1.1 Default Install Files - 'iisadmpwd' Check if exist

Information

6. Restrict access to iisadmpwd Virtual Directory to Windows Authenticated users if it exist or remove the virtual directory mapping. Removing unnecessary files and folders will help to reduce attack surface thus mitigating unnecessary attack vectors.

Solution

Make sure 'iisadmpwd' does not exist.

See Also

https://workbench.cisecurity.org/files/657

Item Details

Audit Name: CIS IIS 6.0 v1.0.0

Category: ACCESS CONTROL

References: 800-53|AC-6(1), CCE|CCE-19797-0

Plugin: Windows

Control ID: b14ac5ccce84f897f59e727fa0608cd0686e9897aa3ac0f9d13fa76ad3f6bb1c