TO HOW: Mask ??????? ????? ?? ?????? ?? IIS ??????? ???????

???? ?????? ???? ??????
???? ID: 317741
?? ?????? ??????? ???? ??? ?? ??? ???????????? ?? ??? Microsoft ??????? ?????????? ???????? (IIS) ??????? 7.0 ???????? ?? Microsoft Windows Server 2008 ??? ??? ??? IIS 7.0 ???????????? ??? ?????? ??????? ?????? ??? IIS ???????-?????? ?????? ?? ???? ??? ???? ??????? ?? ??? ????? Microsoft ??? ???? ?? ????:
HTTP://www.Microsoft.com/technet/Security/prodtech/IIS.mspx
IIS 7.0 ?? ???? ??? ???? ??????? ?? ??? ????? Microsoft ??? ???? ?? ????:
HTTP://www.IIS.NET/default.aspx?tabid=1
??? ?? ??????? ???? | ??? ?? ??????? ????

?? ????? ??

??????

?? ??? ?? ??? ???? ????? ???? ?? ?? ??????? ????? ????? (IIS) ?? ??????? ?????????? ???????? (IIS) ??????? ??????? ?????? ????? ????? ??? ?? ?????? ???? ?? ?????? ?? ?? ?? ??????? ????? ??? ?? ?? ????????? ???? ?? ????? ?? ??? ???? ????? ????????? ???? ?? ?? ??????? ?? ????? ?? ??? ?? URLScan, ?? Microsoft ??????? ??????? ?? ?????? ???? ?????? ?? ??????????? ?? ???? ????

??????? ?????????? ????????? ????? ?? ????? ???????

?? ?? ?? ??????? ????? ?? ??????? ?? ??? ?????, TCP ????? ?????? ????, ?? ??? ???? GET ?????? ???? ?? ??? ?? IIS ????? ?? ???? ??????? ??, ????? ?? ?? ??? ??? ??? ?????? ?? ????????? ??????? IIS ????? ?? ??????????? ??? ?????? ???? ??? ??:

IIS 4.0: ???
HTTP: ????? Microsoft-IIS/4.0 =
IIS 5.0: ???
HTTP: ????? Microsoft-IIS/5.0 =
?? ??????? ?????:
  1. ?? ??????? ????? ?? ?????? ???? ??????? ?????? ?? ??? ??????? ???????? ?? ??????? ????????:: ??? ???? ?? ??? ???? ??????? tracing ??????????, ???? ??? ???? ?? ??? ?????? ???? ???? ??? ????? ?? IP ??? ???? ?????????????? ??????? ?? ???, ???? ?? ???? ?????? ?? ????? ?? ???? ?? Microsoft ???????? ??? ?????::
    252876????? HTTP ???? ????? ??????? ?????? ?? ????? ???? ????
  2. ?? IIS ??? ????? ?? ?? ??? ?? ?????? ?? ??? ???? ??? ??????? ?? ????? ?????
  3. ?? ???? ???????? ??? ???? ?????? ???????? ????? ?? ??? ??, ?????? ?????, HTTP ????????? ???????? ?? ?????? ????, ?? ?????? ?? ??????? ????? ???????? ?????? ?? ???????? ?? ??? ????? ?? ????? ?? ?????????? ?? ??????? IIS ????? ?? ???? HTTP ???????? ?????? ??? ????????? ???? ???? ????? ?? ??? ???????? ?????? ?? ????? ??????? ????? ?? ????? ???? ?? ???????? ??????:.

??? ?????? ?????? ?? ????? ???????

IIS ??? ????? ?? HTTP ????? ?? ?? ?????? ???? ?? ??? ????? ????????? ?? ????? ????, ?? ???? ????? ??????? ????? ???:

IIS 4.0:
?????: Microsoft - IIS/4-0
IIS 5.0:
?????: Microsoft - IIS/5.0
?????? ?????? ?? ???? ?? ??? ????? ????????? ?? ????? ??????? ?????:
??????ip_address_of_web_server80
"??????" ?? IP ??? ?? IP ??? ?? "80" ?? ??? ?????? ?? ??? ?????? ??? ?????

