Network Management
Secure IIS by removing the default website
While deploying IIS to the Windows server, Default Web Site is deployed. This website contains known vulnerabilities. To further harden your SolarWinds deployment, complete steps described in the Resolution section.
First published date
Last published date
Overview
website to improve the security of your SolarWinds deployment.
The resolution addresses the following vulnerability: CVE-2022-21907 (© 2022 The MITRE Corporation, available at https://www.cve.org, obtained on November 17, 2022)
Product section
Cause
Resolution
Manual steps
- Create a backup of your Orion Servers.
- RDP to the server hosting SolarWinds Platform Web Console.
- Open Internet Information Services (IIS) Manager (Default location: %windir%\system32\inetsrv\InetMgr.exe).
- Expand the Server.
- Expand Sites.
- Right-click the Default Web Site, select Remove, and click Yes to remove the selected site.
- Select Application Pools.
- Right-click the DefaultAppPool, select Remove, and click Yes to remove the selected site.
- Open File Explorer and navigate to your website root folder (Default location: C:\inetpub\wwwroot).
- Remove all files and folders located in the folder.
Automated steps
- Create a backup of your Orion Servers.
- RDP to the server hosting SolarWinds Platform Web Console.
- Open PowerShell ISE as Administrator.
- Paste the following commands to Script Pane:
# Scripts are not supported under any SolarWinds support program or service. # Scripts are provided AS IS without warranty of any kind. SolarWinds further # disclaims all warranties including, without limitation, any implied warranties # of merchantability or of fitness for a particular purpose. The risk arising # out of the use or performance of the scripts and documentation stays with you. # In no event shall SolarWinds or anyone else involved in the creation, # production, or delivery of the scripts be liable for any damages whatsoever # (including, without limitation, damages for loss of business profits, business # interruption, loss of business information, or other pecuniary loss) arising # out of the use of or inability to use the scripts or documentation. #Requires -RunAsAdministrator cls $ws = Get-Website -Name "Default Web Site" # Web Site if ($ws) { $path = [System.Environment]::ExpandEnvironmentVariables($ws.physicalPath) $wap = Get-IISAppPool -Name $ws.applicationPool # Web Application Pool if ($ws.state -eq "Started") { Stop-Website -Name $ws.name Write-Host $ws.name " website has been Stopped." } Remove-Website -Name $ws.name Write-Host $ws.name " website has been removed from IIS." Remove-Item -Recurse -Path (Join-Path -Path $path -ChildPath "\*") -Force Write-Host "Files and subfolders from this location have been removed: " $path Clear-Variable -Name "ws" Clear-Variable -Name "path" if ($wap) { if ($wap.State -eq "Started") { Stop-WebAppPool -Name $wap.Name Write-Host $wap.Name " application pool has been Stopped." } Remove-WebAppPool -Name $wap.Name Write-Host $wap.Name " application pool has been removed from IIS." Clear-Variable -Name "wap" } }
- Execute the Commands from Script Pane by selecting Debug > Run/Continue.