Thread: Общие вопросы (General Questions)/Preparation IIS for the penetration test

Preparation IIS for the penetration test

Using the Adsutil.vbs Administration Script (IIS 6.0)


www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/d3df4bc9-0954-459a-b5e6-7a8bc462960c.mspx





Re: Preparation IIS for the penetration test

cscript adsutil.vbs set w3svc/x/SetHostName hostname


FIX: IP address is revealed in the content-location field in the TCP header in IIS 6.0


support.microsoft.com/kb/834141





Re: Preparation IIS for the penetration test

IIS 6 Fix – Don’t Give Out the Internal IP Address





Re: Preparation IIS for the penetration test

Removing an IIS server's IP address from HTTP responses


blogs.msdn.com/mike/archive/2008/11/18/removing-an-iis-server-s-ip-address-from-http-responses.aspx