SV-33180r1_rule
V-26323
WA00540
WA00540 W22
CAT II
10
Add the following after the root directory directive:
Order deny,allow
Deny from all
Locate the Apache httpd.conf file.
Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: Directory
For every root directory entry (i.e. <Directory />) ensure the following exists after it:
Order deny,allow
Deny from all
If the statement above is not found in the root directory statement, this is a finding. If Allow directives are included in the root directory statement, this is a finding. If the root directory statement isn't found at all, this is a finding.
V-26323
False
WA00540 W22
Locate the Apache httpd.conf file.
Open the httpd.conf file with an editor such as notepad, and search for the following uncommented directive: Directory
For every root directory entry (i.e. <Directory />) ensure the following exists after it:
Order deny,allow
Deny from all
If the statement above is not found in the root directory statement, this is a finding. If Allow directives are included in the root directory statement, this is a finding. If the root directory statement isn't found at all, this is a finding.
M
Web Administrator
158