locked
How to Forward HTTP request to HTTPS while HTTP PORT is close? RRS feed

  • General discussion

  • Operating SystemWindows Server 2008

    .

    Description: - We have a web project which is running on HTTPS  PORT 443 on WWW and deployed on JBoss Application Server on Windows Operating System. Recently we received an attack on HTTP Port 80 on application server file.

    .

    Attempt: - We scanned application server and were able to identified API which can be executed by an attacker. We have handled this situation.

    .

    Problem Description: - On asking with IT team, why have they opened HTTP Port 80 on the machine? What is the need to open HTTP port, if the project is running on HTTPS  PORT 443? They said that it is open because  if customer access http://www.abc.com, so they will automatically transfer it to https://www.abc.com

    And if they will close the PORT 80, then following request "http://www.abc.com" cannot be received.

    .

    Kindly let us know, how can we deal with this situation? We want some solution so that we can close the HTTP port on the machine but if a request comes to HTTP, we can automatically forward it to https.

    .

    Kindly assist us, I will be really thankful for any suggestion.


    Regards, S.P Singh

    Monday, November 14, 2016 3:28 AM

All replies

  • Hi,

    >>Kindly let us know, how can we deal with this situation? We want some solution so that we can close the HTTP port on the machine but if a request comes to HTTP, we can automatically forward it to https.

    You could check this link for your reference:

    HTTP to HTTPS redirects on IIS 7.x and higher

    https://blogs.msdn.microsoft.com/kaushal/2013/05/22/http-to-https-redirects-on-iis-7-x-and-higher/


    Best Regards,
    Cartman
    Please remember to mark the replies as an answers if they help and unmark them if they provide no help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Tuesday, November 15, 2016 5:45 AM
  • "You could check this link for your reference:

    HTTP to HTTPS redirects on IIS 7.x and higher"

    We are not using IIS Server for web project deployment. We are using JbossEAP Application Server for deploying web project. 


    Regards, S.P Singh

    Friday, November 18, 2016 5:47 PM
  • "You could check this link for your reference:

    HTTP to HTTPS redirects on IIS 7.x and higher"

    We are not using IIS Server for web project deployment. We are using JbossEAP Application Server for deploying web project. 


    Regards, S.P Singh

    Hi,

    This one may help:

    Http to Https automatic redirection in JBoss AS7

    And I suggest you could post on JBOSS forum for further  assistant:

    http://www.jboss.org/forums/


    Best Regards,
    Cartman
    Please remember to mark the replies as an answers if they help and unmark them if they provide no help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Monday, November 21, 2016 4:03 AM