WA000-WI090 IIS7 - Directory Browsing must be disabled.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The Directory Browsing feature can be used to facilitate a directory traversal exploit. Directory browsing must be disabled.

Solution

1. Open the IIS Manager.
2. Click the site name under review.
3. Click Directory browsing icon.
4. Click Disable in the Actions Pane to disable Directory Browsing.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CAT|II, CSCv6|9.1, Rule-ID|SV-32466r3_rule, STIG-ID|WA000-WI090_IIS7, Vuln-ID|V-6755

Plugin: Windows

Control ID: 53848526f91aa4d8b055e839585ec65b89aa644e10c8fda330fc7b42991ca6d9