2.2.10 Ensure HTTP server is not enabled

Information

Unless there is a need to run the system as a web server, it is recommended that the service be disabled to reduce the potential attack surface.

Solution

Run the following command to disable httpd - # chkconfig httpd offNotes-Several httpd servers exist and can use other service names. apache, apache2, lighttpd, and nginx are example services that provide an HTTP server. These and other services should also be audited.

See Also

https://workbench.cisecurity.org/files/1863

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: b7ad880dc84c378559667ac52a7388fffa5b86988b7ba8caa4766721834143bf