Details
The presence of a compiler on a production server facilitates the malicious user’s task of creating custom versions of programs and installing Trojan Horses or viruses.
NOTE: This check only searches the ‘C:’ drive, if the system has multiple drives ensure each drive doesn’t contain compilers.
Solution
Remove any compiler programs found on the production web server.
Supportive Information
The following resource is also helpful.
This security hardening control applies to the following category of controls within NIST 800-53: Configuration Management.This control applies to the following type of system Windows.
References
- 800-53|CM-7(4)
- CAT|II
- Rule-ID|SV-38190r1_rule
- STIG-ID|WG080_IIS6
- Vuln-ID|V-2236