SV-218781r558649_rule
V-218781
SRG-APP-000141-WSR-000087
IIST-SI-000263
CAT II
10
Remove the backup files from the production web server.
Determine whether scripts are used on the web server for the subject website. Common file extensions include, but are not limited to: .cgi, .pl, .vb, .class, .c, .php, .asp, and .aspx. The scope of this requirement is to analyze only within the web server content directories, not the entire underlying operating system.
If the website does not utilize CGI, this finding is Not Applicable.
Open the IIS 10.0 Manager.
Right-click the IIS 10.0 web site name and select "Explore".
Search for the listed script extensions
Search for the following files: *.bak, *.old, *.temp, *.tmp, *.backup, or “copy of...”.
If files with these extensions are found, this is a finding.
V-218781
False
IIST-SI-000263
Determine whether scripts are used on the web server for the subject website. Common file extensions include, but are not limited to: .cgi, .pl, .vb, .class, .c, .php, .asp, and .aspx. The scope of this requirement is to analyze only within the web server content directories, not the entire underlying operating system.
If the website does not utilize CGI, this finding is Not Applicable.
Open the IIS 10.0 Manager.
Right-click the IIS 10.0 web site name and select "Explore".
Search for the listed script extensions
Search for the following files: *.bak, *.old, *.temp, *.tmp, *.backup, or “copy of...”.
If files with these extensions are found, this is a finding.
M
4051