2.3 Ensure Managed Object Browser (MOB) is disabled

Information

The Managed Object Browser (MOB) is a web-based server application that lets you
examine objects that exist on the server side. This is installed and started automatically
when vCenter is installed.

*Rationale*

The MOB is meant to be used primarily for debugging the vSphere SDK. Because there are no access controls,
the MOB could also be used as a method to obtain information about a host being targeted for unauthorized access.

Solution

To disable the MOB, run the following ESXi shell command:

vim-cmd proxysvc/remove_service '/mob' 'httpsWithRedirect'

Additionally, the following PowerCLI command may be used:

Get-VMHost | Get-AdvancedSetting -Name
Config.HostAgent.plugins.solo.enableMob |Set-AdvancedSetting -value "false"

Note: You cannot disable the MOB while a host is in lockdown mode.

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.2

Plugin: VMware

Control ID: 66ae7057d727a8f1b7c1e9548e2a83e0ba96bd3cca70a4a0bba0e3a9feb40de1