Details
Logging in to a web server via a telnet session or using HTTP or FTP in order to upload documents to the web site is a risk if proper encryption is not utilized to protect the data being transmitted. A secure shell service or HTTPS needs to be installed and in use for these purposes.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Use only secure encrypted logons and connections for uploading files to the web site.
Supportive Information
The following resource is also helpful.
This control applies to the following type of system Windows.
References
- CAT|I
- Rule-ID|SV-40028r1_rule
- STIG-ID|WG235_IIS6
- Vuln-ID|V-13686