Check: EMG2-275 Exch2K3
Microsoft Exchange Server 2003:
EMG2-275 Exch2K3
(in version v1 r5)
Title
Scripts are permitted to execute in the Public Folder web server. (Cat II impact)
Discussion
Scripts on virtual servers are a frequent cause of server compromises. Since this virtual (web) server is the primary interface between Exchange and the web, it is particularly at risk of compromise. Therefore, attack vectors via scripts and executables running on the server, should be minimized. The Public Virtual Server enables web access for shared public folders. This control allows the administrator to specify whether scripts and/or executables may be run on this virtual server. Scripts and executables should be denied permissions to run on this server, eliminating this attack vector from the security profile.
Check Content
Validate that scripts are not permitted to execute in the Public Virtual Server. Procedure: Exchange system Manager >>Administrative Groups>> [administrative group]>> Servers >> [server name] >> protocols >> HTTP >> Exchange Virtual Server >> Public >> Properties >> Access tab For Execute Permissions, ‘None’ should be selected. Criteria: If Execute Permissions have ‘None’ selected, this is not a finding.
Fix Text
Configure the Public Virtual Server. Procedure: Exchange system Manager >>Administrative Groups>> [administrative group]>> Servers >> [server name] >> protocols >> HTTP >> Exchange Virtual Server >> Public >> Properties >> Access tab For Execute Permissions, select ‘None’.
Additional Identifiers
Rule ID: SV-20530r1_rule
Vulnerability ID: V-18804
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |