for particular servers. It won't actually make your server any more secure.



Related Entries
10 people found this page useful, what do you think?

Trackback Address: 506/68312FF34C26A2F02EB44BAACC58E5BA
On 12/06/2005 at 1:09:20 PM MST Pete Freitag wrote:
1
I should point out that this method only works on IIS6+ Windows 2003 I believe.

On 04/20/2006 at 2:02:45 PM MDT Chris @ Port80 wrote:
2
ServerMask for IIS takes this concept a bit further for full IIS security masking:

http://www.servermask.com

On 11/09/2006 at 4:52:42 AM MST Matt wrote:
3
This hasn't worked for me on Server 2003 R2 / IIS 6.0.

On 02/26/2008 at 4:35:08 AM MST Seb wrote:
4
Doesnt work on my Web edition Windows Server 2003. Anyone have a solution for this OS?




  



Spell Checker by Foundeo





Subscribe to my RSS Feed: solosub RSS
Tags