2.4 Ensure the Status Module Is Disabled

Information

The Apache 'mod_status' module provides current server performance statistics.

Rationale:

While having server performance status information available as a web page may be convenient, it's recommended that this module be disabled. When it is enabled, its handler capability is available in all configuration files, including per-directory files (e.g., '.htaccess'). This may have security-related ramifications.

Solution

Perform either one of the following to disable the 'mod_status' module:

1. For source builds with static modules, run the Apache './configure' script with the '--disable-status configure' script options.

$ cd $DOWNLOAD/httpd-2.2.22
$ ./configure --disable-status

2. For dynamically loaded modules, comment out or remove the 'LoadModule' directive for the 'mod_status' module from the 'httpd.conf' file.

##LoadModule status_module modules/mod_status.so

See Also

https://workbench.cisecurity.org/files/2378

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-4, CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 386919333b97aa076b67d79370d6375e16a9de79cb46aa0ad04f1efcbc01f832