| Hostname | IP Address | Status | Assigned To | Last Scan | Actions |
|---|---|---|---|---|---|
| MONT-DP-001 | 164.231.187.44 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-IIS10_0_Site_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: Site: Default Web Site ResultHash: 964A425E614B45D739FF9628D93B9C7268F1E643 ~~~~~ Access Policy: Read,Script Enabled Handler Mappings: ----------------------------------- Name: TRACEVerbHandler Path: * State: Enabled PathType: Unspecified Handler: ProtocolSupportModule ReqAccess: None Name: OPTIONSVerbHandler Path: * State: Enabled PathType: Unspecified Handler: ProtocolSupportModule ReqAccess: None Name: StaticFile Path: * State: Enabled PathType: File or Folder Handler: StaticFileModule,DefaultDocumentModule,DirectoryListingModule ReqAccess: Read Disabled Handler Mappings: ----------------------------------- Name: ISAPI-dll Path: *.dll State: Disabled PathType: File Handler: IsapiModule ReqAccess: Execute Comments |
|||||
| MONT-MB-002 | 164.231.187.36 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-IIS10_0_Site_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: Site: Exchange Back End ResultHash: 8356F37642CEDEB903ECD7759F6B764F91491675 ~~~~~ Access Policy: Read,Script Enabled Handler Mappings: ----------------------------------- Name: xamlx-ISAPI-4.0_64bit Path: *.xamlx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: xamlx-ISAPI-4.0_32bit Path: *.xamlx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: xamlx-Integrated-4.0 Path: *.xamlx State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: rules-ISAPI-4.0_64bit Path: *.rules State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: rules-ISAPI-4.0_32bit Path: *.rules State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: rules-Integrated-4.0 Path: *.rules State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: xoml-ISAPI-4.0_64bit Path: *.xoml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: xoml-ISAPI-4.0_32bit Path: *.xoml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: xoml-Integrated-4.0 Path: *.xoml State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: svc-ISAPI-4.0_64bit Path: *.svc State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: svc-ISAPI-4.0_32bit Path: *.svc State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: svc-Integrated-4.0 Path: *.svc State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: AXD-ISAPI-4.0_64bit Path: *.axd State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: PageHandlerFactory-ISAPI-4.0_64bit Path: *.aspx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: SimpleHandlerFactory-ISAPI-4.0_64bit Path: *.ashx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: WebServiceHandlerFactory-ISAPI-4.0_64bit Path: *.asmx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: HttpRemotingHandlerFactory-rem-ISAPI-4.0_64bit Path: *.rem State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: HttpRemotingHandlerFactory-soap-ISAPI-4.0_64bit Path: *.soap State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: aspq-ISAPI-4.0_64bit Path: *.aspq State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: cshtm-ISAPI-4.0_64bit Path: *.cshtm State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: cshtml-ISAPI-4.0_64bit Path: *.cshtml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: vbhtm-ISAPI-4.0_64bit Path: *.vbhtm State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: vbhtml-ISAPI-4.0_64bit Path: *.vbhtml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: TraceHandler-Integrated-4.0 Path: trace.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: WebAdminHandler-Integrated-4.0 Path: WebAdmin.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: AssemblyResourceLoader-Integrated-4.0 Path: WebResource.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: PageHandlerFactory-Integrated-4.0 Path: *.aspx State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: SimpleHandlerFactory-Integrated-4.0 Path: *.ashx State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: WebServiceHandlerFactory-Integrated-4.0 Path: *.asmx State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: HttpRemotingHandlerFactory-rem-Integrated-4.0 Path: *.rem State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: HttpRemotingHandlerFactory-soap-Integrated-4.0 Path: *.soap State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: aspq-Integrated-4.0 Path: *.aspq State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: cshtm-Integrated-4.0 Path: *.cshtm State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: cshtml-Integrated-4.0 Path: *.cshtml State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: vbhtm-Integrated-4.0 Path: *.vbhtm State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: vbhtml-Integrated-4.0 Path: *.vbhtml State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: ScriptHandlerFactoryAppServices-Integrated-4.0 Path: *_AppService.