WA000-WWA066 A22 – The HTTP request line must be limited. Details Buffer overflow attacks are carried out by a malicious attacker sending amounts of data that the web server cannot...
WA00500 A22 – Active software modules must be minimized. Details Modules are the source of Apache httpd servers core and dynamic capabilities. Thus not every module available is needed...
WA00505 A22 – Web Distributed Authoring and Versioning (WebDAV) must be disabled. Details The Apache mod_dav and mod_dav_fs modules support WebDAV (‘Web-based Distributed Authoring and Versioning’) functionality for Apache. WebDAV is an...
WA00510 A22 – Web server status module must be disabled. Details The Apache mod_info module provides information on the server configuration via access to a /server-info URL location, while the...
WA00515 A22 – Automatic directory indexing must be disabled. Details To identify the type of web servers and versions software installed it is common for attackers to scan for...
WA00520 A22 – The web server must not be configured as a proxy server. Details The Apache proxy modules allow the server to act as a proxy (either forward or reverse proxy) of http...
WA00525 A22 – User specific directories must not be globally enabled. Details The UserDir directive must be disabled so that user home directories are not accessed via the web site with...
WA00530 A22 – The process ID (PID) file must be properly secured – config Details The PidFile directive sets the file path to the process ID file to which the server records the process...
WA00530 A22 – The process ID (PID) file must be properly secured – permissions Details The PidFile directive sets the file path to the process ID file to which the server records the process...
WA00540 A22 – The web server must be configured to explicitly deny access to the OS root – Order Details The Apache Directory directive allows for directory specific configuration of access controls and many other features and options. One...