Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
DTBI001 | DTBI001 | DTBI001_rule | Medium |
Description |
---|
By setting this parameter inappropriately, a malicious web site will be automatically loaded into a browser which may contain mobile code. |
STIG | Date |
---|---|
Microsoft Internet Explorer 11 Security Technical Implementation Guide | 2014-02-18 |
Check Text ( C-DTBI001_chk ) |
---|
Open Internet Explorer. From the menu bar select Tools. From the Tools drop-down menu, select Internet Options. From the Internet Options window, select the General tab. Under the Home page area, verify 'about:blank' or a trusted site is listed. If 'about:blank' or a trusted site is not listed, this is a finding. Procedure: Use the Windows Registry Editor to navigate to the following key: HKCU\Software\Microsoft\Internet Explorer\Main Criteria: If the value Start Page is about:blank or a trusted site, this is not a finding. |
Fix Text (F-DTBI001_fix) |
---|
Open Internet Explorer. From the menu bar select Tools. From the Tools drop-down menu, select Internet Options. From the Internet Options window, select the General tab. Under the Home page area, enter 'about:blank' or a trusted site. Change the registry key: HKCU\Software\Microsoft\Internet Explorer\Main so that value Start Page is set to 'about:blank' or a trusted site. |