2.3 Ensure Managed Object Browser (MOB) is disabled

Information

The Managed Object Browser (MOB) is a web-based server application that lets you
examine objects that exist on the server side. This is installed and started automatically
when vCenter is installed.

*Rationale*

The MOB is meant to be used primarily for debugging the vSphere SDK. Because there are no access controls,
the MOB could also be used as a method to obtain information about a host being targeted for unauthorized access.

Solution

To disable the MOB, run the following ESXi shell command:

vim-cmd proxysvc/remove_service '/mob' 'httpsWithRedirect'

Additionally, the following PowerCLI command may be used:

Get-VMHost | Get-AdvancedSetting -Name
Config.HostAgent.plugins.solo.enableMob |Set-AdvancedSetting -value "false"

Note: You cannot disable the MOB while a host is in lockdown mode.

See Also

https://workbench.cisecurity.org/files/2168

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7, CSCv6|9.2

Plugin: VMware

Control ID: 0282320f98ce60186a3dde69bad8bc25f715498fed29a62f0e1d0c29cfefbf92