WA000-WI070 - Content Index Service indexes directories, other than web document directories.

Information

Vulnerability Key: V0003963
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category III
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 2.1
Enabling indexing also facilitates directory traversal exploits. To reveal such information to a malicious
user is potentially harmful. Such information and the contents of files listed are normally readable by
the anonymous Web user, yet are not intended to be viewed as they often contain information relevant
to the configuration and security of the Web service. The indexing service can be used to facilitate a
search function for large Web sites.
NOTE: If Indexing Service is running, verify only web content directories are being indexed.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1

Plugin: Windows

Control ID: 6f98ce2b699cd68ad3f2d499448ae235b188ae0efd1c890cd9102a151d64a7d0