UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The web-site must not allow non-ASCII characters in URLs.


Overview

Finding ID Version Rule ID IA Controls Severity
V-26044 WA000-WI6240 SV-32695r2_rule ECSC-1 Medium
Description
By setting limits on web requests, it ensures availability of web services and mitigates the risk of buffer overflow type attacks. The allow high-bit characters Request Filter enables rejection of requests containing non-ASCII characters.
STIG Date
IIS 7.0 WEB SITE STIG 2014-12-05

Details

Check Text ( C-32892r2_chk )
For each site reviewed:
1. Open the IIS Manager.
2. Click on the site name.
3. Double-click the Request Filtering icon.
4. Click Edit Feature Settings in the Actions Pane.

If the allow high-bit characters checkbox is checked, this is a finding.

NOTE: If the site has operational reasons to set allow high-bit characters to checked, this vulnerability can be documented locally by the IAM/IAO.
Fix Text (F-29038r2_fix)
1. Open the IIS Manager.
2. Click the site name under review.
3. Double-click the Request Filtering icon.
4. Click Edit Feature Settings in the Actions Pane.
5. Uncheck the allow high-bit characters checkbox.