IIS 8.5 web server system files must conform to minimum file permission requirements.

From IIS 8.5 Server Security Technical Implementation Guide

Part of SRG-APP-000340-WSR-000029

Associated with: CCI-002235

SV-91441r1_rule IIS 8.5 web server system files must conform to minimum file permission requirements.

Vulnerability discussion

This check verifies the key web server system configuration files are owned by the SA or the web administrator controlled account. These same files that control the configuration of the web server, and thus its behavior, must also be accessible by the account running the web service. If these files are altered by a malicious user, the web server would no longer be under the control of its managers and owners; properties in the web server configuration could be altered to compromise the entire server platform.

Check content

Open Explorer and navigate to the inetpub directory. Right-click inetpub and select “Properties”. Click the "Security" tab. Verify the permissions for the following users; if the permissions are less restrictive, this is a finding. System: Full control Administrators: Full control TrustedInstaller: Full control ALL APPLICATION PACKAGES (built-in security group): Read and execute Users: Read and execute, list folder contents Creator/Owner: Special permissions to subkeys

Fix text

Open Explorer and navigate to the inetpub directory. Right-click inetpub and select “Properties”. Click the "Security" tab. Set the following permissions: SYSTEM: Full control Administrators: Full control TrustedInstaller: Full control ALL APPLICATION PACKAGES (built-in security group): Read and execute Users: Read and execute, list folder contents Creator/Owner: special permissions to subkeys

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer