SV-241788r695281_rule
V-241788
SRG-APP-000266-WSR-000159
IIST-SV-000210
CAT III
10
Navigate to “HKLM\CurrentControlSet\Services\HTTP\Parameters”
Create REG_DWORD “DisableServerHeader” and set it to “1”
Note: This can be performed multiple ways, this is an example.
Open Registry Editor.
Navigate to “HKLM\CurrentControlSet\Services\HTTP\Parameters”
Verify “DisableServerHeader” is set to “1”.
If REG_DWORD DisableServerHeader is not set to 1, this is a finding.
If the System Administrator can show that Server Version information has been removed via other means, such as using a rewrite outbound rule, this is not a finding.
V-241788
False
IIST-SV-000210
Open Registry Editor.
Navigate to “HKLM\CurrentControlSet\Services\HTTP\Parameters”
Verify “DisableServerHeader” is set to “1”.
If REG_DWORD DisableServerHeader is not set to 1, this is a finding.
If the System Administrator can show that Server Version information has been removed via other means, such as using a rewrite outbound rule, this is not a finding.
M
4052