VCLD-67-000026 - VAMI must restrict access to the web root.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version


As a rule, accounts on a web server are to be kept to a minimum, and those accounts are then restricted as to what they are allowed to access. The web root of the VAMI Lighttpd installation contains the content that is served up to the end user. This content must have the minimum necessary permissions and proper ownership to help protect against unprivileged modification of the content.


At the command prompt, execute the following commands:

# chmod 0755 <directory>
# chown root:root <directory>

Note: Substitute <directory> with each directory returned from the check.

See Also

Item Details

References: CAT|II, CCI|CCI-001082, Rule-ID|SV-239733r816815_rule, STIG-ID|VCLD-67-000026, Vuln-ID|V-239733

Plugin: Unix

Control ID: f3b10170b11a7de5cdacf0d9e10a941539c73b2d2be7118baa99e7fd2b3f003f