Exchange Version is displayed through ERG

BS

f you access the site https://fqdn-of-the-erg/owa/auth/ and use the Debug Tools Networktrafic in IE or chrome you are able to get the OWA Version of the Exchange.

This could be a security issue, as an attacker could use some vulnerabilities of this version to get access to the Exchange.

Is there any possibility to cover this response?

Thank you and best Regards

Beni

4 years ago
SOTI MobiControl
ANSWERS
D
DJMOD@SOTI
4 years ago

Hi Benjamin,

Thanks for requesting a response from SOTI Support Staff,

Please find the link below that give more details on deployment server and ports

https://www.soti.net/mc/help/v15.0/en/adminutility/reference/dialogs/adminutility/deployment_server.html?

I will be checking with the product team on the issue. 

BS
Benjamin Spahr
4 years ago

Hello there

I don't think this issue is related to the deployment server, as I'm making a connection to the ERG Server without connectiong to the Doploymant server.

Please test it the following way:

Connect with Internetexplorer to an exchange erg with the following url schema:

 https://fqdn-of-the-erg/owa/auth/

Then start the debugging tools with F12 and switch to the network tab.

Then you could see that the XOWA Version is displayed in the Response.

In my opinion this should be blocked by the ERG.

JD
John Doe
4 years ago

After a quicksearch i came up with this:

https://social.technet.microsoft.com/Forums/en-US/9126f314-f48f-43f3-b7d3-591d72dc36ff/hide-the-version-number-in-owa-html?forum=exchangesvrclients

Shouldnt that be applicable to your issue?

D
DJMOD@SOTI
4 years ago (edited 3 years ago)

Hi Benjamin,

Thanks for contacting SOTI.  As you can see John has provided a link that has more information on the issue you are looking for. 

I am working with product team to find more information on the concern you raised. Could you please let us know if the suggestions provided by John helped as the solution you were looking for. 

BS
Benjamin Spahr
4 years ago

Hello there

Thank you for the provided informations.

I will discuss this with the customer but it seems, that this could be the solution.

Thank you and Best Regards

Beni

J
JMMOD@SOTI
3 years ago

Hi Benjamin,

Just following up on your query. Were you able to find solution to your request from the link suggested by John? If yes, please confirm the same so that the answer by john can be marked as the solution. It will be helpful to people who have similar issue/queries. 


Looking forward to your reply

Thank you!!

BS
Benjamin Spahr
3 years ago

Hello

Unfortunately I didn't hear anything yet from the customer.

I will update it asap.

Best REgards

beni