Score:0

Disable the 'base' URL for SSRS

np flag

We keep getting hit with moderate security risks on our internal and external penetration tests on our SSRS servers. The main reason for this is that the scanner is attempting to use http(s)://reports.whatever.com.

As far as I could tell in my investigation of SSRS' webservices, this 'base url' is never used. It's only the Web Service URL and the Web Portal URL.

It also appears that in this configuration of SSRS, the webserver being used is the internal http.sys webserver, not IIS. Is it possible to disable this base listener so that only the web service URL and web portal URL send responds to a client?

I have experimented with removing some of the urlacl's in netsh http show urlacl, but to no avail.

I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.