1. Home
  2. Security Hardening
  3. DISA STIG Apache Site 2.2 Windows V1R13
  4. WG290 W22 – The web client account access to the content and scripts directories must be limited to read and execute. – ‘Alias’

WG290 W22 – The web client account access to the content and scripts directories must be limited to read and execute. – ‘Alias’

Details

Excessive permissions for the anonymous web user account are one of the most common faults contributing to the compromise of a web server. If this user is able to upload and execute files on the web server, the organization or owner of the server will no longer have control of the asset.

Solution

Assign the appropriate permissions to the applicable directories and files.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: Access Control, Configuration Management.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles