First, the name of the vulnerability
Vulnerability Name |
Vulnerability Summary |
Fix suggestions |
Web Server HTTP header information Disclosure |
The remote Web server exposes information through the HTTP header. |
Modify the HTTP header of the Web server to not expose details about the underlying Web server. |
Ii. installation of IIS 6 Management compatibility
Right-click Roles Web Server (IIS), click Add Role Services, tick "IIS 6 Management Compatibility", and click Next to install.
Third, installation urlscan_v31_x64
1, installation urlscan3.1
2, install UrlScan3.1, using UrlScan 3.1 features, modify the configuration file C:\Windows\System32\inetsrv\UrlScan\UrlScan.ini file as follows
Removeserverheader=1; If 1, removethe ' Server ' header from
; Response. Thedefault is 0.
Or
removeserverheader=0; Do not show server after changing to 1
alternateservername=; If removeserverheader=0 can define itself
The original removeserverheader=0 will be changed to 1, and restart the system.
This article is from the "Wind Valley" blog, please be sure to keep this source http://chenchunjia.blog.51cto.com/1878790/1958168
Windows2008 R2 "Web server HTTP Header information Disclosure" vulnerability fix