Preventing host header attack
Hi,
Is there way to prevent host header attack on CF2016 (Win Server 2008 IIS7.5)?
We had server scan and identified this vulnerability where X-Forwarded-Host was modified to trigger redirect to potentially malicious site.
I have seen some references to adding dummy virtual hosts to apache server but, I am not skilled in server administration and not sure how to do that in CF2016.
Thank you,
Gena
