2.8 Ensure the Info Module Is Disabled (Automated)
Profile Applicability
- Level 1
Description
The Apache mod_info module provides information on the server configuration via access to a /server-info URL location.
Rationale
While having server configuration information available as a web page may be convenient it's recommended that this module NOT be enabled. Once mod_info is loaded into the server, its handler capability is available in all per-directory .htaccess files and can leak sensitive information from the configuration directives of other Apache modules such as system paths, usernames/passwords, database names, etc.
Audit
Perform the following to determine if the Info module is enabled.
Run the httpd server with the -M option to list enabled modules:
# httpd -M | egrep 'info_module'
Note: If the module is correctly disabled, there will be no output when executing the above command.
Remediation
Perform either one of the following to disable the mod_info module:
- For source builds with static modules, run the Apache
./configurescript without including themod_infoin the--enable-modules= configurescript options.$ cd $DOWNLOAD_HTTPD$ ./configure
- For dynamically loaded modules, comment out or remove the LoadModule directive for the
mod_infomodule from thehttpd.conffile.##LoadModule info_module modules/mod_info.so
Default Value
The mod_info module is not enabled with a default source build.
References
CIS Controls
- v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- v7: 9.2 Ensure Only Approved Ports, Protocols and Services Are Running
Profile
- Level 1