STIGQter STIGQter: STIG Summary: Microsoft IIS 10.0 Site Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 23 Apr 2021:

Backup interactive scripts on the IIS 10.0 server must be removed.

DISA Rule

SV-218781r558649_rule

Vulnerability Number

V-218781

Group Title

SRG-APP-000141-WSR-000087

Rule Version

IIST-SI-000263

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove the backup files from the production web server.

Check Contents

Determine whether scripts are used on the web server for the subject website. Common file extensions include, but are not limited to: .cgi, .pl, .vb, .class, .c, .php, .asp, and .aspx. The scope of this requirement is to analyze only within the web server content directories, not the entire underlying operating system.

If the website does not utilize CGI, this finding is Not Applicable.

Open the IIS 10.0 Manager.

Right-click the IIS 10.0 web site name and select "Explore".

Search for the listed script extensions

Search for the following files: *.bak, *.old, *.temp, *.tmp, *.backup, or “copy of...”.

If files with these extensions are found, this is a finding.

Vulnerability Number

V-218781

Documentable

False

Rule Version

IIST-SI-000263

Severity Override Guidance

Determine whether scripts are used on the web server for the subject website. Common file extensions include, but are not limited to: .cgi, .pl, .vb, .class, .c, .php, .asp, and .aspx. The scope of this requirement is to analyze only within the web server content directories, not the entire underlying operating system.

If the website does not utilize CGI, this finding is Not Applicable.

Open the IIS 10.0 Manager.

Right-click the IIS 10.0 web site name and select "Explore".

Search for the listed script extensions

Search for the following files: *.bak, *.old, *.temp, *.tmp, *.backup, or “copy of...”.

If files with these extensions are found, this is a finding.

Check Content Reference

M

Target Key

4051

Comments