WG260 IIS6 - Only fully reviewed and tested web sites must exist on a production web server.

Information

In the case of a production web server, areas for content development and testing will not exist, as this type of content is only permissible on a development web site. The process of developing on a functional production web site entails a degree of trial and error and repeated testing. This process is often accomplished in an environment where debugging, sequencing, and formatting of content are the main goals. The opportunity for a malicious user to obtain files revealing business logic and login schemes is high in this situation. The existence of such immature content on a web server represents a significant security, which is totally avoidable.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Ensure any pages in development are not installed on a production web server.

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

References: CAT|II, Rule-ID|SV-38069r2_rule, STIG-ID|WG260_IIS6, Vuln-ID|V-2254

Plugin: Windows

Control ID: 827642c51911630d65b68df074f82f11383b8cd7cec0290bfe959c47057da765