WebApp Sec mailing list archives

Obfuscating IIS 6.0


From: Bénoni MARTIN <Benoni.MARTIN () libertis ga>
Date: Thu, 8 Sep 2005 21:31:51 +0100

Hi list !

I'm looking for a way to hide/change/obfuscate/... the banner on a IIS 6.0 web server. I saw that ServerMask from 
port80software.com can do this, but I was wondering if I need to buy a tool just to change a banner ?!

It's feasible under Apache as we can recompile the source after changing this feature, but under IIS 6.0 ?

BTW, I am not relying my web's server security on just this, I know more and more tools/crawlers/scanners/... nowadays 
just skip banner gathering (httprint for instance) as it's easy to fake. But why not adding this little security's 
layer if I can ? :)

Thanks for any clue !


Current thread: