SV-218798r561041_rule
V-218798
SRG-APP-000141-WSR-000081
IIST-SV-000124
CAT II
10
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Under IIS, double-click the "MIME Types" icon.
From the "Group by:" drop-down list, select "Content Type".
From the list of extensions under "Application", remove MIME types for OS shell program extensions, to include at a minimum, the following extensions:
.exe
.dll
.com
.bat
.csh
Under the "Actions" pane, click "Apply".
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Under IIS, double-click the "MIME Types" icon.
From the "Group by:" drop-down list, select "Content Type".
From the list of extensions under "Application", verify MIME types for OS shell program extensions have been removed, to include at a minimum, the following extensions:
.exe
.dll
.com
.bat
.csh
If any OS shell MIME types are configured, this is a finding.
V-218798
False
IIST-SV-000124
Open the IIS 10.0 Manager.
Click the IIS 10.0 web server name.
Under IIS, double-click the "MIME Types" icon.
From the "Group by:" drop-down list, select "Content Type".
From the list of extensions under "Application", verify MIME types for OS shell program extensions have been removed, to include at a minimum, the following extensions:
.exe
.dll
.com
.bat
.csh
If any OS shell MIME types are configured, this is a finding.
M
4052