WG310 - A Private web server responds to requests from public search engines. - 'IP address and domain name restrictions'

Information

Vulnerability Key: V0002260
IA Controls: ECLP-1 Least Privilege
Categories: 2.2 Least Privilege
Severity: Category II
Ref: WEB SERVER SECURITY TECHNICAL IMPLEMENTATION GUIDE Section 3.4, Web Site Administration Policies & Procedures
With Amendments and Corrections incorporated in red italics.
Search engines are constantly at work on the Internet. Search engines are augmented by agents,
often referred to as spiders or bots, that endeavor to capture and catalog web site content. In turn,
these search engines make the content they obtain and catalog available to any public web user. Such
information in the public domain defeats the purpose of a Limited or Certificate-based web server,
provides information to those not authorized access to the web site, and could provide clues of the
sites architecture to malicious parties.
NOTE: Review each web sites' list of granted and denied domains and ips to ensure restrictions are in place on the web server.

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-17

Plugin: Windows

Control ID: 73133886ce18fbf04d691b7c022c54c63930a75b1bac443f2b6ac295f8afecaf