STIGQter STIGQter: STIG Summary: Apache Server 2.4 Windows Server Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 23 Oct 2020:

The Apache web server must be protected from being stopped by a non-privileged user.

DISA Rule

SV-214353r505936_rule

Vulnerability Number

V-214353

Group Title

SRG-APP-000435-WSR-000147

Rule Version

AS24-W1-000820

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Restrict access to the web administration tool to only the Web Manager and the Web Manager's designees.

Check Contents

Right-click <'Install Path'>\bin\httpd.exe.

Click "Properties" from the "Context" menu.

Select the "Security" tab.

Review the groups and user names.

The following account may have Full control privileges:

TrustedInstaller
Web Managers
Web Manager designees

The following accounts may have read and execute, or read permissions:

Non Web Manager Administrators
ALL APPLICATION PACKAGES (built-in security group)
SYSTEM
Users

Specific users may be granted read and execute and read permissions.

Compare the local documentation authorizing specific users against the users observed when reviewing the groups and users.

If any other access is observed, this is a finding.

Vulnerability Number

V-214353

Documentable

False

Rule Version

AS24-W1-000820

Severity Override Guidance

Right-click <'Install Path'>\bin\httpd.exe.

Click "Properties" from the "Context" menu.

Select the "Security" tab.

Review the groups and user names.

The following account may have Full control privileges:

TrustedInstaller
Web Managers
Web Manager designees

The following accounts may have read and execute, or read permissions:

Non Web Manager Administrators
ALL APPLICATION PACKAGES (built-in security group)
SYSTEM
Users

Specific users may be granted read and execute and read permissions.

Compare the local documentation authorizing specific users against the users observed when reviewing the groups and users.

If any other access is observed, this is a finding.

Check Content Reference

M

Target Key

3998

Comments