Skip to main content
CUI

Documentation - V-214236

V-214236

Apache Server 2.4 UNIX Server Security Technical Implementation Guide

CAT II

Title

The log information from the Apache web server must be protected from unauthorized modification or deletion.

Description

<VulnDiscussion>Log data is essential in the investigation of events. If log data were to become compromised, competent forensic analysis and discovery of the true source of potentially malicious system activity would be difficult, if not impossible, to achieve. In addition, access to log records provides information an attacker could potentially use to their advantage since each event record might contain communication ports, protocols, services, trust relationships, user names, etc. The web s...

Fix Text (Documentation Requirement)

Determine the location of the "ErrorLog" directory in the "httpd.conf" file: # apachectl -V | egrep -i 'httpd_root|server_config_file' -D HTTPD_ROOT="/etc/httpd" -D SERVER_CONFIG_FILE="conf/httpd.conf" Open the "httpd.conf" file. Look for the "ErrorLog" directive. Ensure the permissions and ownership of all files in the Apache log directory are correct by executing the following commands as an administrative service account: # chown <'service account'> <'ErrorLog directive PATH'>/*

Documentation Status

Cancel
CUI