Quantcast
Channel: Security
Viewing all articles
Browse latest Browse all 1881

Mitigating Host Header Attacks in IIS and ASP

$
0
0

I am researching the mitigation of Host Header Attacks in IIS and ASP. In this article written by James Kettle; there are several solutions for servers using Apache and PHP. I however am looking for solutions on how this might be fixed in an IIS / ASP environment. James suggests in his article that on the server side we need to make the variable SERVER_NAME trustworthy. How is this accomplished in IIS? Can I use a Request Validation or a Whitelist? If so how might I implement this?


Viewing all articles
Browse latest Browse all 1881

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>