
CMuesing843928 (Community Member) asked a question.
We have Veracode findings on CWE ID 526 and the remediation tips are to use IIS Lockdown and URLScan. Both tools are no longer available for download from Microsoft. URLScan happens to be installed on our older servers and I was able to confirm that the Server Headers were already turned off. But I cannot use IIS Lockdown and I do not know exactly what the issue is that is causing the finding. • Information Exposure Through Environmental Variables (CWE ID 526) Has anybody else been able to resolve this one in the past with a different tool or process?
.png)
Great question, I recommend reviewing the flaw in the triage flaw view. This area highlights the exact server header that should be turned off in the description. Click on the request/response tab on the triage flaw view, and scroll through the response, you should find the specific header we are tagging as an issue. There are many server headers that expose versioning information, so it may not be the one you fixed.
Reviewing Dynamic Flaws
https://help.veracode.com/reader/DGHxSJy3Gn3gtuSIN2jkRQ/SiDRX38ekGp0QWuT~~B8Tg
hi @Justin Yao (Veracode, Inc.)
in iis where shouid i find headers ,and how can i turned off those headers .please let me know the solution
thanks
naveen kumar