I was required to fix three low risk security issues of a Web Application on a Windows 2003 server, NetFramework 2.0, IIS/6.0.
It is tracert-able. That may assist for crackers to know network topologies of the institute and the University.
Suggestion >> ICMP packets should be blocked for both of inbound and outbound direction.
contains visible Front Page where direct description of the version information of ‘server extensions’, authorizing programs (admin.exe, author.exe etc), and URLs of displaying program (shtml.exe) etc. That may help crackers effective attacks for the server and so on.
Suggestions >> those files should be deleted, if you could, or if you need those files, give appropriate attributes or access protection.
In HTTP service, response header and/or Web contents contains IP address information of the internal network. Those may help effective attack to the internal network.
I don’t know exactly where to look and what to do to fix the issues. Firewall? IIS?