WA000-WI6140 IIS7 - Debug must be turned off on a production website.

Information

Setting compilation debug to false ensures detailed error information does not inadvertently display during live application usage, mitigating the risk of application information being display to users.

Solution

1. Open the IIS Manager.
2. Click the site name under review.
3. Double-click .NET Compilation
4. Scroll down to the Behavior section and set the value for Debug to False.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_7-0_STIG.zip

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-11, CAT|III, Rule-ID|SV-32662r2_rule, STIG-ID|WA000-WI6140_IIS7, Vuln-ID|V-26011

Plugin: Windows

Control ID: af66d1314343c944e13db0071fdeb2f4f34bccdb769494a3634943437a6d7a37