locked
What about the httpErrors section for IIS7? RRS feed

Answers

  • User1059346350 posted

    That being said, paying more attention to the messages on the screen in IIS7.

    If you are running in classic mode:

    "When running in this mode, custom errors apply to all content except ASP.NET content."

    So maybe we don't need to worry about those pages for this security flaw.

    -Hanan 

    • Marked as answer by Anonymous Thursday, October 7, 2021 12:00 AM
    Monday, September 20, 2010 6:29 AM

All replies

  • User1059346350 posted

    From my understanding the  problem is the error page returning too much infromation. You are correct thoguh, I've tested it on my servers and the httpErrors section in IIS7 does override the customErrors. It seems like you have to set each entry in there to go to your generic error page as well.

    Anyone else have any other ideas?

     

    -Hanan

    Monday, September 20, 2010 6:13 AM
  • User1059346350 posted

    That being said, paying more attention to the messages on the screen in IIS7.

    If you are running in classic mode:

    "When running in this mode, custom errors apply to all content except ASP.NET content."

    So maybe we don't need to worry about those pages for this security flaw.

    -Hanan 

    • Marked as answer by Anonymous Thursday, October 7, 2021 12:00 AM
    Monday, September 20, 2010 6:29 AM