2.3 Disable Managed Object Browser (MOB)

Information

The Managed Object Browser (MOB) is a web-based server application that lets you
examine objects that exist on the server side. This is installed and started automatically
when vCenter is installed.

*Rationale*

The managed object browser (MOB) provides a way to explore the object model used by
the VMkernel to manage the host; it enables configurations to be changed as well. This
interface is meant to be used primarily for debugging the vSphere SDK. Because there are
no access controls the MOB could also be used as a method to obtain information about a
host being targeted for unauthorized access.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

To implement the recommended configuration state, run the following ESXi shell
command-vim-cmd proxysvc/remove_service '/mob' 'httpsWithRedirect'

Note- You cannot disable the MOB while a host is in lockdown mode.

Impact-The MOB will no longer be available for diagnostics. Some 3rd party tools use this interface
to gather information. Testing should be done after disabling the MOB to verify 3rd party
applications are still functioning as expected.
To re-enable the MOB temporarily-vim-cmd proxysvc/add_np_service '/mob' httpsWithRedirect /var/run/vmware/proxy-mob

Default Value-The prescribed state is not the default state.

See Also

https://workbench.cisecurity.org/files/145

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|MP-2

Plugin: VMware

Control ID: 89eba83c0a7f2ccf5ba876dc4195ecc7a752f97262ad12a6b8c63e36ba1bfafc