WG210 W22 - Web content directories must not be anonymously shared.

Information

Sharing of web server content is a security risk when a web server is involved. Users accessing the share anonymously could experience privileged access to the content of such directories. Network sharable directories expose those directories and their contents to unnecessary access. Any unnecessary exposure increases the risk that someone could exploit that access and either compromises the web content or cause web server performance problems.
NOTE: The presence of operating system shares on the web server is not an issue as long as the shares are not part of the web content directories.

Solution

Remove the shares from the applicable directories.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Apache_2-2_WIN_V1R12_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, Rule-ID|SV-33109r2_rule, STIG-ID|WG210, Vuln-ID|V-2226

Plugin: Windows

Control ID: 62516828f676858467fe74957964c3b9d1e8be79a22c5eb881c8b93563d3c879