AS24-W1-000670 – The Apache web server must restrict inbound connections from nonsecure zones. Details Remote access to the Apache web server is any access that communicates through an external, non-organization-controlled network. Remote access...
AS24-W1-000680 – The Apache web server must be configured to immediately disconnect or disable remote access to the hosted applications. Details During an attack on the Apache web server or any of the hosted applications, the system administrator may need...
AS24-W1-000530 – The Apache web server must generate unique session identifiers with definable entropy – SSLRandomSeed startup Details Generating a session identifier (ID) that is not easily guessed through brute force is essential to deter several types...
AS24-W1-000550 – The Apache web server must be built to fail to a known safe state if system initialization fails, shutdown fails, or aborts fail. Details Determining a safe state for failure and weighing that against a potential DoS for users depends on what type...
AS24-W1-000580 – The Apache web server document directory must be in a separate partition from the Apache web servers system files. Details A web server is used to deliver content on the request of a client. The content delivered to a...
AS24-W1-000590 – The Apache web server must restrict the ability of users to launch denial-of-service (DoS) attacks against other information systems or networks. Details Apache web server can limit the ability of the web server being used in a DoS attack through several...
AS24-W1-000620 – Warning and error messages displayed to clients must be modified to minimize the identity of the Apache web server, patches, loaded modules, and directory paths. Details Information needed by an attacker to begin looking for possible vulnerabilities in a web server includes any information about...
AS24-W1-000630 – Debugging and trace information used to diagnose the Apache web server must be disabled. Details Information needed by an attacker to begin looking for possible vulnerabilities in a web server includes any information about...
AS24-W1-000640 – The Apache web server must set an absolute timeout for sessions. Details Leaving sessions open indefinitely is a major security risk. An attacker can easily use an already authenticated session to...
AS24-W1-000650 – The Apache web server must set an inactive timeout for completing the TLS handshake – mod_reqtimeout Details Leaving sessions open indefinitely is a major security risk. An attacker can easily use an already authenticated session to...