The Internet Printing Protocol (IPP) must be disabled on the IIS 8.5 web server.

From IIS 8.5 Server Security Technical Implementation Guide

Part of SRG-APP-000383-WSR-000175

Associated with: CCI-001762

SV-91449r1_rule The Internet Printing Protocol (IPP) must be disabled on the IIS 8.5 web server.

Vulnerability discussion

The use of Internet Printing Protocol (IPP) on an IIS web server allows client’s access to shared printers. This privileged access could allow remote code execution by increasing the web servers attack surface. Additionally, since IPP does not support SSL, it is considered a risk and will not be deployed.

Check content

If the Print Services role and the Internet Printing role are not installed, this check is Not Applicable. Navigate to the following directory: %windir%\web\printers If this folder exists, this is a finding. Determine whether Internet Printing is enabled: Click “Start”, then click “Administrative Tools”, and then click “Server Manager”. Expand the roles node, then right-click “Print Services”, and then select “Remove Roles Services”. If the Internet Printing option is enabled, this is a finding.

Fix text

Click “Start”, then click “Administrative Tools”, and then click “Server Manager”. Expand the roles node, then right-click “Print Services”, and then select “Remove Roles Services”. If the Internet Printing option is checked, clear the check box, click “Next”, and then click “Remove” to complete the wizard.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer