WG235 W22 - Web Administrators must only use encrypted connections for Document Root directory uploads.

Information

Logging in to a web server via an unencrypted protocol or service, to upload documents to the web site, is a risk if proper encryption is not utilized to protect the data being transmitted. An encrypted protocol or service must be used for remote access to web administration tasks.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Use only secure encrypted logons and connections for uploading files to the web site.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apache_2-2_WIN_V1R13_STIG.zip

Item Details

References: CAT|I, Rule-ID|SV-33131r1_rule, STIG-ID|WG235_W22, Vuln-ID|V-13686

Plugin: Windows

Control ID: abcc81be0d2d20cea83e15aab8fc81c5b9c6db1f9914d4087772a1bbcf2d3bf3