Step 1: Remove Server response header with an outboundRule URL Rewrite ruleĐặt trong thẻ system.webserver
Mã:
<rewrite>
<outboundRules rewriteBeforeCache="true">
<rule name="Remove Server header">
<match serverVariable="RESPONSE_Server" pattern=".+" />
<action type="Rewrite" value="" />
</rule>
</outboundRules>
</rewrite>
Step 2: Remove ASP.NET X-Powered-By header in IIS using web.config customHeadersĐặt trong thẻ system.webserver
Mã:<httpProtocol>
<customHeaders>
<remove name="X-Powered-By" />
</customHeaders>
</httpProtocol>
Trong thẻ httpruntime trên system.web bổ sung thêm cái này
Mã:<httpRuntime
enableVersionHeader="false" />