4.4 Ensure http server is not running

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Web serving should not be done from a user desktop. Dedicated webservers or appropriate cloud storage should be used. Open ports make it easier to exploit the computer.

Solution

Ensure that the Web Server is not running and is not set to start at boot
Stop the Web Server
sudo apachectl stop
Ensure that the web server will not auto-start at boot
sudo defaults write /System/Library/LaunchDaemons/org.apache.httpd Disabled -bool true

See Also

https://benchmarks.cisecurity.org/tools2/osx/CIS_Apple_OSX_10.11_Benchmark_v1.0.0.pdf

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6, CSCv6|3.1

Plugin: Unix

Control ID: 063e7572d77998de9b59ca26845c0b75ec5538e8d44ae503c019528e846f8a17