SV-36641r1_rule
V-2270
WG430
WG430 A22
CAT II
10
If the CGI, the cgi-bin, or the cgi-shl directories can be accessed via FTP by any group or user that does not require access, remove permissions to such directories for all but the web administrators and the SAs. Ensure that any such access employs an encrypted connection.
Locate the directories containing the CGI scripts. These directories should be language-specific (e.g., PERL, ASP, JS, JSP, etc.).
Using ls –al, examine the file permissions on the CGI, the cgi-bin, and the cgi-shl directories.
Anonymous FTP users must not have access to these directories.
If the CGI, the cgi-bin, or the cgi-shl directories can be accessed by any group that does not require access, this is a finding.
V-2270
False
WG430 A22
Locate the directories containing the CGI scripts. These directories should be language-specific (e.g., PERL, ASP, JS, JSP, etc.).
Using ls –al, examine the file permissions on the CGI, the cgi-bin, and the cgi-shl directories.
Anonymous FTP users must not have access to these directories.
If the CGI, the cgi-bin, or the cgi-shl directories can be accessed by any group that does not require access, this is a finding.
M
Web Administrator
161