SV-223263r612235_rule
V-223263
SRG-APP-000340
SP13-00-000140
CAT I
10
Configure the SharePoint server to prevent non-privileged users from circumventing malicious code protection capabilities.
Navigate to Central Administration.
Click "Manage web applications".
Select the web application by clicking its name.
Select "Blocked File Types" from the ribbon.
Add file types that are defined in the SSP but not in the list of blocked file types.
Click "Ok".
Repeat for each web application that has findings.
Review the SharePoint server configuration to ensure non-privileged users are prevented from circumventing malicious code protection capabilities.
Confirm that the list of blocked file types configured in Central Administration matches the "blacklist" document in the application's SSP. See TechNet for default file types that are blocked: http://technet.microsoft.com/en-us/library/cc262496.aspx
Navigate to Central Administration.
Click "Manage web applications".
Select the web application by clicking its name.
Select "Blocked File Types" from the ribbon.
Compare the list of blocked file types to those listed in the SSP. If the SSP has file types that are not in the blocked file types list, this is a finding.
Repeat check for each web application.
V-223263
False
SP13-00-000140
Review the SharePoint server configuration to ensure non-privileged users are prevented from circumventing malicious code protection capabilities.
Confirm that the list of blocked file types configured in Central Administration matches the "blacklist" document in the application's SSP. See TechNet for default file types that are blocked: http://technet.microsoft.com/en-us/library/cc262496.aspx
Navigate to Central Administration.
Click "Manage web applications".
Select the web application by clicking its name.
Select "Blocked File Types" from the ribbon.
Compare the list of blocked file types to those listed in the SSP. If the SSP has file types that are not in the blocked file types list, this is a finding.
Repeat check for each web application.
M
4096