WG330 IIS7 - A web server must limit e-mail to outbound only.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Incoming e-mails have been known to provide hackers with access to servers. Disabling the incoming mail service prevents this type of attacks. Additionally, e-mail is a specialized application requiring the dedication of server resources. A production web server should only provide hosting services for web-sites. Supporting mail services on a web server opens the server to the risk of abuse as an e-mail relay.

Solution

1. Disable the SMTP service.
2. If other e-mail programs are running remove the programs.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, 800-53|CM-7, CAT|II, CSCv6|3.1, CSCv6|9.1, Rule-ID|SV-32639r2_rule, STIG-ID|WG330_IIS7, Vuln-ID|V-2261

Plugin: Windows

Control ID: 62ba4ef2ab81fce187e2f0c6fa94b0da41134ef980c09f59405592c4acd16e01