Internal IP Address Disclosure

info Nessus Network Monitor Plugin ID 4666

Synopsis

The remote web server has not properly configured its 'Host' settings.

Description

The remote web server has not properly configured its 'Host' settings. The server discloses its internal IP addresses within HTTP headers. Such information can give an attacker useful information regarding the IP address scheme of the internal network. This may aid the attacker in future attacks.

Solution

Ensure that the server has a properly configured hostname. Note: NNM only reports on the first occurence of this item on a web server. Parse your entire web source for similar occurrences.

Plugin Details

Severity: Info

ID: 4666

Family: Web Servers

Published: 9/15/2008

Updated: 1/16/2019