Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-26044 | WA000-WI6240 | SV-32695r1_rule | ECSC-1 | Medium |
Description |
---|
By setting limits on web requests, it ensures availability of web services and mitigates the risk of buffer overflow type attacks. The allow high-bit characters Request Filter enables rejection of requests containing non-ASCII characters. |
STIG | Date |
---|---|
IIS 7.0 WEB SITE STIG | 2011-08-19 |
Check Text ( C-32892r1_chk ) |
---|
For each site reviewed: 1. Open the IIS Manager. 2. Click on the site name. 3. Double-click the Request Filtering icon. 4. Click Edit Feature Settings in the Actions Pane. If the allow high-bit characters checkbox is not checked, this is a finding. NOTE: If the site has operational reasons to set allow high-bit characters to unchecked, this vulnerability can be documented locally by the IAM/IAO. |
Fix Text (F-29038r1_fix) |
---|
1. Open the IIS Manager. 2. Click the site name under review. 3. Double-click the Request Filtering icon. 4. Click Edit Feature Settings in the Actions Pane. 5. Check the allow high-bit characters checkbox. |