Network Management

Secure IIS by removing the default website

While deploying IIS to the Windows server, Default Web Site is deployed. This website contains known vulnerabilities. To further harden your SolarWinds deployment, complete steps described in the Resolution section.

First published date

11/23/2022 7:11 AM

Last published date

11/23/2022 7:11 AM

Overview

Complete the manual steps or run the PowerShell script to remove the Default Web Site, DefaultAppPool, and files located in the hosting directory of the Default Web Site
website to improve the security of your SolarWinds deployment.

The resolution addresses the following vulnerability: CVE-2022-21907 (© 2022 The MITRE Corporation, available at https://www.cve.org, obtained on November 17, 2022)

Product section

Network Performance Monitor

Cause

While deploying SolarWinds Platform Main Polling Engine, Additional Web Server, or EOC on a new server, IIS is installed. Default Web Site is deployed while the IIS is installed.
 

Resolution

Manual steps

  1. Create a backup of your Orion Servers.
  2. RDP to the server hosting SolarWinds Platform Web Console.
  3. Open Internet Information Services (IIS) Manager (Default location: %windir%\system32\inetsrv\InetMgr.exe).
  4. Expand the Server.
  5. Expand Sites.
  6. Right-click the Default Web Site, select Remove, and click Yes to remove the selected site.
  7. Select Application Pools.
  8. Right-click the DefaultAppPool, select Remove, and click Yes to remove the selected site.
  9. Open File Explorer and navigate to your website root folder (Default location: C:\inetpub\wwwroot).
  10. Remove all files and folders located in the folder.

Automated steps

  1. Create a backup of your Orion Servers.
  2. RDP to the server hosting SolarWinds Platform Web Console.
  3. Open PowerShell ISE as Administrator.
  4. Paste the following commands to Script Pane:
    # Scripts are not supported under any SolarWinds support program or service.
    # Scripts are provided AS IS without warranty of any kind. SolarWinds further
    # disclaims all warranties including, without limitation, any implied warranties
    # of merchantability or of fitness for a particular purpose. The risk arising
    # out of the use or performance of the scripts and documentation stays with you.
    # In no event shall SolarWinds or anyone else involved in the creation,
    # production, or delivery of the scripts be liable for any damages whatsoever
    # (including, without limitation, damages for loss of business profits, business
    # interruption, loss of business information, or other pecuniary loss) arising
    # out of the use of or inability to use the scripts or documentation.
    
    #Requires -RunAsAdministrator
     
    cls
    $ws = Get-Website -Name "Default Web Site"       # Web Site
     
    if ($ws) {
        $path = [System.Environment]::ExpandEnvironmentVariables($ws.physicalPath)
        $wap = Get-IISAppPool -Name $ws.applicationPool     # Web Application Pool
        if ($ws.state -eq "Started")
        {
            Stop-Website -Name $ws.name
            Write-Host $ws.name " website has been Stopped."
        }
       
        Remove-Website -Name $ws.name
        Write-Host $ws.name " website has been removed from IIS."
        Remove-Item -Recurse -Path (Join-Path -Path $path -ChildPath "\*") -Force
        Write-Host "Files and subfolders from this location have been removed: " $path
        Clear-Variable -Name "ws"
        Clear-Variable -Name "path"
     
        if ($wap)
        {
            if ($wap.State -eq "Started")
            {
                Stop-WebAppPool -Name $wap.Name
                Write-Host $wap.Name " application pool has been Stopped."
            }
            Remove-WebAppPool -Name $wap.Name
            Write-Host $wap.Name " application pool has been removed from IIS."
            Clear-Variable -Name "wap"
        }
    }
  5. Execute the Commands from Script Pane by selecting Debug > Run/Continue.