00c - Disable the loopback adapter check or Specify loopback host names

Table of Contents

You have two options for working with loopback checks, disabling or configuring. Disabling the loopback check increases your attack surface for security threats. As MS KB 896861 states, the loopback check "is designed to help prevent reflection attacks on your computer." 

Option 1 - Disabling

Run this PowerShell script by Michael Blumenthal (note: copy and paste the script from the page - if you download the file, it has HTML markup which will throw an error)


Restart your server

Option 2 - Configuring

The more secure option is to specify host names that you would like to allow connections to from the browser on your server.

From http://support.microsoft.com/kb/896861:

To specify the host names that are mapped to the loopback address and can connect to Web sites on your computer, follow these steps:

  1. Set the DisableStrictNameChecking registry entry to 1. For more information about how to do this, click the following article number to view the article in the Microsoft Knowledge Base: 281308  (http://support.microsoft.com/kb/281308/ ) Connecting to SMB share on a Windows 2000-based computer or a Windows Server 2003-based computer may not work with an alias name
  2. Click Start, click Run, type regedit, and then click OK.
  3. In Registry Editor, locate and then click the following registry key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0
  4. Right-click MSV1_0, point to New, and then click Multi-String Value.
  5. Type BackConnectionHostNames, and then press ENTER.
  6. Right-click BackConnectionHostNames, and then click Modify.
  7. In the Value data box, type the host name or the host names for the sites that are on the local computer, and then click OK.
  8. Quit Registry Editor, and then restart the IISAdmin service.
Enter labels to add to this page:
Please wait 
Looking for a label? Just start typing.
  1. Nov 25, 2009

    Anonymous says:

    You will need to use the "Add Feature" function to install PowerShell in order t...

    You will need to use the "Add Feature" function to install PowerShell in order to run this script. Windows Server 2008 R2 X64 does not install it by default.

  2. Dec 02, 2009

    pHil Rittenhouse says:

    This step should be labeled "Disable the Loopback Adapter Check" rather than "Di...

    This step should be labeled "Disable the Loopback Adapter Check" rather than "Disable the Loopback Adapter"...

    1. Dec 03, 2009

      Jeremy Thake says:

      Thanks Phil, remember this is a wiki so feel free to edit the page and change th...

      Thanks Phil, remember this is a wiki so feel free to edit the page and change the title. I'm trying to encourage more collaboration.


Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 3.0 Unported License. Hosted generously by CustomWare