WA000-WI6210 - The web-site must limit the number of bytes accepted in a request.

Information

By setting limits on web requests, it ensures availability of web services and mitigates the risk of buffer overflow type attacks. The maxAllowedContentLength Request Filter limits the number of bytes the server will accept in a request.

Solution

1. Open the IIS Manager.
2. Click the site name under review.
3. Double-click the Request Filtering icon.
4. Click Edit Feature Settings in the Actions Pane.
5. Set the maxAllowedContentLength value to 30000000.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-10, CAT|II, Rule-ID|SV-32692r3_rule, STIG-ID|WA000-WI6210, Vuln-ID|V-26041

Plugin: Windows

Control ID: dbf22923135d6ae59353269f55e3b7af10c4aceeb9b51e424670e00168cf0763