Check: WG520 A24
Apache Server 2.4 Unix:
WG520 A24
(in version v1 r1)
Title
Web server and/or operating system information must be protected. (Cat III impact)
Discussion
The web server response header of an HTTP response can contain several fields of information including the requested HTML page. The information included in this response can be web server type and version, operating system and version, and ports associated with the web server. This provides the malicious user valuable information without the use of extensive tools.
Check Content
Enter the following command: find / -name httpd.conf -print -exec grep -H -i "ServerTokens" {} \; The directive ServerTokens must be set to "Prod" (ex. ServerTokens Prod). This directive controls whether Server response header field that is sent back to clients that includes a description of the OS-type of the server as well as information about compiled-in modules. If the web server or operating system information are sent to the client via the server response header or the directive does not exist, this is a finding. Note: The default value is set to Full.
Fix Text
Edit the httpd.conf file and ensure the ServerTokens directive is set to Prod.
Additional Identifiers
Rule ID:
Vulnerability ID: V-6724
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |