You might have seen the following information in the request header of your website. An attacker can use this information to carry out attacks on your website. You can easily avoid this.

The following will remove version header

<httpRuntime enableVersionHeader=”false” />


The following will remove X-Powered-By and IIS version

<remove name=”X-Powered-By” />
<rule name=”Remove RESPONSE_Server” >
<match serverVariable=”RESPONSE_Server” pattern=”.+” />
<action type=”Rewrite” value=”NA” />

Donate me $1 or above 🙂