SV-214244r612240_rule
V-214244
SRG-APP-000141-WSR-000082
AS24-U1-000310
CAT II
10
Determine the location of the "HTTPD_ROOT" directory and the "httpd.conf" file:
# httpd -V | egrep -i 'httpd_root|server_config_file'
-D HTTPD_ROOT="/etc/httpd"
-D SERVER_CONFIG_FILE="conf/httpd.conf"
Review "Script", "ScriptAlias" or "ScriptAliasMatch", and "ScriptInterpreterSource" directives.
Go into each directory and locate "cgi-bin" files. Remove any script that is not needed for application operation.
Ensure this process is documented and approved by the ISSO.
Determine the location of the "HTTPD_ROOT" directory and the "httpd.conf" file:
# httpd -V | egrep -i 'httpd_root|server_config_file'
-D HTTPD_ROOT="/etc/httpd"
-D SERVER_CONFIG_FILE="conf/httpd.conf"
Locate "cgi-bin" files and directories enabled in the Apache configuration via "Script", "ScriptAlias" or "ScriptAliasMatch", and "ScriptInterpreterSource" directives:
# cat /<path_to_file>/httpd.conf | grep -i "Script"
If any scripts are present that are not needed for application operation, this is a finding.
If this is not documented and approved by the Information System Security Officer (ISSO), this is a finding.
V-214244
False
AS24-U1-000310
Determine the location of the "HTTPD_ROOT" directory and the "httpd.conf" file:
# httpd -V | egrep -i 'httpd_root|server_config_file'
-D HTTPD_ROOT="/etc/httpd"
-D SERVER_CONFIG_FILE="conf/httpd.conf"
Locate "cgi-bin" files and directories enabled in the Apache configuration via "Script", "ScriptAlias" or "ScriptAliasMatch", and "ScriptInterpreterSource" directives:
# cat /<path_to_file>/httpd.conf | grep -i "Script"
If any scripts are present that are not needed for application operation, this is a finding.
If this is not documented and approved by the Information System Security Officer (ISSO), this is a finding.
M
3996