Skip to content

APACHE 2.2 Site for UNIX Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • WA00620

    <GroupDescription></GroupDescription>
    Group
  • WG360

    <GroupDescription></GroupDescription>
    Group
  • Symbolic links must not be used in the web content directory tree.

    &lt;VulnDiscussion&gt;A symbolic link allows a file or a directory to be referenced using a symbolic name raising a potential hazard if symbolic li...
    Rule High Severity
  • WG400

    <GroupDescription></GroupDescription>
    Group
  • All interactive programs (CGI) must be placed in a designated directory with appropriate permissions.

    &lt;VulnDiscussion&gt;CGI scripts represents one of the most common and exploitable means of compromising a web server. By definition, CGI are exec...
    Rule Medium Severity
  • WG110

    <GroupDescription></GroupDescription>
    Group
  • The number of allowed simultaneous requests must be set.

    &lt;VulnDiscussion&gt;Resource exhaustion can occur when an unlimited number of concurrent requests are allowed on a web site, facilitating a denia...
    Rule Medium Severity
  • WG170

    <GroupDescription></GroupDescription>
    Group
  • Each readable web document directory must contain either a default, home, index, or equivalent file.

    &lt;VulnDiscussion&gt;The goal is to completely control the web users experience in navigating any portion of the web document root directories. En...
    Rule Low Severity
  • WG230

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules