WG230 - Web server administration will be performed over a secure path or at the console. - 'UserAuthentication - Enabled (registry check)'

Information

Vulnerability Key: V0002249
IA Controls: EBRU-1 Remote Access for User Functions
Categories: 8.1 Encrypted Data in Transit
Severity: Category I
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 3.5
Logging in to a web server via a telnet session or using http or ftp in order to perform updates and
maintenance is a major risk. In all such cases, userids and passwords are passed in the plain text.
Acquiring such account information over a network is routinely accomplished and made all the worse
by the fact that the account information so obtained is for privileged users. A secure shell service or
https needs to be installed and in use for these purposes. Another alternative is to administer the web
server from the console, which implies physical access to the server.

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17

Plugin: Windows

Control ID: 8d295d86bdef4c0c3eb5083eeecf85348d339384190a7d9e25dd9b61c119ca45