2.3 Ensure Managed Object Browser (MOB) is disabled

Information

The Managed Object Browser (MOB) is a web-based server application that lets you examine objects that exist on the server side, explore the object model used by the VM kernel to manage the host, and change configurations. It is installed and started automatically when vCenter is installed.

Rationale:

The MOB is meant to be used primarily for debugging the vSphere SDK. Because there are no access controls, the MOB could also be used as a method to obtain information about a host being targeted for unauthorized access.

Impact:

Some third-party tools may utilize the Managed Object Browser (MOB) meaning that disabling it will cause those tools to malfunction.

Solution

To disabled MOB, perform the following from the vSphere Web Client:

Select a host

Click Configure then expand System then select Advanced System Settings.

Click Edit then search for Config.HostAgent.plugins.solo.enableMob

Set the value to false.

Click OK.

Note: You cannot disable the MOB while a host is in lockdown mode.
Note 2: You must disable MOB from the vSphere interface not via the vim-cmd command.

See Also

https://workbench.cisecurity.org/benchmarks/12725

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|9.4

Plugin: VMware

Control ID: b6a7b3f7a31342d54b006a8a08a0d8a326ee4ec8dea152b2cd44bd9e30e23a91