1. Home
  2. Security Hardening
  3. DISA STIG IIS 6.0 Site Checklist V6R16
  4. WG235 IIS6 – Web Administrators must secure encrypted connections for Document Root directory uploads.

WG235 IIS6 – Web Administrators must secure encrypted connections for Document Root directory uploads.

Details

Logging in to a web server via a telnet session or using HTTP or FTP in order to upload documents to the web site is a risk if proper encryption is not utilized to protect the data being transmitted. A secure shell service or HTTPS needs to be installed and in use for these purposes.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Use only secure encrypted logons and connections for uploading files to the web site.

Supportive Information

The following resource is also helpful.

This control applies to the following type of system Windows.

References

  • CAT|I
  • Rule-ID|SV-40028r1_rule
  • STIG-ID|WG235_IIS6
  • Vuln-ID|V-13686

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles