WG235 IIS6 - Web Administrators must secure encrypted connections for Document Root directory uploads.

Information

Logging in to a web server via a telnet session or using HTTP or FTP in order to upload documents to the web site is a risk if proper encryption is not utilized to protect the data being transmitted. A secure shell service or HTTPS needs to be installed and in use for these purposes.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Use only secure encrypted logons and connections for uploading files to the web site.

See Also

http://iasecontent.disa.mil/stigs/zip/July2015/U_IIS_6-0_V6R16_STIG.zip

Item Details

References: CAT|I, Rule-ID|SV-40028r1_rule, STIG-ID|WG235_IIS6, Vuln-ID|V-13686

Plugin: Windows

Control ID: 63fa0bcf61c1ba662d3d74085c9ae905cd58c1ad09f37f8516b94e8a8fcf1721