Home All Groups Group Topic Archive Search About
Author
13 Jun 2005 6:25 PM
GQuitugua
I'm trying to secure the "http trace" vulnerability on my web server (xforce
article 11149).  I have applied url scan and disabled the appropriate verbs. 
My question is, I'd like to test it to ensure that in fact tracing is
disabled.  Is there a command I can issue against my web server to test this
or some way I can check the status?

Regards,

George Quitugua

Author
14 Jun 2005 12:50 AM
Bernard Cheah [MVP]
Related to this ?
http://msmvps.com/bernard/archive/2003/12/30/1359.aspx

You can do a manual telnet to port 80 and issue the command, or you can try
wfetch
HOW TO: Use Wfetch.exe to Troubleshoot HTTP Connections
http://support.microsoft.com/?id=284285

Show quoteHide quote
"GQuitugua" <GQuitu***@discussions.microsoft.com> wrote in message
news:A0CCB1AA-9954-4E2C-8CED-53965E42709C@microsoft.com...
> I'm trying to secure the "http trace" vulnerability on my web server
> (xforce
> article 11149).  I have applied url scan and disabled the appropriate
> verbs.
> My question is, I'd like to test it to ensure that in fact tracing is
> disabled.  Is there a command I can issue against my web server to test
> this
> or some way I can check the status?
>
> Regards,
>
> George Quitugua