IIS error response message and how to block it
Hackers always uses a variety of methods to detect your site to get target information when you step on it. One of them is to get some configuration information about the site with the response of http. Here we talk about how it makes corresponding defenses on the Web server.
1. Custom IIS error code response message
The name of the site here is open
Open the IIS Manager, right-click open-Properties on the site you want to edit, and a dialog box pops up.
Locate the Custom errors tab
Select the HTTP error message to edit and edit it.
Note:
Edit Custom error Properties
Use this dialog box to edit custom error messages. Click the custom error message, and then click Edit.
Given security and other system conditions, some errors cannot be customized to point to URL. For example, error 401.2 ("unauthorized-login failed due to server configuration") does not allow custom error messages on the URL because if a server configuration exists, the URL containing the custom error file may not be accessible.
Message type
From the message Type list box, click the type of message you want to return to the client browser-default, file, or URL.
Default value
Click here to return the default HTTP 1.1 error to the client browser. File allows custom errors to be mapped to files by using fully qualified file names. URL allows custom errors to be mapped to URL. If the output type is URL, the URL
Must exist on the local server. Click OK to save your selections.
File / URL
Browse to or type the location of the file that is mapped to the custom error.
Browse
Click here to find directories and files.
Second, block the script message