2.8 Ensure the Info Module Is Disabled

Information

The Apache 'mod_info' module provides information on the server configuration via access to a '/server-info' URL location.

Rationale:

While having server configuration information available as a web page may be convenient it's recommended that this module NOT be enabled.
Once 'mod_info' is loaded into the server, its handler capability is available in per-directory '.htaccess' files and can leak sensitive information from the configuration directives of other Apache modules such as system paths, usernames/passwords, database names, etc.

Solution

Perform either one of the following to disable the 'mod_info' module:

1. For source builds with static modules, run the Apache './configure' script without including the 'mod_info' in the '--enable-modules= configure' script options.

$ cd $DOWNLOAD_HTTPD
$ ./configure

2. For dynamically loaded modules, comment out or remove the 'LoadModule' directive for the 'mod_info' module from the 'httpd.conf' file.

##LoadModule info_module modules/mod_info.so

See Also

https://workbench.cisecurity.org/files/2381

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: 6f7c610a514cee4dd3ec9ded84d07bdeb71b14871ec8856a7d4d0ff764531ad5