WG420 IIS6 - Backup interactive scripts must be removed from the web site.

Information

Copies of backup files will not execute on the server, but they can be read by the anonymous user if special precautions are not taken. Such backup copies contain the same sensitive information as the actual script being executed and, as such, are useful to malicious users. Techniques and systems exist today that search web servers for such files and are able to exploit the information contained in them.
NOTE: This check only searches the 'C:' drive, if the system has multiple drives ensure each drive doesn't contain compilers.
NOTE: If there is nothing reported in the plugin output then Nessus did not find any backup files on the system.

Solution

Remove the backup scripts from the web server.

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7(4), CAT|III, Rule-ID|SV-38084r1_rule, STIG-ID|WG420_IIS6, Vuln-ID|V-2230

Plugin: Windows

Control ID: 2fb8ba1f7c7814f8d916c466a060f6065ffb3fb72efa69bc6f70ea2b3e70cdbd