IIST-SI-000263 - Backup interactive scripts on the IIS 10.0 server must be removed.

Information

Copies of backup files will not execute on the server, but they can be read by the anonymous user if special precautions are not taken. Such backup copies contain the same sensitive information as the actual script being executed and, as such, are useful to malicious users. Techniques and systems exist today to search web servers for such files and are able to exploit the information contained in them.

Solution

Remove the backup files from the production web server.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_IIS_10-0_Y23M10_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CAT|II, CCI|CCI-000381, Rule-ID|SV-218781r879587_rule, STIG-ID|IIST-SI-000263, STIG-Legacy|SV-109387, STIG-Legacy|V-100283, Vuln-ID|V-218781

Plugin: Windows

Control ID: 61369c68c142ac602ade17c167e481bbeb05254efbea742d46a00abb68c1d4d4