Item Search

NameAudit NamePluginCategory
2.4 Disable X-Powered-By HTTP Header and Rename the Server Value for all ConnectorsCIS Apache Tomcat 10.1 v1.1.0 L2Unix

CONFIGURATION MANAGEMENT

2.4 Disable X-Powered-By HTTP Header and Rename the Server Value for all ConnectorsCIS Apache Tomcat 9 L2 v1.2.0 MiddlewareUnix

CONFIGURATION MANAGEMENT

WA000-WWA020 A22 - The Timeout directive must be properly set.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA022 A22 - The KeepAlive directive must be enabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA024 A22 - The KeepAliveTimeout directive must be defined.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA026 A22 - The httpd.conf StartServers directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA028 A22 - The httpd.conf MinSpareServers directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WWA032 A22 - The httpd.conf MaxClients directive must be set properly.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND COMMUNICATIONS PROTECTION

WA000-WWA050 A22 - All interactive programs must be placed in a designated directory with appropriate permissions - printenvDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA052 A22 - The '-FollowSymLinks' setting must be disabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - -+IncludesNOEXEC|-IncludesDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - +IncludesDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA000-WWA054 A22 - Server side includes (SSIs) must run with execution capability disabled - NoneDISA STIG Apache Server 2.2 Unix v1r11Unix
WA000-WWA058 A22 - Directory indexing must be disabled on directories not containing index files.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA000-WWA066 A22 - The HTTP request line must be limited.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA060 A22 - A public web server, if hosted on the NIPRNet, must be isolated in an accredited DoD DMZ Extension.DISA STIG Apache Server 2.2 Unix v1r11Unix
WA120 A22 - Administrative users and groups that have access rights to the web server must be documented.DISA STIG Apache Server 2.2 Unix v1r11Unix
WA230 A22 - The Web site software used with the web server must have all applicable security patches applied and documented.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND INFORMATION INTEGRITY

WA00530 A22 - The process ID (PID) file must be properly secured - permissionsDISA STIG Apache Server 2.2 Unix v1r11Unix
WA00535 A22 - The score board file must be properly secured.DISA STIG Apache Server 2.2 Unix v1r11Unix
WA00540 A22 - The web server must be configured to explicitly deny access to the OS root - DenyDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA00545 A22 - Web server options for the OS root must be disabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00547 A22 - The ability to override the access configuration for the OS root directory must be disabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WA00555 A22 - The web server must be configured to listen on a specific IP address and port - [::ffff:0.0.0.0]:80DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00555 A22 - The web server must be configured to listen on a specific IP address and port - 0.0.0.0:80DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00555 A22 - The web server must be configured to listen on a specific IP address and port - listenDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00565 A22 - HTTP request methods must be limited - DenyDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WA00565 A22 - HTTP request methods must be limited - OrderDISA STIG Apache Server 2.2 Unix v1r11Unix
WG040 A22 - Public web server resources must not be shared with private assets.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG050 A22 - The web server password(s) must be entrusted to the SA or Web Manager.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG080 A22 - Installation of a compiler on production web server is prohibited.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG130 A22 - All utility programs, not necessary for operations, must be removed or disabled.DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG145 A22 - The private web server must use an approved DoD certificate validation process.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG190 A22 - Web server software must be a vendor-supported version.DISA STIG Apache Server 2.2 Unix v1r11Unix

SYSTEM AND INFORMATION INTEGRITY

WG200 A22 - Administrators must be the only users allowed access to the directory tree, the shell, or other operating system functions and utilities.DISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WG204 A22 - A web server must be segregated from other services.DISA STIG Apache Server 2.2 Unix v1r11Unix
WG220 A22 - Web administration tools must be restricted to the web manager and the web manager's designees - AccessConfigDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WG220 A22 - Web administration tools must be restricted to the web manager and the web manager's designees - ResourceConfigDISA STIG Apache Server 2.2 Unix v1r11Unix

ACCESS CONTROL

WG270 A22 - The web server's htpasswd files (if present) must reflect proper ownership and permissionsDISA STIG Apache Server 2.2 Unix v1r11Unix
WG300 A22 - Web server system files must conform to minimum file permission requirements - apache binDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - apache bin/*DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - cgi_binDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - cgi_bin/*DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - configDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - config/*DISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - document rootDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG300 A22 - Web server system files must conform to minimum file permission requirements - logsDISA STIG Apache Server 2.2 Unix v1r11 MiddlewareUnix

CONFIGURATION MANAGEMENT

WG330 A22 - A public web server must limit email to outbound only - netstatDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG370 A22 - MIME types for csh or sh shell programs must be disabled - AddHandlerDISA STIG Apache Server 2.2 Unix v1r11Unix

CONFIGURATION MANAGEMENT

WG440 A22 - Monitoring software must include CGI or equivalent programs in its scope.DISA STIG Apache Server 2.2 Unix v1r11Unix