Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-214423 | IISW-SV-000138 | SV-214423r508658_rule | Medium |
Description |
---|
Directory browsing allows the contents of a directory to be displayed upon request from a web client. If directory browsing is enabled for a directory in IIS, users could receive a web page listing the contents of the directory. If directory browsing is enabled the risk of inadvertently disclosing sensitive content is increased. |
STIG | Date |
---|---|
Microsoft IIS 8.5 Server Security Technical Implementation Guide | 2021-09-22 |
Check Text ( C-15633r505363_chk ) |
---|
If the Directory Browsing IIS Feature is disabled, this is Not Applicable. Open the IIS 8.5 Manager. Click the IIS 8.5 web server name. Double-click the "Directory Browsing" icon. Under the “Actions” pane verify "Directory Browsing" is disabled. If “Directory Browsing” is not disabled, this is a finding. |
Fix Text (F-15631r505364_fix) |
---|
If the Directory Browsing IIS Feature is disabled, this is Not Applicable. Open the IIS 8.5 Manager. Click the IIS 8.5 web server name. Double-click the "Directory Browsing" icon. Under the "Actions" pane click "Disabled". Under the "Actions" pane, click "Apply". |