Check: WA000-WWA050 A24
Apache Server 2.4 Unix:
WA000-WWA050 A24
(in version v1 r1)
Title
All interactive programs must be placed in a designated directory with appropriate permissions. (Cat II impact)
Discussion
Directory options directives are directives that can be applied to further restrict access to file and directories. The Options directive controls which server features are available in a particular directory. The ExecCGI option controls the execution of CGI scripts using mod_cgi. This needs to be restricted to only the directory intended for script execution.
Check Content
Search for the unnecessary CGI programs which may be found in the directories configured with ScriptAlias, Script or other Script* directives. Often, CGI directories are named cgi-bin. Also, CGI AddHandler or SetHandler directives may also be in use for specific handlers such as perl, python and PHP. To search the httpd.conf file for Options enter the following command: find / -name httpd.conf -print -exec grep -H -i "Options" {} \; If the value for Options is returned with a ExecCGI (no +) this is a finding.
Fix Text
Locate any cgi-bin files and directories enabled in the Apache configuration via Script, ScriptAlias or other Script* directives. Remove the printenv default CGI in cgi-bin directory if it is installed. rm $APACHE_PREFIX/cgi-bin/printenv. Remove the test-cgi file from the cgi-bin directory if it is installed. rm $APACHE_PREFIX/cgi-bin/test-cgi. Review and remove any other cgi-bin files which are not needed for business purposes.
Additional Identifiers
Rule ID:
Vulnerability ID: V-13731
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |