VCLD-67-000026 - VAMI must restrict access to the web root.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

As a rule, accounts on a web server are to be kept to a minimum, and those accounts are then restricted as to what they are allowed to access. The web root of the VAMI Lighttpd installation contains the content that is served up to the end user. This content must have the minimum necessary permissions and proper ownership to help protect against unprivileged modification of the content.

Solution

At the command prompt, execute the following commands:

# chmod 0755 <directory>
# chown root:root <directory>

Note: Substitute <directory> with each directory returned from the check.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_VMW_vSphere_6-7_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001082, Rule-ID|SV-239733r679309_rule, STIG-ID|VCLD-67-000026, Vuln-ID|V-239733

Plugin: Unix

Control ID: 349a431cd37ccf72c1a933c8e122f9a15cab68baa0f4fe2f5e7bccb7f792ecae