All IIS 8.5 web server sample code, example applications, and tutorials must be removed from a production IIS 8.5 server.

From IIS 8.5 Server Security Technical Implementation Guide

Part of SRG-APP-000141-WSR-000077

Associated with: CCI-000381

SV-91401r1_rule All IIS 8.5 web server sample code, example applications, and tutorials must be removed from a production IIS 8.5 server.

Vulnerability discussion

Web server documentation, sample code, example applications, and tutorials may be an exploitable threat to a web server. A production web server may only contain components that are operationally necessary (i.e., compiled code, scripts, web content, etc.). Delete all directories containing samples and any scripts used to execute the samples.

Check content

Navigate to the following folders: inetpub\ Program Files\Common Files\System\msadc Program Files (x86)\Common Files\System\msadc If the folder or sub-folders contain any executable sample code, example applications, or tutorials which are not explicitly used by a production website, this is a finding.

Fix text

Remove any executable sample code, example applications, or tutorials which are not explicitly used by a production website.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer