2.4 Ensure the Status Module Is Disabled

Information

The Apache 'mod_status' module provides current server performance statistics.

Rationale:

When 'mod_status' is loaded into the server, its handler capability is available in all configuration files, including per-directory files (e.g., '.htaccess'). The 'mod_status' module may provide an adversary with information that can be used to refine exploits that depend on measuring server load.

Solution

Perform either one of the following to disable the 'mod_status' module:
1. For source builds with static modules, run the Apache './configure' script with the '--disable-status configure' script options.

$ cd $DOWNLOAD_HTTPD
$ ./configure --disable-status

2. For dynamically loaded modules, comment out or remove the 'LoadModule' directive for the 'mod_status' module from the 'httpd.conf' file.

##LoadModule status_module modules/mod_status.so

See Also

https://workbench.cisecurity.org/files/2381

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: f81d5ba247ce5a8faea2a7c428a3282c3ed3b4699132af0aa5637378ff02d49b