WG235 - Remote authors or content providers will only use secure encrypted logons and connections to upload files to the Document Root directory.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Logging in to a web server via a telnet session or using HTTP or FTP in order to upload documents to the web site is a risk if proper encryption is not utilized to protect the data being transmitted. A secure shell service or HTTPS needs to be installed and in use for these purposes.

Solution

Use only secure encrypted logons and connections for uploading files to the web site.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17(2), CAT|I, Rule-ID|SV-14278r2_rule, STIG-ID|WG235, Vuln-ID|V-13686

Plugin: Windows

Control ID: f28a3d7e355ebcdc7be4a726ad2da28205bdd5635be7e3fce49b7d130151e48a