WG290 IIS7 - Access to the web content and script directories must be restricted.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Excessive permission for the anonymous web user account is a common fault contributing to the compromise of a web server. If this account is able to upload and execute files on the web server, the organization or owner of the server will no longer have control of the asset.

Solution

1. Open the IIS Manager.
2. Click the site name under review.
3. In the Action Pane select Edit Permissions.
4. Select the Security tab.
5. Set the permissions for the accounts IUSR and Everyone to read.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-6(7), 800-53|CM-6, CAT|I, CSCv6|3.1, Rule-ID|SV-32331r2_rule, STIG-ID|WG290_IIS7, Vuln-ID|V-2258

Plugin: Windows

Control ID: c27683ad7a8d5a88fe18acb1d57151c6e42b6e8a7a87a4d03f033a9712f51564