1.3.10 Hide IIS HTTP Detailed Errors from Displaying Remotely

Information

The information contained in custom error messages can provide clues as to how applications function, opening up unnecessary attack vectors. Ensuring custom errors are never displayed remotely can help mitigate the risk of malicious persons obtaining information as to how the application works.

Solution

The following describes how to change the errorMode attribute to DetailedLocalOnly or Custom for a Web site by using IIS Manager: Open IIS Manager with Administrative privileges In the Connections pane on the left, expand the server, then expand the Sites folder Select the Web site or application to be configured In Features View, select Error Pages, in the Actions pane, select Open Feature In the Actions pane, select Edit Feature Settings In the Edit Error Pages Settings dialog, under Error Responses, select either Custom error pages or Detailed errors for local requests and custom error pages for remote requests Click OK and exit the Edit Error Pages Settings dialog

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-11

Plugin: Windows

Control ID: fe1425fd5ccc1d859328e003050fc1190703cd7a15917d51aa6ae3a451b48ec6