UCF STIG Viewer Logo

Web server and/or operating system information must be protected.


Overview

Finding ID Version Rule ID IA Controls Severity
V-6724 WG520 IIS6 SV-30051r1_rule ECSC-1 Low
Description
The web server response header of an HTTP response can contain several fields of information including the requested HTML page. The information included in this response can be web server type and version, operating system and version, and ports associated with the web server. This provides the malicious user valuable information without the use of extensive tools.
STIG Date
IIS6 Server 2015-06-01

Details

Check Text ( C-11026r1_chk )
Query the SA regarding the publishing of the web server or operating system information. The SA should be able to show that the web server is configured to not display the host operating system of the web server.

The reviewer should review the following registry key using the registry editor:

HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\DisableServerHeader (REG-DWORD)

If the value is not set to 1, this is a finding.
Fix Text (F-13213r1_fix)
Set the following registry key to 1:

HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\DisableServerHeader (REG_DWORD)