WA000-WI6240 - The web-site must not allow non-ASCII characters in URLs.

Information

By setting limits on web requests, it ensures availability of web services and mitigates the risk of buffer overflow type attacks. The allow high-bit characters Request Filter enables rejection of requests containing non-ASCII characters.

Solution

1. Open the IIS Manager.
2. Click the site name under review.
3. Double-click the Request Filtering icon.
4. Click Edit Feature Settings in the Actions Pane.
5. Uncheck the allow high-bit characters checkbox.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-10, CAT|II, Rule-ID|SV-32695r4_rule, STIG-ID|WA000-WI6240, Vuln-ID|V-26044

Plugin: Windows

Control ID: fdc2d59de5f56f94306be32b51a7be902b6f63acffeb6b6f844da6789d19f781