WG520 IIS6 - Web server and/or operating system information must be protected.

Information

The web server response header of an HTTP response can contain several fields of information including the requested HTML page. The information included in this response can be web server type and version, operating system and version, and ports associated with the web server. This provides the malicious user valuable information without the use of extensive tools.

Solution

Set the following registry key to 1-

HKLM\SYSTEM\CurrentControlSet\Services\HTTP\Parameters\DisableServerHeader (REG_DWORD)

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|III, Rule-ID|SV-30051r1_rule, STIG-ID|WG520_IIS6, Vuln-ID|V-6724

Plugin: Windows

Control ID: e11ba94451cb643ba3546dbb3a2d5771a5977c58483de399052390eeee700634