|
security
newsgroups
|
|||||||||||||||||||||||
|
|||||||||||||||||||||||
IIS 6.0 leaks internal IP address in Content-Location headerHello,
I have an IP leak problem running IIS 6.0 on W2K3 SP1. I have followed recomendations in KB218180 and KB834141 and configured SetHostName so that my websites do not return internal IP addresses. I have also configured host headers for my websites. But, my server still returns a private IP in the response to the following request: HEAD / HTTP/1.0 I can't find any other solutions beyond the above. Does anyone have any suggestions?
Show quote
Hide quote
"Andrew Head" <AndrewH***@discussions.microsoft.com> wrote in message KB218180 is for IIS4 and IIS5.news:B05A112E-88E6-4A36-9237-8591136686CB@microsoft.com... > Hello, > > I have an IP leak problem running IIS 6.0 on W2K3 SP1. I have followed > recomendations in KB218180 and KB834141 and configured SetHostName so that > my websites do > > > not return internal IP addresses. I have also configured host headers for > my websites. > > But, my server still returns a private IP in the response to the following > request: > HEAD / HTTP/1.0 > > I can't find any other solutions beyond the above. Does anyone have any > suggestions? > KB834141 is for IIS6, but also requires the hotfix. However, that hotfix is pre-SP1 - SP1 includes newer versions of both of those files. I remember going through both of those articles, and some others. If I remember, I'll post details. As of right now, there is no Content-Location: header returned by my sites - and I don't have a custom ISAPI dll installed. Dan
Network/Web Site Authentication
iis problems with some xp clients - kerberos issue? IIS + SQL (Not enough storage is available to complete this operation) Network service default permissions Virtual Directory On UNC Share Not Writable changing "CN" name Microsoft URL Scan HTTP 405: The HTTP verb used to access this page is not allowed Integrated Windows Authentication results in -2146893052 (0x80090304) Application Pool Identity |
|||||||||||||||||||||||