1. Home
  2. Security Hardening
  3. CIS IIS 10 V1.1.1 L2
  4. Ensure ‘MaxQueryString request filter’ is configured – Default

Ensure ‘MaxQueryString request filter’ is configured – Default

Details

The MaxQueryString Request Filter may be set for a server, website, or application using the IIS Manager GUI, using AppCmd.exe commands in a command-line window, and/or directly editing the configuration files. To configure using the IIS Manager GUI:

1. Open Internet Information Services (IIS) Manager

2. In the Connections pane, go to the connection, site, application, or directory to be configured

3. In the Home pane, double-click Request Filtering

4. Click Edit Feature Settings… in the Actions pane

5. Under the Request Limits section, key in a safe upper bound in the Maximum query string (Bytes) textbox

Enter the following command in AppCmd.exe to configure:

%systemroot%system32inetsrvappcmd set config /section:requestfiltering /requestLimits.maxQueryString:2048

OR

Enter the following command in PowerShell to configure:

Set-WebConfigurationProperty -pspath ‘MACHINE/WEBROOT/APPHOST’ -filter ‘system.webServer/security/requestFiltering/requestLimits’ -name ‘maxQueryString’ -value 2048

Default Value:

When request filtering is installed on a system, the default value is maxQueryString=’2048′

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Information Integrity.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles