II - Mission Support Sensitive
Rules and Groups employed by this XCCDF Profile
-
WG400
<GroupDescription></GroupDescription>Group -
All interactive programs must be placed in a designated directory with appropriate permissions.
<VulnDiscussion>CGI scripts represents one of the most common and exploitable means of compromising a web server. By definition, CGI are exec...Rule Medium Severity -
WG410
<GroupDescription></GroupDescription>Group -
Interactive scripts used on a web server must have proper access controls.
<VulnDiscussion>The use of CGI scripts represent one of the most common and exploitable means of compromising a web server. By definition, CG...Rule Medium Severity -
WG110
<GroupDescription></GroupDescription>Group -
The number of allowed simultaneous requests must be set.
<VulnDiscussion>Resource exhaustion can occur when an unlimited number of concurrent requests are allowed on a web site, facilitating a denia...Rule Medium Severity -
WG170
<GroupDescription></GroupDescription>Group -
Each readable web document directory must contain either a default, home, index, or equivalent file.
<VulnDiscussion>The goal is to completely control the web users experience in navigating any portion of the web document root directories. En...Rule Low Severity -
WG230
<GroupDescription></GroupDescription>Group -
Web server administration must be performed over a secure path or at the local console.
<VulnDiscussion>Logging into a web server remotely using an unencrypted protocol or service when performing updates and maintenance is a majo...Rule High Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Capacity
Modules