OH12-1X-000208 - A production OHS Installation must prohibit the installation of a compiler.

Information

The presence of a compiler on a production server facilitates the malicious user's task of creating custom versions of programs and installing Trojan Horses or viruses. For example, the attacker's code can be uploaded and compiled on the server under attack.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Ask the System Administrator to remove any compilers installed on the system.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_HTTP_Server_12-1-3_V2R3_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-221446r961863_rule, STIG-ID|OH12-1X-000208, STIG-Legacy|SV-79145, STIG-Legacy|V-64655, Vuln-ID|V-221446

Plugin: Unix

Control ID: 6e31ea6db98eea809e2663fa0be512b13d0b880227d89264643776af3e66eb6b