UCF STIG Viewer Logo

Backup interactive scripts must be removed from the web site.


Overview

Finding ID Version Rule ID IA Controls Severity
V-2230 WG420 IIS7 SV-32630r3_rule Low
Description
Copies of backup files will not execute on the server, but they can be read by the anonymous user if special precautions are not taken. Such backup copies contain the same sensitive information as the actual script being executed and, as such, are useful to malicious users. Techniques and systems exist today to search web servers for such files and are able to exploit the information contained in them.
STIG Date
IIS 7.0 Site STIG 2019-05-15

Details

Check Text ( C-30361r2_chk )
This check is limited to CGI/interactive content and not static HTML.

Search the IIS Root and Site Directories for the following files: *.bak, *.old, *.temp, *.tmp, *.backup, or ‘copy of...’.

If files with these extensions are found, this is a finding.
Fix Text (F-29059r1_fix)
Remove the backup files from the production web site.