Removing/Hiding/Disabling excessive HTTP response headers in Azure/IIS7 without UrlScan

后端 未结 5 829
长发绾君心
长发绾君心 2020-11-28 01:48

I need to remove excessive headers (primarily to pass penetration testing). I have spent time looking at solutions that involve running UrlScan, but these are cumbersome as

5条回答
  •  天命终不由人
    2020-11-28 02:41

    There's also a package on NuGet that helps you achieve this through a few lines of config and no changes to code: NWebsec. The docs on removing version headers can be found here: https://github.com/NWebsec/NWebsec/wiki/Suppressing-version-headers

    It's demoed here: http://www.nwebsec.com/HttpHeaders/VersionHeaders (in Azure)

    Disclaimer: I'm the developer on the project.

提交回复
热议问题