1.2.4 Configure Forms Authentication to Use Cookies

Information

Using cookies to manage session state may help mitigate the risk of session hi-jacking attempts by preventing ASP.NET from having to move session information to the URL. Moving session information identifiers into the URL may cause session IDs to show up in proxy logs, browsing history, and be accessible to client scripting via document.location.

Solution

Open IIS Manager and navigate to the level where Forms Authentication is enabled In Features View, double-click Authentication On the Authentication page, select Forms Authentication In the Actions pane, click Edit In the Cookie settings section, select Use cookies from the Mode dropdown

See Also

https://benchmarks.cisecurity.org/tools2/iis/CIS_Microsoft_IIS_7_Benchmark_v1.7.1.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: 36f4a36351ee0b9f2b29d88ec734cf23159f64d13adfa3b4f15ca596ec155abe