3.10 Ensure ActiveX filtering is enabled

Information

Removes ActiveX controls from the HTTP reply traffic received on the security appliance.

Rationale:

ActiveX controls are used to provide a rich users' browsing experience. Because the ActiveX control is a written program that is executed in the users' computers, it can be used by attackers to perform malicious tasks on the machines of their victims.

Solution

* Step 1: Acquire the TCP port <port> used for the HTTP traffic containing ActiveX objects, the IP address <internal_users_ip> and mask <internal_users_mask> of internal users generating the HTTP traffic, and the IP address <external_servers_ip> and mask <external_servers_mask> of the external servers to which the internal users connect and that are source of ActiveX objects.
* Step 2: Run the following command to filter ActiveX applets.

HOSTNAME(CONFIG)# FILTER ACTIVEX _<port>__ <internal_users_ip> __<internal_users_mask>__ <external_servers_ip> <external_servers_mask>_

See Also

https://workbench.cisecurity.org/files/1903

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-2, CSCv7|11.1

Plugin: Cisco

Control ID: 48ecf41306e884149f7c41c8a15e3d01ad6138816ff8d38b9216afaa6dcc32d0