WA000-WI120 - The Content Location header contains proprietary IP addresses.

Information

Vulnerability Key: V0013702
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category III
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
When using static HTML pages, a Content-Location header is added to the response. By default,
Internet Information Server (IIS) 4.0 Content-Location references the IP address of the server rather
than the FQDN or Hostname. This header may expose internal IP addresses that are usually hidden or
masked behind a Network Address Translation (NAT) firewall or proxy server. There is a value that can
be modified in the IIS metabase to change the default behavior from exposing IP addresses to sending
the FQDN instead. The value that needs to be set is the w3svc/UseHostName, and it needs to be set
to True. The other option to prevent this from occurring is to use Active Server Pages instead of static
HTML pages and create a custom header that sends back a specific Content-Location. For complete
instructions on this issue, please refer to Microsoft Knowledge Base article Q218180.
NOTE: Review each websites UseHostName value to ensure it is set to True.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: 42dfec0f003c846210bb90747a0247368b96253bfc4d6d45eb912d94abad583e