1.4.9 Ensure Configuration Attribute notListedCgisAllowed set to false

Information

Restricting this attribute to false will help prevent unlisted CGI extensions, including potentially malicious CGI scripts from being run.

Solution

To set the notListedCgisAllowed attribute to false using IIS Manager: Open IIS Manager as Administrator In the Connections pane on the left, select the server to configure In Features View, select ISAPI and CGI Restrictions; in the Actions pane, select Open Feature In the Actions pane, select Edit Feature Settings In the Edit ISAPI and CGI Restrictions Settings dialog, clear the Allow unspecified CGI modules check box Click OK

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-18

Plugin: Windows

Control ID: 87e243963f1fa4681e15d3c0e793aaff3dd539c24b5177f357ba1ca5f162f8a3