WG300 IIS7 - Web server system files must conform to minimum file permission requirements.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This check verifies the key web server system configuration files are owned by the SA or the web administrator controlled account. These same files that control the configuration of the web server, and thus its behavior, must also be accessible by the account running the web service. If these files are altered by a malicious user, the web server would no longer be under the control of its managers and owners; properties in the web server configuration could be altered to compromise the entire server platform.

Solution

1. Open Explorer and navigate to the inetpub directory.
2. Right-click inetpub and select Properties.
3. Click the Security tab.
4. Set the following permissions:
System: Full control
Administrators: Full control
TrustedInstaller: Full control
Users: Read & execute, list folder contents
Creator/Owner: special permissions to subkeys

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6(7), 800-53|CM-6, CAT|II, CSCv6|3.1, Rule-ID|SV-32332r2_rule, STIG-ID|WG300_IIS7, Vuln-ID|V-2259

Plugin: Windows

Control ID: a67618afed309cb4f945c2a7acb7ec24188b25b526984c2d3e45494ce3a83b6d