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: ScriptResourceIntegrated-4.0 Path: *ScriptResource.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: AXD-ISAPI-4.0_32bit Path: *.axd State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: PageHandlerFactory-ISAPI-4.0_32bit Path: *.aspx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: SimpleHandlerFactory-ISAPI-4.0_32bit Path: *.ashx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: WebServiceHandlerFactory-ISAPI-4.0_32bit Path: *.asmx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: HttpRemotingHandlerFactory-rem-ISAPI-4.0_32bit Path: *.rem State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: HttpRemotingHandlerFactory-soap-ISAPI-4.0_32bit Path: *.soap State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: aspq-ISAPI-4.0_32bit Path: *.aspq State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: cshtm-ISAPI-4.0_32bit Path: *.cshtm State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: cshtml-ISAPI-4.0_32bit Path: *.cshtml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: vbhtm-ISAPI-4.0_32bit Path: *.vbhtm State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: vbhtml-ISAPI-4.0_32bit Path: *.vbhtml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: TRACEVerbHandler Path: * State: Enabled PathType: Unspecified Handler: ProtocolSupportModule ReqAccess: None Name: OPTIONSVerbHandler Path: * State: Enabled PathType: Unspecified Handler: ProtocolSupportModule ReqAccess: None Name: ExtensionlessUrlHandler-ISAPI-4.0_32bit Path: *. State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: ExtensionlessUrlHandler-ISAPI-4.0_64bit Path: *. State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: ExtensionlessUrlHandler-Integrated-4.0 Path: *. State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: StaticFile Path: * State: Enabled PathType: File or Folder Handler: StaticFileModule,DefaultDocumentModule,DirectoryListingModule ReqAccess: Read Disabled Handler Mappings: ----------------------------------- Name: ISAPI-dll Path: *.dll State: Disabled PathType: File Handler: IsapiModule ReqAccess: Execute Comments |
|||||
| MONT-MB-002 | 164.231.187.36 | 2026-01-14 | |||
Finding DetailsEvaluate-STIG 1.2507.5 (Scan-IIS10_0_Site_Checks) was unable to determine a Status but found the below configuration on 10/23/2025: Site: Default Web Site ResultHash: 8356F37642CEDEB903ECD7759F6B764F91491675 ~~~~~ Access Policy: Read,Script Enabled Handler Mappings: ----------------------------------- Name: xamlx-ISAPI-4.0_64bit Path: *.xamlx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: xamlx-ISAPI-4.0_32bit Path: *.xamlx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: xamlx-Integrated-4.0 Path: *.xamlx State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: rules-ISAPI-4.0_64bit Path: *.rules State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: rules-ISAPI-4.0_32bit Path: *.rules State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: rules-Integrated-4.0 Path: *.rules State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: xoml-ISAPI-4.0_64bit Path: *.xoml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: xoml-ISAPI-4.0_32bit Path: *.xoml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: xoml-Integrated-4.0 Path: *.xoml State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: svc-ISAPI-4.0_64bit Path: *.svc State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: svc-ISAPI-4.0_32bit Path: *.svc State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: svc-Integrated-4.0 Path: *.svc State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: AXD-ISAPI-4.0_64bit Path: *.axd State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: PageHandlerFactory-ISAPI-4.0_64bit Path: *.aspx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: SimpleHandlerFactory-ISAPI-4.0_64bit Path: *.ashx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: WebServiceHandlerFactory-ISAPI-4.0_64bit Path: *.asmx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: HttpRemotingHandlerFactory-rem-ISAPI-4.0_64bit Path: *.rem State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: HttpRemotingHandlerFactory-soap-ISAPI-4.0_64bit Path: *.soap State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: aspq-ISAPI-4.0_64bit Path: *.aspq State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: cshtm-ISAPI-4.0_64bit Path: *.cshtm State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: cshtml-ISAPI-4.0_64bit Path: *.cshtml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: vbhtm-ISAPI-4.0_64bit Path: *.vbhtm State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: vbhtml-ISAPI-4.0_64bit Path: *.vbhtml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: TraceHandler-Integrated-4.0 Path: trace.