SV-40832r1_rule
V-13689
WG255
WG255 W22
CAT II
10
To ensure the integrity of the data that is being captured in the log files, ensure that only the members of the Auditors group, Administrators, and the user assigned to run the web server software is granted permissions to read the log files.
Determine permissions for log files
Find the httpd.conf configuration file to determine the location of the log files. The location is indicated at the "ServerRoot" directive. The log directory is a sub-directory under the ServerRoot.
ex. :\Apache Group\Apache2\logs or :\Apache Software Foundation\Apache2.2\logs
After locating the logs, use the Explorer to move to these files and examine their properties:
Properties >> Security >> Permissions.
Administrators: Read
Auditors: Full Control
Web Managers: Read
WebServer Account: Read/Write/Execute
If anyone other than the Auditors, Administrators, Web Managers, or the account that runs the web server has access to the log files, this is a finding.
V-13689
False
WG255 W22
Determine permissions for log files
Find the httpd.conf configuration file to determine the location of the log files. The location is indicated at the "ServerRoot" directive. The log directory is a sub-directory under the ServerRoot.
ex. :\Apache Group\Apache2\logs or :\Apache Software Foundation\Apache2.2\logs
After locating the logs, use the Explorer to move to these files and examine their properties:
Properties >> Security >> Permissions.
Administrators: Read
Auditors: Full Control
Web Managers: Read
WebServer Account: Read/Write/Execute
If anyone other than the Auditors, Administrators, Web Managers, or the account that runs the web server has access to the log files, this is a finding.
M
Web Administrator
161