WG170 - Each readable web document directory does not contain either a default, home, index or equivalent file 'DefaultDoc'

Information

Vulnerability Key: V0002245
IA Controls: ECSC-1 Security Configuration Compliance
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 3.4, Web Site Administration Policies & Procedures, With Amendments
and Corrections incorporated in red italics
The goal is to completely control the web user's experience in navigating any portion of the web
document root directories. Ensuring all web content directories have at least the equivalent of an
index.html file is a significant factor to accomplish this end. Also, enumeration techniques, such as url
parameter manipulation, rely upon being able to obtain information about the web server's directory
structure by locating directories with default pages. This practice helps ensure that the anonymous
web user will not obtain directory browsing information nor an error message that reveals the server
type and version.
NOTE: Review each website's default documents list to ensure each site contains a default document.

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Windows

Control ID: e223fd359f42e7e7acf14b1cde037aacf3d5541348743a7cd468eae4e5226d55