Check: WG235 W22
APACHE SITE 2.0 for Windows:
WG235 W22
(in version v1 r5)
Title
Web Administrators must only use encrypted connections for Document Root directory uploads. (Cat I impact)
Discussion
Logging in to a web server via an unencrypted protocol or service, to upload documents to the web site, is a risk if proper encryption is not utilized to protect the data being transmitted. An encrypted protocol or service must be used for remote access to web administration tasks.
Check Content
Query the SA to determine if there is a process for the uploading of files to the web site. This process should include the requirement for the use of a secure encrypted logon and secure encrypted connection. If the remote users are uploading files without utilizing approved encryption methods, this is a finding.
Fix Text
Use only secure encrypted logons and connections for uploading files to the web site.
Additional Identifiers
Rule ID: SV-33131r1_rule
Vulnerability ID: V-13686
Group Title: WG235
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |