Security vulnerability states Microsoft IIS default installation/welcome page installed on Director

Security vulnerability states Microsoft IIS default installation/welcome page installed on Director

book

Article ID: CTX550423

calendar_today

Updated On:

Description

Security vulnerability indicates that Microsoft IIS default installation/welcome page installed on Director
Vulnerability Title:Microsoft IIS default installation/welcome page installed
Vulnerability Description:The IIS default installation or "Welcome" page is installed on this server. This usually indicates a newly installed server which has not yet been configured properly and which may not be known about.

In many cases, IIS is installed by default and the user may not be aware that the web server is running. These servers are rarely patched and rarely monitored, providing hackers with a convenient target that is not likely to trip any alarms.

Vulnerability Proof:* Running HTTPS service

* Product IIS exists -- Microsoft IIS

HTTP GET request to 
HTTP response code was an expected 200
HTTP header 'Content-Location' not present
HTTP response code was an expected 200HTTP response code was an expected 200HTTP response code was an expected 200HTTP response code was an expected 200HTTP response code was an expected 200HTTP response code was an expected 200HTTP response code was an expected 200HTTP response code was an expected 200
1: <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN""http://ww... 2: <html xmlns="http://www.w3.org/1999/xhtml"> 3: <head> 4: IIS Windows Server</title>

Customer try to disable the default.htm in default document on IIS, but Director can't open successfully after that

Environment

Citrix is not responsible for and does not endorse or accept any responsibility for the contents or your use of these third party Web sites. Citrix is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement by Citrix of the linked Web site. It is your responsibility to take precautions to ensure that whatever Web site you use is free of viruses or other harmful items.

Resolution

Following https://carlwebster.com/make-dirtector-default-page-within-iis/ to make Director as the default page on IIS