Check: SRG-APP-000141-WSR-000076
Web Server SRG:
SRG-APP-000141-WSR-000076
(in versions v4 r2 through v2 r2)
Title
The web server must not be a proxy server. (Cat II impact)
Discussion
A web server should be primarily a web server or a proxy server but not both, for the same reasons that other multi-use servers are not recommended. Scanning for web servers that will also proxy requests into an otherwise protected network is a very common attack making the attack anonymous.
Check Content
Review the web server documentation and deployed configuration to determine if the web server is also a proxy server. If the web server is also acting as a proxy server, this is a finding.
Fix Text
Uninstall any proxy services, modules, and libraries that are used by the web server to act as a proxy server. Verify all configuration changes are made to assure the web server is no longer acting as a proxy server in any manner.
Additional Identifiers
Rule ID: SV-206376r960963_rule
Vulnerability ID: V-206376
Group Title: SRG-APP-000141
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000381 |
Configure the system to provide only organization-defined mission essential capabilities. |
Controls
Number | Title |
---|---|
CM-7 |
Least Functionality |