Forum Discussion
GET, provides a host name or an IP address in the response
We have a issue with some old Web Server Internal IP Address Disclosure, please see notes below. Is this something that can be fixed using the BigIP?
When Microsoft Internet Information Services (IIS) receives a GET request without a host header, the Web server may reveal the IP address of the server in the content-location field or the location field in the TCP header in the response. This problem occurs because when IIS receives a GET request that has no host header, IIS must provide a host name or an IP address in the response.
2 Replies
- Brad_Parker
Cirrus
If you are only running the one site on the IP, which I assume you are since host headers would be required to run more than one, you can use a simple iRule like this to ensure the host header is passed back to your IIS server.
when HTTP_REQUEST { HTTP::host www.mysite.com } - Gill_32697
Nimbostratus
Ok, thank you. I will try this iRule.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com