Skip to content

III - Administrative Public

Rules and Groups employed by this XCCDF Profile

  • WG400

    <GroupDescription></GroupDescription>
    Group
  • All interactive programs must be placed in a designated directory with appropriate permissions.

    &lt;VulnDiscussion&gt;CGI scripts represents one of the most common and exploitable means of compromising a web server. By definition, CGI are exec...
    Rule Medium Severity
  • WG410

    <GroupDescription></GroupDescription>
    Group
  • Interactive scripts used on a web server must have proper access controls.

    &lt;VulnDiscussion&gt;The use of CGI scripts represent one of the most common and exploitable means of compromising a web server. By definition, CG...
    Rule Medium Severity
  • WG110

    <GroupDescription></GroupDescription>
    Group
  • The number of allowed simultaneous requests must be set.

    &lt;VulnDiscussion&gt;Resource exhaustion can occur when an unlimited number of concurrent requests are allowed on a web site, facilitating a denia...
    Rule Medium Severity
  • WG170

    <GroupDescription></GroupDescription>
    Group
  • Each readable web document directory must contain either a default, home, index, or equivalent file.

    &lt;VulnDiscussion&gt;The goal is to completely control the web users experience in navigating any portion of the web document root directories. En...
    Rule Low Severity
  • WG230

    <GroupDescription></GroupDescription>
    Group
  • Web server administration must be performed over a secure path or at the local console.

    &lt;VulnDiscussion&gt;Logging into a web server remotely using an unencrypted protocol or service when performing updates and maintenance is a majo...
    Rule High Severity
  • WG240

    <GroupDescription></GroupDescription>
    Group
  • Logs of web server access and errors must be established and maintained.

    &lt;VulnDiscussion&gt;A major tool in exploring the web site use, attempted use, unusual conditions, and problems are reported in the access and er...
    Rule Medium Severity
  • WG250

    <GroupDescription></GroupDescription>
    Group
  • Log file access must be restricted to System Administrators, Web Administrators or Auditors.

    &lt;VulnDiscussion&gt;A major tool in exploring the web site use, attempted use, unusual conditions and problems are the access and error logs. In ...
    Rule Medium Severity
  • WG260

    <GroupDescription></GroupDescription>
    Group
  • Only web sites that have been fully reviewed and tested must exist on a production web server.

    &lt;VulnDiscussion&gt;In the case of a production web server, areas for content development and testing will not exist, as this type of content is ...
    Rule Medium Severity
  • WG290

    <GroupDescription></GroupDescription>
    Group
  • The web client account access to the content and scripts directories must be limited to read and execute.

    &lt;VulnDiscussion&gt;Excessive permissions for the anonymous web user account are one of the most common faults contributing to the compromise of ...
    Rule High Severity
  • WG310

    <GroupDescription></GroupDescription>
    Group
  • A web site must not contain a robots.txt file.

    &lt;VulnDiscussion&gt;Search engines are constantly at work on the Internet. Search engines are augmented by agents, often referred to as spiders ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules