2.4 Ensure the Status Module Is Disabled

Information

The Apache 'mod_status' module provides current server performance statistics.

Rationale:

While having server performance status information available as a web page may be convenient, it's recommended that this module be disabled. When it is enabled, its handler capability is available in all configuration files, including per-directory files (e.g., '.htaccess'). This may have security-related ramifications.

Solution

Perform either one of the following to disable the 'mod_status' module:

1. For source builds with static modules, run the Apache './configure' script with the '--disable-status configure' script options.

$ cd $DOWNLOAD/httpd-2.2.22
$ ./configure --disable-status

2. For dynamically loaded modules, comment out or remove the 'LoadModule' directive for the 'mod_status' module from the 'httpd.conf' file.

##LoadModule status_module modules/mod_status.so

See Also

https://workbench.cisecurity.org/files/2378

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 6887b7cee5836a10c5648bc7c0b1fa6e8bddf178035118ed6897df57d6a57abd