Comments for ServerMask for IIS

ServerMask for IIS Listing updated: June 3, 2003

An often overlooked security issue is the exposure of a Web server’s identity via its HTTP header. By anonymizing your Web server's identity, you can trick hackers to attempt mistargeted exploits, making it easier for intrusion detection systems and firewalls to accomplish their missions and foil the hack. ServerMask obscures the identity of a Windows Web server by removing the most obvious signs that you are running IIS. ServerMask removes or modifies unnecessary response data. The software provides control over what Server header data, if any, is visible in HTTP responses. Session cookie masking permits the customization of any type of session cookie (including the Windows-specific ASP session cookie). ServerMask can emulate the Apache Web server’s HTTP header order and disable Microsoft WebDav with one click to suppress its multiple identifiable headers. It also removes the Windows-specific Public header from HTTP responses, a relic of HTTP 1.0 seldom used today, and converts the Windows SMTP banner to any message. When combined with these security recommendations and other server tools like PageXchanger and CustomError, ServerMask provides the anonymization component of your total security strategy.
  • Users' Rating: 4 [9 votes] - Vote

Comments

Post your own comments with ServerMask for IIS to this page: 

Disclaimer: The views and opinions of visitors published on ISAserver.org do not necessarily state or reflect the opinion of ISAserver.org.


Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center

Readers' Choice

Which is your preferred ISA Monitoring and Management solution?