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: WebAdminHandler-Integrated-4.0 Path: WebAdmin.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: AssemblyResourceLoader-Integrated-4.0 Path: WebResource.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: PageHandlerFactory-Integrated-4.0 Path: *.aspx State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: SimpleHandlerFactory-Integrated-4.0 Path: *.ashx State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: WebServiceHandlerFactory-Integrated-4.0 Path: *.asmx State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: HttpRemotingHandlerFactory-rem-Integrated-4.0 Path: *.rem State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: HttpRemotingHandlerFactory-soap-Integrated-4.0 Path: *.soap State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: aspq-Integrated-4.0 Path: *.aspq State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: cshtm-Integrated-4.0 Path: *.cshtm State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: cshtml-Integrated-4.0 Path: *.cshtml State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: vbhtm-Integrated-4.0 Path: *.vbhtm State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: vbhtml-Integrated-4.0 Path: *.vbhtml State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: ScriptHandlerFactoryAppServices-Integrated-4.0 Path: *_AppService.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: ScriptResourceIntegrated-4.0 Path: *ScriptResource.axd State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: AXD-ISAPI-4.0_32bit Path: *.axd State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: PageHandlerFactory-ISAPI-4.0_32bit Path: *.aspx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: SimpleHandlerFactory-ISAPI-4.0_32bit Path: *.ashx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: WebServiceHandlerFactory-ISAPI-4.0_32bit Path: *.asmx State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: HttpRemotingHandlerFactory-rem-ISAPI-4.0_32bit Path: *.rem State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: HttpRemotingHandlerFactory-soap-ISAPI-4.0_32bit Path: *.soap State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: aspq-ISAPI-4.0_32bit Path: *.aspq State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: cshtm-ISAPI-4.0_32bit Path: *.cshtm State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: cshtml-ISAPI-4.0_32bit Path: *.cshtml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: vbhtm-ISAPI-4.0_32bit Path: *.vbhtm State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: vbhtml-ISAPI-4.0_32bit Path: *.vbhtml State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: TRACEVerbHandler Path: * State: Enabled PathType: Unspecified Handler: ProtocolSupportModule ReqAccess: None Name: OPTIONSVerbHandler Path: * State: Enabled PathType: Unspecified Handler: ProtocolSupportModule ReqAccess: None Name: ExtensionlessUrlHandler-ISAPI-4.0_32bit Path: *. State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: ExtensionlessUrlHandler-ISAPI-4.0_64bit Path: *. State: Enabled PathType: Unspecified Handler: IsapiModule ReqAccess: Script Name: ExtensionlessUrlHandler-Integrated-4.0 Path: *. State: Enabled PathType: Unspecified Handler: ManagedPipelineHandler ReqAccess: Script Name: StaticFile Path: * State: Enabled PathType: File or Folder Handler: StaticFileModule,DefaultDocumentModule,DirectoryListingModule ReqAccess: Read Disabled Handler Mappings: ----------------------------------- Name: ISAPI-dll Path: *.dll State: Disabled PathType: File Handler: IsapiModule ReqAccess: Execute Comments |
|||||
Check Text
Note: If the server being reviewed is hosting SharePoint, this is not applicable. For Handler Mappings, the ISSO must document and approve all allowable scripts the website allows (whitelist) and denies (blacklist). The whitelist and blacklist will be compared to the Handler Mappings in IIS 10.0. Handler Mappings at the site level take precedence over Handler Mappings at the server level. Open the IIS 10.0 Manager. Click the site name under review. Double-click "Handler Mappings". If any script file extensions from the blacklist are enabled, this is a finding.
Fix Text
Open the IIS 10.0 Manager. Click the site name under review. Double-click "Handler Mappings". Remove any script file extensions listed on the black list that are enabled. Select "Apply" from the "Actions" pane.