Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-6724 | WG520 IIS6 | SV-30051r1_rule | ECSC-1 | Low |
Description |
---|
The web server response header of an HTTP response can contain several fields of information including the requested HTML page. The information included in this response can be web server type and version, operating system and version, and ports associated with the web server. This provides the malicious user valuable information without the use of extensive tools. |
STIG | Date |
---|---|
IIS6 Server | 2015-06-01 |
Check Text ( C-11026r1_chk ) |
---|
Query the SA regarding the publishing of the web server or operating system information. The SA should be able to show that the web server is configured to not display the host operating system of the web server. The reviewer should review the following registry key using the registry editor: HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\DisableServerHeader (REG-DWORD) If the value is not set to 1, this is a finding. |
Fix Text (F-13213r1_fix) |
---|
Set the following registry key to 1: HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\DisableServerHeader (REG_DWORD) |