Wednesday, December 11, 2013

Tools: Capture Http/https traffic: Web Browsers

This is a good tool to look at how a web application is interacting with browsers on a client machine.

http://fiddler2.com/features

Look at session metrics
Filter captured traffic
Checking headers

Servers: Windows: IIS: Remove Headers

Install Microsoft URL scan and edit C:\Windows\System32\inetsrv\urlscan\UrlScan.ini choose 'Remove Server Header' and configure it to be a '1'.

Software to install Microsoft Urlscan Filter