Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-6755 | WA000-WI090 IIS7 | SV-32466r1_rule | ECSC-1 | Medium |
Description |
---|
The Directory Browsing feature can be used to facilitate a directory traversal exploit. Directory browsing must be disabled. |
STIG | Date |
---|---|
IIS 7.0 WEB SITE STIG | 2013-02-01 |
Check Text ( C-32785r1_chk ) |
---|
1. Open the IIS Manager. 2. Click the site name under review. 3. Click Directory browsing icon. 4. In the Alerts Pane ensure Directory Browsing is disabled. If not, this is a finding. |
Fix Text (F-28974r1_fix) |
---|
1. Open the IIS Manager. 2. Click the site name under review. 3. Click Directory browsing icon. 4. Click Disable in the Actions Pane to disable Directory Browsing. |