3 | P a g e
2.8 Ensure 'credentials' are not stored in configuration files (Scored) .......................... 37
3 ASP.NET Configuration Recommendations ..................................................................................... 39
3.1 Ensure 'deployment method retail' is set (Scored) ......................................................... 39
3.2 Ensure 'debug' is turned off (Scored) ................................................................................... 41
3.3 Ensure custom error messages are not off (Scored) ...................................................... 43
3.4 Ensure IIS HTTP detailed errors are hidden from displaying remotely (Scored)
..................................................................................................................................................................... 45
3.5 Ensure ASP.NET stack tracing is not enabled (Scored) ................................................. 47
3.6 Ensure 'httpcookie' mode is configured for session state (Scored) ......................... 49
3.7 Ensure 'cookies' are set with HttpOnly attribute (Scored) .......................................... 51
3.8 Ensure 'MachineKey validation method - .Net 3.5' is configured (Scored) ........... 53
3.9 Ensure 'MachineKey validation method - .Net 4.5' is configured (Scored) ........... 55
3.10 Ensure global .NET trust level is configured (Scored) ................................................ 57
4 Request Filtering and Other Restriction Modules ........................................................................ 60
4.1 Ensure 'maxAllowedContentLength' is configured (Not Scored) .............................. 60
4.2 Ensure 'maxURL request filter' is configured (Scored) ................................................. 63
4.3 Ensure 'MaxQueryString request filter' is configured (Scored) ................................. 65
4.4 Ensure non-ASCII characters in URLs are not allowed (Scored) ............................... 67
4.5 Ensure Double-Encoded requests will be rejected (Scored) ....................................... 69
4.6 Ensure 'HTTP Trace Method' is disabled (Scored).......................................................... 71
4.7 Ensure Unlisted File Extensions are not allowed (Scored) .......................................... 73
4.8 Ensure Handler is not granted Write and Script/Execute (Scored) ......................... 75
4.9 Ensure 'notListedIsapisAllowed' is set to false (Scored) .............................................. 77
4.10 Ensure 'notListedCgisAllowed' is set to false (Scored) ............................................... 79
4.11 Ensure 'Dynamic IP Address Restrictions' is enabled (Not Scored) ...................... 81
5 IIS Logging Recommendations ............................................................................................................. 83
5.1 Ensure Default IIS web log location is moved (Scored) ................................................ 83
5.2 Ensure Advanced IIS logging is enabled (Scored) ........................................................... 85
5.3 Ensure 'ETW Logging' is enabled (Not Scored) ................................................................ 87
6 FTP Requests ............................................................................................................................................... 89
6.1 Ensure FTP requests are encrypted (Scored) ................................................................... 89