??? ??? ???? ????? ????????? ???? ???? ??, ?? ENTER ????? ????? ?? ????

Mask the Server Header Information

To hide the server header information, download URLScan and then configure the Urlscan.ini file.

???:: The steps in this article only mask the server header information. This procedure does not prevent users from deducing from other information that is returned from Web pages that are served by an IIS Web server.

Install URLScan

URLScan, which you can install with the IIS Lockdown Tool, is an ISAPI filter that provides the Web server administrator with additional configuration options to secure the server. One configurable option is theRemoveServerHeader??????? By default, this option is set to 0, or False.

To download the URLScan utility, visit the following Microsoft Web site:
Urlscan Security Tool
http://www.microsoft.com/downloads/details.aspx?FamilyID=12244f33-a5da-4203-a3a8-83f4388bb71f&DisplayLang=en
By default, URLScan is installed in %systemroot%\System32\Inetsrv\UrlScan directory.

For additional information about how to install and configure URLScan, click the article number below to view the article in the Microsoft Knowledge Base:
307608INFO: Availability of URLScan Version 2.5 Security Tool
To download the IIS Lockdown Tool, visit the following Microsoft Web site:
IIS Lockdown Tool
http://www.microsoft.com/technet/security/tools/locktool.mspx

Edit the Urlscan.ini File

  1. Stop the IISAdmin service, which will also stop all of the services that are dependent on it, such as the World Wide Web Publishing Service.
  2. In My Computer, locate the Urlscan folder. By default, this is located at %systemroot%\System32\Inetsrv\Urlscan.
  3. In Notepad or another text editor, open the Urlscan.ini file.
  4. Locate the following entry:
    RemoveServerHeader=0 
    					
  5. Modify this entry as follows:
    RemoveServerHeader=1
    					
  6. ????? ??????..
  7. Restart the World Wide Web Publishing service and all of the other services that were stopped when the IISAdmin service was stopped. Starting a service that runs under the IISAdmin service also starts the IISAdmin service.

??????

For additional information about URLScan and how URLScan affects other Web technologies, click the article numbers below to view the articles in the Microsoft Knowledge Base:
313489You Can Place Content Headers in the Body of a Response If an ISAPI Filter Is Installed
307976FP: Error Message When You Use FrontPage with URLScan
???? ??????? ?? ???, Microsoft ?? ????? ??? ???? ?? ????::
Security and Privacy
HTTP://www.Microsoft.com/Security

???

???? ID: 317741 - ????? ???????: 04 ?????? 2010 - ??????: 2.0
??????: 
kbhowtomaster kbmt KB317741 KbMthi
???? ?????? ????????
??????????: ?? ???? ?? ???? ??????? ?? ????? ?? Microsoft ????-?????? ?????????? ?????? ?????? ???? ??? ??. Microsoft ???? ??? ????-???????? ?? ????-???????? ????? ?????? ?? ???? ???????? ???? ?? ???? ????? ????? ??? ?? ??? ?????? ?? ???? ???? ???? ??? ????? ??. ???????, ????-???????? ???? ????? ???? ???? ???? ???. ?????, ????????, ?????-???? ?? ??????? ?? ???????? ?? ???? ???, ???? ?? ??? ?????? ???? ???? ??? ????? ??? ?? ???? ??. Microsoft ??????? ??? ???? ?? ?????? ?? ??????????, ????????? ?? ??? ?????? ?? ???? ????? ?? ???? ???????? ?? ??? ???? ????? ?? ??? ????????? ???? ??. Microsoft ????-?????? ?????????? ?? ????? ?????? ?? ?? ??? ??.
?????????? ?? ??????? ????????? ??????? ??:317741

??????????? ???

 

Contact us for more help

Contact us for more help
Connect with Answer Desk for expert help.
Get more support from smallbusiness.support.microsoft.com