UCF STIG Viewer Logo

The web-site must not allow non-ASCII characters in URLs.


Overview

Finding ID Version Rule ID IA Controls Severity
V-26044 WA000-WI6240 SV-32695r4_rule Medium
Description
By setting limits on web requests, it ensures availability of web services and mitigates the risk of buffer overflow type attacks. The allow high-bit characters Request Filter enables rejection of requests containing non-ASCII characters.
STIG Date
IIS 7.0 Site STIG 2019-05-15

Details

Check Text ( C-32892r3_chk )
For each site reviewed:
1. Open the IIS Manager.
2. Click on the site name.
3. Double-click the Request Filtering icon.
4. Click Edit Feature Settings in the Actions Pane.

If the allow high-bit characters checkbox is checked, this is a finding.

NOTE: If the site has operational reasons to set allow high-bit characters to checked, this vulnerability can be documented locally by the ISSM/ISSO.
Fix Text (F-29038r2_fix)
1. Open the IIS Manager.
2. Click the site name under review.
3. Double-click the Request Filtering icon.
4. Click Edit Feature Settings in the Actions Pane.
5. Uncheck the allow high-bit characters checkbox.