SV-214413r508658_rule
V-214413
SRG-APP-000141-WSR-000081
IISW-SV-000124
CAT II
10
Open the IIS 8.5 Manager.
Click the IIS 8.5 web server name.
Under IIS, double-click the “MIME Types” icon.
From the "Group by:" drop-down list, select "Content Type".
From the list of extensions under "Application", remove MIME types for OS shell program extensions, to include at a minimum, the following extensions:
.exe
.dll
.com
.bat
.csh
Under the "Actions" pane, click "Apply".
Open the IIS 8.5 Manager.
Click the IIS 8.5 web server name.
Under IIS, double-click the “MIME Types” icon.
From the "Group by:" drop-down list, select "Content Type".
From the list of extensions under "Application", verify MIME types for OS shell program extensions have been removed, to include at a minimum, the following extensions:
.exe
.dll
.com
.bat
.csh
If any OS shell MIME types are configured, this is a finding.
V-214413
False
IISW-SV-000124
Open the IIS 8.5 Manager.
Click the IIS 8.5 web server name.
Under IIS, double-click the “MIME Types” icon.
From the "Group by:" drop-down list, select "Content Type".
From the list of extensions under "Application", verify MIME types for OS shell program extensions have been removed, to include at a minimum, the following extensions:
.exe
.dll
.com
.bat
.csh
If any OS shell MIME types are configured, this is a finding.
M
4000