SV-36699r1_rule
V-13687
WG237
WG237 A22
CAT II
10
Install anti-virus software on the system and set it to automatically scan new files that are introduced to the web server.
Remote web authors should not be able to upload files to the Document Root directory structure without virus checking and checking for malicious or mobile code.
Query the SA to determine if there is anti-virus software active on the server with auto-protect enabled, or if there is another process in place for the scanning of files being posted by remote authors.
If there is no virus software on the system with auto-protect enabled, or if there is not a process in place to ensure all files being posted are being virus scanned before being saved to the document root, this is a finding.
V-13687
False
WG237 A22
Remote web authors should not be able to upload files to the Document Root directory structure without virus checking and checking for malicious or mobile code.
Query the SA to determine if there is anti-virus software active on the server with auto-protect enabled, or if there is another process in place for the scanning of files being posted by remote authors.
If there is no virus software on the system with auto-protect enabled, or if there is not a process in place to ensure all files being posted are being virus scanned before being saved to the document root, this is a finding.
M
Web Administrator
161