删除/隐藏HTTP响应中的敏感信息

时间:2011-07-07 07:10:06

标签: sharepoint iis

我在Sharepoint服务中创建了一个站点并在IIS 6.0中托管,该站点在响应中显示了一些敏感信息,如服务器名称。请帮我保护或隐藏这些信息。请求和响应如下所示(敏感信息用粗线标出)。

请求 -

GET /Finance/_layouts/userdisp.aspx HTTP/1.1
Host: (Server IP)
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close

回应 -

HTTP/1.1 200 OK
Date: Wed, 29 Jun 2011 00:08:33 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
MicrosoftSharePointTeamServices: 12.0.0.6421
X-AspNet-Version: 2.0.50727
Set-Cookie: WSS_KeepSessionAuthenticated=443; path=/
Set-Cookie: MSOWebPartPage_AnonymousAccessCookie=443; expires=Wed, 29-Jun-2011 00:38:33 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 32318

1 个答案:

答案 0 :(得分:0)

您可以使用URLScan隐藏标题中报告的服务器名称:

http://www.iis.net/download/urlscan