You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何从IIS Web Farm中移除X-Powered-By: ARR/3.0响应头?

移除IIS/ARR托管网站Powered-By响应头的调试与解决方案

一、现有注册表方案失效的调试步骤

  • 验证注册表配置准确性
    1. 检查路径:32位系统确认HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IIS\Server\CustomHeader,64位系统需同时排查HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\IIS\Server\CustomHeader
    2. 确认键值:需创建字符串类型键X-Powered-By,值设为空字符串
    3. ARR专项检查:若启用ARR,验证HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WebManagement\Server下是否存在DWORD类型键RemoveServerHeader,值需设为1
  • 确认服务重启完整性
    1. 执行iisreset重启IIS服务,同时重启ARR关联服务(如Application Request Routing Cache、Web Management Service)
    2. 必要时重启服务器,确保配置完全加载
  • 定位响应头来源
    1. 用Fiddler或浏览器开发者工具捕获完整请求响应,判断X-Powered-By来自IIS、ARR还是后端应用
    2. 若来自后端(如ASP.NET),需在web.config添加<httpRuntime enableVersionHeader="false" />,并在<system.webServer>节点下补充:
      <httpProtocol>
        <customHeaders>
          <remove name="X-Powered-By" />
        </customHeaders>
      </httpProtocol>
      

二、替代可行方案

  • URL重写模块移除响应头
    1. 确保已安装IIS URL重写模块
    2. 在站点或服务器级web.config中添加规则:
      <system.webServer>
        <rewrite>
          <outboundRules rewriteBeforeCache="true">
            <rule name="Remove X-Powered-By">
              <match serverVariable="RESPONSE_X-Powered-By" pattern=".+" />
              <action type="Rewrite" value="" />
            </rule>
          </outboundRules>
        </rewrite>
      </system.webServer>
      
  • ARR代理设置调整
    1. 在ARR服务器的IIS管理器中,打开服务器节点下的Application Request Routing Cache
    2. 点击Server Proxy Settings,勾选Reverse rewrite host in response headers,并在代理规则中配置移除响应头
  • 自定义HTTP模块
    编写简单模块拦截响应并移除目标头:
    public class RemovePoweredByModule : IHttpModule
    {
        public void Init(HttpApplication context)
        {
            context.PreSendRequestHeaders += OnPreSendRequestHeaders;
        }
    
        void OnPreSendRequestHeaders(object sender, EventArgs e)
        {
            HttpContext.Current.Response.Headers.Remove("X-Powered-By");
        }
    
        public void Dispose() { }
    }
    
    编译后将模块注册到IIS的web.config中。

内容的提问来源于stack exchange,提问作者Behnam Esmaili

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.11 00:05:28