Check: WA00505 W20
APACHE SERVER 2.0 for Windows:
WA00505 W20
(in version v1 r5)
Title
Web Distributed Authoring and Versioning (WebDAV) must be disabled. (Cat II impact)
Discussion
The Apache mod_dav and mod_dav_fs modules support WebDAV ('Web-based Distributed Authoring and Versioning') functionality for Apache. WebDAV is an extension to the HTTP protocol which allows clients to create, move, and delete files and resources on the web server. WebDAV is not widely used, and has serious security concerns as it may allow clients to modify unauthorized files on the web server. Therefore, the WebDav modules mod_dav and mod_dav_fs should be disabled.
Check Content
Open the httpd.conf file. Search for uncommented LoadModule dav_module, LoadModule dav_fs_module, and LoadModule dav_lock_module directive statements. If any of these statements are found uncommented, this is a finding.
Fix Text
Edit the httpd.conf file and remove, or comment out, the following modules statements: dav_module, dav_fs_module, and dav_lock_module. Restart the server.
Additional Identifiers
Rule ID: SV-36611r1_rule
Vulnerability ID: V-26287
Group Title: WA00505
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |