Last post Aug 08, 2018 08:36 AM by PatriceSc
Aug 07, 2018 05:52 AM|sanii101|LINK
I want to remove the server tag from the response header due to some security constraints.I have tried url scan,url rewrite,registry update(disableserverheader) etc..My application is hosted in IIS 8.5.
Please help me to solve this issue .
Response header screenshots are attached.
Aug 07, 2018 06:36 AM|PatriceSc|LINK
The url rewriting approach you used is something like https://scotthelme.co.uk/hardening-your-http-response-headers/ ?
Aug 07, 2018 06:42 AM|sanii101|LINK
Thanks for your reply.
I have already tried the solution explained in the https://scotthelme.co.uk/hardening-your-http-response-headers/ ?
Aug 08, 2018 08:07 AM|Brando ZWZ|LINK
As far as I know, there are three ways to remove the srever header.
1. Using the Registry key.
2. Using the URLScan tool.
3. Using URLRewrite
More details you could refer to below article:
Aug 08, 2018 08:36 AM|PatriceSc|LINK
I gave this a try and it seems to work here at least for 200 OK. Will try to test for http 411