Check: WG235 IIS6
IIS6 Site:
WG235 IIS6
(in version v6 r16)
Title
Web Administrators must secure encrypted connections for Document Root directory uploads. (Cat I impact)
Discussion
Logging in to a web server via a telnet session or using HTTP or FTP in order to upload documents to the web site is a risk if proper encryption is not utilized to protect the data being transmitted. A secure shell service or HTTPS needs to be installed and in use for these purposes.
Check Content
Query the SA to determine if there is a process for the uploading of files to the web site. This process should include the requirement for the use of a secure encrypted logon and secure encrypted connection. NOTE: See results from WG230 for data that will assist in the validation of this vulnerability. If the remote users are uploading files without utilizing approved encryption methods, this is finding.
Fix Text
Use only secure encrypted logons and connections for uploading files to the web site.
Additional Identifiers
Rule ID: SV-40028r1_rule
Vulnerability ID: V-13686
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |