Test Methods ( Detailed Overview )

Here is a list of every test performed by Web Scan Service.

IIS Missing Host Header Internal IP Address Disclosure

Remediation Task

Check server configuration

WASC Classification

Information Disclosure: Information Leakage

Affected Products

Microsoft IIS 4.0/5.0/6.0

Technical Description

The default settings of the IIS sends in the Content-Location header the internal IP address of the server and not as it should be the Fully Qualified Domain Name or the Hostname.

Fix Recommendation

Follow the steps described in the following article: http://support.microsoft.com/kb/218180/en-us