Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-108

Web Security: WEB BANNER REVEALS VERSION INFO

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: High
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Issue Importance:
      Must Have
    • Sprint:
      ST Sprint 1

      Description

      Praetorian discovered this vulnerability while manually monitoring the data sent to the application in the server responses. The web banner revealed the application server software name and version number.

        Attachments

          Activity

          Hide
          niteen.surwase Niteen Surwase (Inactive) added a comment - - edited

          Commented code : SharedFunctionWebTier\SharedFunctionWebTier\Modules\SharedSessionModule.cs

          This code is commented because for this patch, changes made in IIS Configuration Editor at Web Server.

          Show
          niteen.surwase Niteen Surwase (Inactive) added a comment - - edited Commented code : SharedFunctionWebTier\SharedFunctionWebTier\Modules\SharedSessionModule.cs This code is commented because for this patch, changes made in IIS Configuration Editor at Web Server.
          Hide
          niteen.surwase Niteen Surwase (Inactive) added a comment -

          Path to Test:
          Open Login Page --> Right Click --> Inspect Element --> "Network" Tab --> Ctrl+F5 --> Click on files from list, you will get file details at Right side.

          To Check :
          In earlier scenario,

          In the file details there was Server attribute which reveals Server Version Info

          Now, this attribute is removed for all files

          Show
          niteen.surwase Niteen Surwase (Inactive) added a comment - Path to Test : Open Login Page --> Right Click --> Inspect Element --> "Network" Tab --> Ctrl+F5 --> Click on files from list, you will get file details at Right side. To Check : In earlier scenario, In the file details there was Server attribute which reveals Server Version Info Now, this attribute is removed for all files
          Hide
          amitg Amit Gude (Inactive) added a comment -

          Assigning to Zeeshan

          Show
          amitg Amit Gude (Inactive) added a comment - Assigning to Zeeshan
          Hide
          Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

          Verified as Server Banner is removed from responses.

          Show
          Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Verified as Server Banner is removed from responses.
          Hide
          Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

          Verified that server header does not appear in response on stage.

          Show
          Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Verified that server header does not appear in response on stage.
          Hide
          niteen.surwase Niteen Surwase (Inactive) added a comment - - edited

          Zeeshan Chishty

          Deployed on Production on all 3 Web Servers.
          Please check carefully. If you found any Response Header related to this ticket please let us know.
          Removed Response Headers:

          1. Server
          2. X-Powered-By
          3. X-Aspnet-Version
          4. X-AspNetMvc-Version

          NOTE : Check this headers only for WORKTERRA Resources

          Show
          niteen.surwase Niteen Surwase (Inactive) added a comment - - edited Zeeshan Chishty Deployed on Production on all 3 Web Servers. Please check carefully. If you found any Response Header related to this ticket please let us know. Removed Response Headers: Server X-Powered-By X-Aspnet-Version X-AspNetMvc-Version NOTE : Check this headers only for WORKTERRA Resources
          Hide
          Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

          Confirmed that server header does not appear in response on Production Server's response

          Show
          Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Confirmed that server header does not appear in response on Production Server's response
          Hide
          deepalit Deepali Tidke (Inactive) added a comment -

          as discussed with Niteen no functional testing is involved here , can close this ticket.

          Show
          deepalit Deepali Tidke (Inactive) added a comment - as discussed with Niteen no functional testing is involved here , can close this ticket.

            People

            Assignee:
            deepalit Deepali Tidke (Inactive)
            Reporter:
            samir Samir
            Developer:
            Niteen Surwase (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: