Hiding IIS version from Response Header


  
 Applies To 
  
 Product(s):eB Web
 Version(s):16.X.X
 Environment: N/A
 Area: Internet Information Services (IIS)
 Subarea: N/A
 Original Author:Gintautas Bajoriunas, Bentley Technical Support Group
  

 

 

 

 

 

 

 

 

This Wiki article will explain how to hide Internet Information Services (IIS) version in Response Header.

















Background

This can be tested by using Fiddler

Steps to Accomplish 

  1. Download and install UrlScan 3.1 security tool from http://www.iis.net/downloads/microsoft/urlscan.

  2. If IIS version 7 is used then add additional role 'IIS6Metabase Compatability' is required.  IIS > IIS6 Management Compatability>IIS6Metabase Compatability.

  3. After installing UrlScan tool navigate to C:\Windows\System32\inetsrv\urlscan and open UrlScan.ini with text editor. Set 1 for RemoveServerHeader option (as in screenshot below) save and then close the file.

  4. You must restart the server for changes to take effect

 

Result

 

 

 

 

 

See Also